|
Log-Analyse und Auswertung: Softwareupdater.Ui.exe und Malwarebytes Anti-MalwareWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
30.09.2013, 21:39 | #16 | ||||
/// TB-Ausbilder | Softwareupdater.Ui.exe und Malwarebytes Anti-Malware Hallo Brigitte, Zitat:
Zitat:
Zitat:
Zitat:
__________________ cheers, Leo |
30.09.2013, 21:43 | #17 |
| Softwareupdater.Ui.exe und Malwarebytes Anti-Malware # Aktualisiert am 19/07/2013 von Xplode
__________________# Benutzer : Brigitte - BRIGITTE-PC # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) ~ Aktiviere die Benutzerkontensteuerung ... OK ~ Entferne die Bereinigungsprogramme ... Gelöscht : C:\FRST Gelöscht : C:\Users\Brigitte\Downloads\Addition.txt Gelöscht : C:\Users\Brigitte\Downloads\adwcleaner.exe Gelöscht : C:\Users\Brigitte\Downloads\esetsmartinstaller_enu.exe Gelöscht : C:\Users\Brigitte\Downloads\Fixlog.txt Gelöscht : C:\Users\Brigitte\Downloads\FRST.exe Gelöscht : C:\Users\Brigitte\Downloads\FRST.txt Gelöscht : HKLM\SOFTWARE\AdwCleaner ~ Erstelle ein Backup der Registrierungsdatenbank ... OK ~ Lösche die Wiederherstellungspunkte ... Gelöscht : RP #1598 [Geplanter Prüfpunkt | 09/18/2013 07:30:20] Gelöscht : RP #1599 [Geplanter Prüfpunkt | 09/19/2013 08:08:59] Gelöscht : RP #1600 [Geplanter Prüfpunkt | 09/21/2013 05:42:54] Gelöscht : RP #1601 [Windows Update | 09/24/2013 06:06:01] Gelöscht : RP #1602 [Geplanter Prüfpunkt | 09/27/2013 07:04:18] Gelöscht : RP #1603 [Free Driver Scout | 09/29/2013 09:37:58] Gelöscht : RP #1605 [DriverUtilities | 09/29/2013 09:59:27] Gelöscht : RP #1606 [Gerätetreiber-Paketinstallation: LSI Modems | 09/29/2013 10:05:07] Gelöscht : RP #1607 [Gerätetreiber-Paketinstallation: Hewlett-Packard Company Systemgeräte | 09/29/2013 10:08:12] Gelöscht : RP #1609 [Installiert Slim310NB | 09/29/2013 10:25:44] Gelöscht : RP #1610 [Free Driver Scout | 09/29/2013 16:27:00] Gelöscht : RP #1611 [Removed Java 7 Update 25 | 09/30/2013 20:06:00] Gelöscht : RP #1612 [Installed Java 7 Update 40 | 09/30/2013 20:09:52] Ein neuer Wiederherstellungspunkt wurde erstellt ! ~ Stelle die Systemeinstellungen wieder her ... OK ########## - EOF - ########## Benutzer Appdata local row adawaretb dtx.ini.vir geodata.xml.vir etc |
30.09.2013, 21:56 | #18 |
/// TB-Ausbilder | Softwareupdater.Ui.exe und Malwarebytes Anti-Malware Ok, delfix hat geklappt.
__________________Den Ordner kannst du sein lassen, der ist nicht aktiv. Alles in Ordnung und wir können das Thema beenden?
__________________ |
30.09.2013, 21:57 | #19 |
| Softwareupdater.Ui.exe und Malwarebytes Anti-Malware Ja dann gute nacht und noch mal vielen dank. Ich war schon bei paypal.... LG Brigitte |
30.09.2013, 22:00 | #20 |
/// TB-Ausbilder | Softwareupdater.Ui.exe und Malwarebytes Anti-Malware Danke nochmals für die Spende und dir auch gute Nacht. Freut mich, dass wir helfen konnten. Falls du dem Forum noch Verbesserungsvorschläge, Kritik oder ein Lob mitgeben möchtest, kannst du das hier tun. Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Ich bekomme somit keine Benachrichtigung mehr über neue Antworten. Solltest du das Thema erneut brauchen, schicke mir bitte eine PM und wir machen hier weiter. Jeder andere bitte diese Anleitung lesen und einen eigenen Thread erstellen.
__________________ cheers, Leo |
01.10.2013, 16:10 | #21 |
| Softwareupdater.Ui.exe und Malwarebytes Anti-Malware Hallo Leo,O.K. So sieht aus leider Malwarebytes Anti-Malware (Test) 1.75.0.1300 Malwarebytes : Free Anti-Malware download Datenbank Version: v2013.10.01.04 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Brigitte :: BRIGITTE-PC [Administrator] Schutz: Aktiviert 01.10.2013 13:47:32 mbam-log-2013-10-01 (13-47-32).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 216146 Laufzeit: 17 Minute(n), 51 Sekunde(n) Infizierte Speicherprozesse: 1 C:\Users\Brigitte\AppData\Local\FilesFrog Update Checker\update_checker.exe (PUP.Optional.FilesFrog.A) -> 3468 -> Löschen bei Neustart. Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 34 HKCR\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE} (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\escort.escortIEPane.1 (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\escort.escortIEPane (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\delta.deltaHlpr.1 (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\delta.deltaHlpr (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8} (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D} (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\esrv.deltaESrvc.1 (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\esrv.deltaESrvc (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\delta.deltadskBnd.1 (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\delta.deltadskBnd (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\Typelib\{4599D05A-D545-4069-BB42-5895B4EAE05B} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\Interface\{1231839B-064E-4788-B865-465A1B5266FD} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker (PUP.Optional.Somoto.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\DELTA\DELTA (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\BI (PUP.Optional.FilesFrog.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\BabSolution\Updater (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\SOMOTO\SDP (PUP.Optional.Somoto.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Delta\delta\Instl (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar (PUP.Optional.BabSolution.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\delta.deltaappCore.1 (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\delta.deltaappCore (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\d (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\delta (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 6 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SDP (PUP.Optional.FilesFrog.A) -> Daten: C:\Users\Brigitte\AppData\Local\FilesFrog Update Checker\update_checker.exe /auto -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Daten: Delta Toolbar -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Daten: -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Delta\Delta|tlbrSrchUrl (PUP.Optional.Delta.A) -> Daten: -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\BI|ui_path_filesfrog (PUP.Optional.FilesFrog.A) -> Daten: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\Somoto\SDP|affid (PUP.Optional.Somoto.A) -> Daten: software4u -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 1 HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.StartPage.A) -> Bösartig: (Search-Gol) Gut: (Google) -> Erfolgreich ersetzt und in Quarantäne gestellt. Infizierte Verzeichnisse: 12 C:\Users\Brigitte\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Roaming\Delta (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Roaming\BabSolution (PUP.Optional.BabSolution.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Roaming\BabSolution\CR (PUP.Optional.BabSolution.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Roaming\BabSolution\Shared (PUP.Optional.BabSolution.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\Delta\delta\1.8.24.6 (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\Delta\delta\1.8.24.6\bh (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Local\Temp\mt_ffx\Delta (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Local\Temp\mt_ffx\Delta\delta (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Local\Temp\mt_ffx\Delta\delta\1.8.24.6 (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Local\FilesFrog Update Checker (PUP.Optional.FilesFrog.A) -> Löschen bei Neustart. C:\Users\Brigitte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker (PUP.Optional.FilesFrog.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 30 C:\Users\Brigitte\AppData\Local\FilesFrog Update Checker\update_checker.exe (PUP.Optional.FilesFrog.A) -> Löschen bei Neustart. C:\Program Files\Delta\delta\1.8.24.6\bh\delta.dll (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\Delta\delta\1.8.24.6\deltasrv.exe (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\Delta\delta\1.8.24.6\deltaTlbr.dll (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Roaming\BabSolution\Shared\BabMaint.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Local\Temp\UpdateCheckerSetup.exe (PUP.Optional.Somoto.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Local\Temp\F3A5A9F6-BAB0-7891-89D1-A4A486E8A495\Latest\BabMaint.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Local\Temp\F3A5A9F6-BAB0-7891-89D1-A4A486E8A495\Latest\BExternal.dll (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Local\Temp\F3A5A9F6-BAB0-7891-89D1-A4A486E8A495\Latest\CrxInstaller.dll (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Local\Temp\F3A5A9F6-BAB0-7891-89D1-A4A486E8A495\Latest\DSearchLink.exe (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Local\Temp\F3A5A9F6-BAB0-7891-89D1-A4A486E8A495\Latest\MntrDLLInstall.dll (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Local\Temp\F3A5A9F6-BAB0-7891-89D1-A4A486E8A495\Latest\MyDeltaTB.exe (PUP.Optional.Delta) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Local\Temp\F3A5A9F6-BAB0-7891-89D1-A4A486E8A495\Latest\Setup.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Local\Temp\nsvF07D.tmp\bi_client.exe (PUP.Optional.Somoto.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Local\FilesFrog Update Checker\uninstall.exe (PUP.Optional.Somoto.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Roaming\Delta\sqlite3.dll (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage (PUP.Optional.BrowserDefender.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Roaming\BabSolution\CR\Delta.crx (PUP.Optional.BabSolution.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Roaming\BabSolution\Shared\BUSolution.dll (PUP.Optional.BabSolution.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Roaming\BabSolution\Shared\Delta.ico (PUP.Optional.BabSolution.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Roaming\BabSolution\Shared\GUninstaller.exe (PUP.Optional.BabSolution.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Roaming\BabSolution\Shared\SetupParams.ini (PUP.Optional.BabSolution.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Roaming\BabSolution\Shared\sqlite3.dll (PUP.Optional.BabSolution.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\Delta\delta\1.8.24.6\deltaApp.dll (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\Delta\delta\1.8.24.6\deltaEng.dll (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\Delta\delta\1.8.24.6\GUninstaller.exe (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\Delta\delta\1.8.24.6\uninstall.exe (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker\Check for Updates.lnk (PUP.Optional.FilesFrog.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Brigitte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker\Uninstall.lnk (PUP.Optional.FilesFrog.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) LG Brigitte |
01.10.2013, 16:27 | #22 |
/// TB-Ausbilder | Softwareupdater.Ui.exe und Malwarebytes Anti-Malware Oh das hast du dir wieder mit einem Download einen Haufen Adware eingefangen.. Was für ein Programm hast du da wo heruntergeladen und installiert...? Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ cheers, Leo |
01.10.2013, 16:38 | #23 |
| Softwareupdater.Ui.exe und Malwarebytes Anti-Malware Wollte was gutes machen und secunia personal software inspector online war ein warnung habe ich download auf die offizielle seite und noch meine idevice manager unistalliert und gelöscht das war...Und meine avira hat auch was gefunden...FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 27-09-2013 01 Ran by Brigitte at 2013-10-01 17:33:19 Running from C:\Users\Brigitte\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) 2007 Microsoft Office system (Version: 12.0.6612.1000) ABBYY FineReader 5.0 Sprint (Version: 5.0.0.3347) ABBYY FineReader 6.0 (Version: 6.0.759.29410) Activation Assistant for the 2007 Microsoft Office suites Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0) Adobe Flash Player 11 ActiveX (Version: 11.8.800.175) Adobe Flash Player 11 Plugin (Version: 11.8.800.168) Adobe Reader X (10.1.7) - Deutsch (Version: 10.1.7) Adobe Shockwave Player 12.0 (Version: 12.0.4.144) Agere Systems HDA Modem Amazon MP3-Downloader 1.0.17 (Version: 1.0.17) AMD Catalyst Install Manager (Version: 8.0.911.0) Apple Application Support (Version: 2.3.6) Apple Mobile Device Support (Version: 7.0.0.117) Apple Software Update (Version: 2.1.3.127) Atheros WLAN Client (Version: 1.00.000) Avira Free Antivirus (Version: 13.0.0.4052) AVStation Now (Version: 4.0.10.6) BlackBerry Desktop Software 5.0.1 (Version: 5.0.1.37) BlackBerry Device Software Updater (Version: 7.1.0.34) BlackBerry® Media Sync (Version: 3.0.0.39) Bonjour (Version: 3.0.0.10) Bundled software uninstaller Canon Easy-PhotoPrint EX Canon Easy-WebPrint EX Canon IJ Network Scanner Selector EX Canon IJ Network Tool (Version: 3.1.1) Canon MG5300 series Benutzerregistrierung Canon MG5300 series MP Drivers Canon MG5300 series On-screen Manual Canon MP Navigator EX 5.0 Canon My Printer Canon Solution Menu EX Catalyst Control Center Core Implementation (Version: 2007.0730.2152.37233) Catalyst Control Center Graphics Full Existing (Version: 2007.0730.2152.37233) Catalyst Control Center Graphics Full New (Version: 2007.0730.2152.37233) Catalyst Control Center Graphics Light (Version: 2007.0730.2152.37233) Catalyst Control Center Graphics Previews Vista (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Chinese Standard (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Chinese Traditional (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Czech (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Danish (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Dutch (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Finnish (Version: 2007.0730.2152.37233) Catalyst Control Center Localization French (Version: 2007.0730.2152.37233) Catalyst Control Center Localization German (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Greek (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Hungarian (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Italian (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Japanese (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Korean (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Norwegian (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Polish (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Portuguese (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Russian (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Spanish (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Swedish (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Thai (Version: 2007.0730.2152.37233) Catalyst Control Center Localization Turkish (Version: 2007.0730.2152.37233) CCC Help Chinese Standard (Version: 2007.0730.2151.37233) CCC Help Chinese Traditional (Version: 2007.0730.2151.37233) CCC Help Czech (Version: 2007.0730.2151.37233) CCC Help Danish (Version: 2007.0730.2151.37233) CCC Help Dutch (Version: 2007.0730.2151.37233) CCC Help English (Version: 2007.0730.2151.37233) CCC Help Finnish (Version: 2007.0730.2151.37233) CCC Help French (Version: 2007.0730.2151.37233) CCC Help German (Version: 2007.0730.2151.37233) CCC Help Greek (Version: 2007.0730.2151.37233) CCC Help Hungarian (Version: 2007.0730.2151.37233) CCC Help Italian (Version: 2007.0730.2151.37233) CCC Help Japanese (Version: 2007.0730.2151.37233) CCC Help Korean (Version: 2007.0730.2151.37233) CCC Help Norwegian (Version: 2007.0730.2151.37233) CCC Help Polish (Version: 2007.0730.2151.37233) CCC Help Portuguese (Version: 2007.0730.2151.37233) CCC Help Russian (Version: 2007.0730.2151.37233) CCC Help Spanish (Version: 2007.0730.2151.37233) CCC Help Swedish (Version: 2007.0730.2151.37233) CCC Help Thai (Version: 2007.0730.2151.37233) CCC Help Turkish (Version: 2007.0730.2151.37233) ccc-core-static (Version: 2007.0730.2152.37233) ccc-utility (Version: 2007.0730.2152.37233) CCleaner (Version: 4.01) CDex - Open Source Digital Audio CD Extractor (Version: 1.70.4.2009) CD-LabelPrint Dokumentation zu Microsoft Office Communicator 2007-Richtlinien (Version: 3.0.6362.0) DVD Suite (Version: 5.0.1603) Easy Battery Manager (Version: 3.2.1.1) Easy Display Manager (Version: 2.0.0.0) Easy Network Manager 3.0 (Version: 3.0.0.0) Easy SpeedUp Manager (Version: 2.0.0.11) ElsterFormular (Version: 14.1.20130301) Free WMA to MP3 Converter 1.16 Free YouTube Download version 3.2.9.725 (Version: 3.2.9.725) Free YouTube to iPhone Converter version 2.12.9.725 (Version: 2.12.9.725) FRITZ!Box USB-Fernanschluss (HKCU Version: 2.3.1.0) FUJIdirekt Bestellsoftware 5.1 Gigaset QuickSync (Version: 8.3.0868.3) Google Chrome (HKCU Version: 29.0.1547.76) Google Toolbar for Internet Explorer (Version: 1.0.0) Google Toolbar for Internet Explorer (Version: 7.5.4413.1752) imagine digital freedom - Samsung (Version: 1.0.2.0) IrfanView (remove only) (Version: 4.36) iTunes (Version: 11.1.0.126) Java 7 Update 40 (Version: 7.0.400) Java Auto Updater (Version: 2.1.9.8) Junk Mail filter update (Version: 14.0.8117.416) Kyodai Mahjongg 2006 v1.42 LSI HDA Modem (Version: 2.2.97) MagicBerry for Blackberry version 3.5 (Version: 3.5) Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Choice Guard (Version: 2.0.48.0) Microsoft Office 2003 Web Components (Version: 11.0.8003.0) Microsoft Office 2007 Primary Interop Assemblies (Version: 12.0.4518.1014) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Communicator 2007 (Version: 2.0.6362.0) Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Professional Hybrid 2007 (Version: 12.0.6612.1000) Microsoft Office Professional Plus 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Small Business Connectivity Components (Version: 2.0.7024.0) Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SOAP Toolkit 2.0 SP2 (Version: 623.1) Microsoft SQL Server 2005 Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) (Version: 9.4.5000.00) Microsoft SQL Server Native Client (Version: 9.00.5000.00) Microsoft SQL Server VSS Writer (Version: 9.00.5000.00) Microsoft Sync Framework Runtime Native v1.0 (x86) (Version: 1.0.1215.0) Microsoft Sync Framework Services Native v1.0 (x86) (Version: 1.0.1215.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.50727.42) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft XML Parser (Version: 8.70.1104.04) Microsoft_VC100_CRT_SP1_x86 (Version: 10.0.40219.1) MobileMe Control Panel (Version: 2.1.1.13) MSVC80_x86 (Version: 1.0.1.0) MSVC80_x86_v2 (Version: 1.0.3.0) MSVC90_x86 (Version: 1.0.1.2) MSVCRT (Version: 14.0.1468.721) MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0) MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) Nero 8 Demo (Version: 8.10.214) neroxml (Version: 1.0.0) Nokia Connectivity Cable Driver (Version: 7.1.92.0) Nokia Suite (Version: 3.6.36.0) NVIDIA GAME System Software 2.8.1 (Version: 2.8.1) OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0) OpenOffice.org Installer 1.0 (Version: 1.0.9221) PC Connectivity Solution (Version: 12.0.48.0) Personal Backup 5.4 (Version: 5.3) PhotoDose 5.1 PHOTOfunSTUDIO (Version: 3.00.000) PhotoScape PL-2303 Vista Driver Installer (Version: 3.0.1.0) Play AVStation (Version: 4.1.20.46) PowerDVD (Version: 7.0.2802.0) QuickTime (Version: 7.74.80.86) Realtek High Definition Audio Driver (Version: 6.0.1.5659) Recuva (Version: 1.47) Roxio Media Manager (Version: 9.4.067) Safari (Version: 5.34.57.2) Samsung Magic Doctor (Version: 5.00) Samsung Recovery Solution II (Version: 2.0) Samsung Update Plus (Version: 2.0) Sherlock Holmes jagt Jack the Ripper (Version: 1.00.0777) Skins (Version: 2007.0730.2152.37233) Skype™ 6.7 (Version: 6.7.102) Slim310NB (Version: 5.16.1.300) swMSM (Version: 12.0.0.1) Synaptics Pointing Device Driver (Version: 9.1.22.0) Unlocker 1.9.1 (Version: 1.9.1) Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (Version: 9.00.5000.00) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB2836940) (Version: 1) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (Version: 1) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2825641) 32-Bit Edition Update für Microsoft Office Excel 2007 Help (KB963678) Update für Microsoft Office Outlook 2007 Help (KB963677) Update für Microsoft Office Powerpoint 2007 Help (KB963669) Update für Microsoft Office Word 2007 Help (KB963665) User Guide (Version: 1.0) VCRedistSetup (Version: 1.0.0) Visual C++ 2008 x86 Runtime - (v9.0.30729) (Version: 9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 (Version: 9.0.30729.01) VLC media player 2.0.8 (Version: 2.0.8) WebEnhance WIDCOMM Bluetooth Software 6.0.1.5000 (Version: 6.0.1.5000) Windows Live Communications Platform (Version: 14.0.8117.416) Windows Live Essentials (Version: 14.0.8117.0416) Windows Live Essentials (Version: 14.0.8117.416) Windows Live Fotogalerie (Version: 14.0.8117.416) Windows Live Mail (Version: 14.0.8089.0726) Windows Live Writer (Version: 14.0.8089.0726) Windows Live-Uploadtool (Version: 14.0.8014.1029) Windows Media Player Firefox Plugin (Version: 1.0.0.8) Windows-Treiberpaket - Nokia pccsmcfd “LegacyDriver” (05/31/2012 7.1.2.0) (Version: 05/31/2012 7.1.2.0) WinZip (Version: 11.0 (7347g)) ==================== Restore Points ========================= 30-09-2013 20:38:08 Ende der Bereinigung 01-10-2013 09:29:41 Gerätetreiber-Paketinstallation: Apple Netzwerkadapter ==================== Hosts content: ========================== 2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {02773C0A-6385-4205-9357-EB57C584A801} - System32\Tasks\EPUpdater => C:\Users\Brigitte\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {21B3A717-1472-4723-9C6D-86A4C91E2260} - System32\Tasks\SupBackGroundTask => C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe [2010-04-20] () Task: {29E961DE-2895-40F2-9662-776EA02973A2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3801056569-3724766084-3036744875-1003UA => C:\Users\Brigitte\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-01] (Google Inc.) Task: {2E73D919-5704-48F5-BD45-2DA050634DD6} - System32\Tasks\advSRSII => C:\Program Files\Samsung\Samsung Recovery Solution II\WCScheduler.exe [2007-04-04] () Task: {36CC60E7-F073-45B7-92D3-2D0FCA4284BD} - System32\Tasks\SamsungMagicDoctor => C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe [2007-04-26] (Samsung Electronics Co., Ltd.) Task: {37EEFB0D-210F-4FB3-A6F7-14106AAFEAEF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-21] (Adobe Systems Incorporated) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation) Task: {51B409DE-CA92-4DCB-8FE6-2CD12B6D5D35} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-06-01] (Google Inc.) Task: {58A5B91B-3393-49FA-9D03-C3CE696AE2D7} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {678BFEA2-0A29-46AA-9EB9-9802BD48E510} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-04-23] (Piriform Ltd) Task: {75E3C747-302C-4F75-B6F5-81FD1263468D} - System32\Tasks\User_Feed_Synchronization-{59D436A6-1A37-4095-A0AC-FA7FD0F04581} => C:\Windows\system32\msfeedssync.exe [2011-05-12] (Microsoft Corporation) Task: {80AF346F-AA8E-4BBC-8A2E-87C003976B06} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2007-06-01] (SAMSUNG Electronics) Task: {9DBC4E1A-1A47-4365-985F-7EE43499F7AB} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe [2007-06-29] (SAMSUNG Electronics co., LTD.) Task: {D48C3E9E-B925-41C3-B951-8BC30FA23ED0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-06-01] (Google Inc.) Task: {DD2B15F8-372B-4139-A62F-2544A4383927} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] () Task: {E6AEE1D2-7C8B-4DBA-80F2-A952B8F691E9} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3801056569-3724766084-3036744875-1003Core => C:\Users\Brigitte\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-01] (Google Inc.) Task: {E90E0C26-3D38-4B64-893D-954ADAFB7503} - System32\Tasks\EasySpeedUpManager => C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe [2007-04-24] (Samsung Electronics Co., Ltd.) Task: {EFACF2F1-DA3B-4428-8F01-192221D8074D} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3801056569-3724766084-3036744875-1003 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe Task: {F8F4B8BB-1BAE-4D8E-840E-158703022361} - System32\Tasks\Microsoft\Windows\RestartManager\{F0099369-5385-435d-98A4-7EB320CE2F35} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation) Task: C:\Windows\Tasks\Ad-Aware Update (Weekly).job => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3801056569-3724766084-3036744875-1003Core.job => C:\Users\Brigitte\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3801056569-3724766084-3036744875-1003UA.job => C:\Users\Brigitte\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\SupBackGroundTask.job => C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe ==================== Loaded Modules (whitelisted) ============= 2008-06-05 19:32 - 2010-04-16 14:11 - 00155648 _____ () C:\Program Files\Samsung\Samsung Update Plus\HMXML.dll 2007-08-08 01:17 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files\Samsung\Samsung Magic Doctor\HookDllPS2.dll 2007-08-07 07:06 - 2007-08-07 02:31 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll 2007-08-08 00:50 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll 2007-08-08 00:50 - 2006-09-19 02:52 - 00028672 _____ () C:\Program Files\Samsung\Easy Display Manager\WinMove.dll 2007-08-08 00:54 - 2007-02-23 11:32 - 00065536 _____ () C:\Program Files\Samsung\EBM\ChkSec.dll 2007-08-08 00:55 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files\SAMSUNG\EasySpeedUpManager\HookDllPS2.dll 2011-09-27 07:23 - 2011-09-27 07:23 - 00087912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2011-09-27 07:22 - 2011-09-27 07:22 - 01242472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2009-02-26 14:46 - 2009-02-26 14:46 - 00064344 _____ () C:\Program Files\Microsoft Office\Office12\ADDINS\ColleagueImport.dll 2011-06-22 12:46 - 2011-06-22 12:46 - 00434016 _____ () C:\Program Files\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll 2013-07-10 18:07 - 2013-07-10 18:07 - 00756888 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL 2013-09-19 13:35 - 2013-09-17 05:21 - 04053456 _____ () C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\29.0.1547.76\pdf.dll 2013-09-19 13:35 - 2013-09-17 05:21 - 00410576 _____ () C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll 2013-09-19 13:35 - 2013-09-17 05:20 - 01604560 _____ () C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\29.0.1547.76\ffmpegsumo.dll 2013-09-19 13:35 - 2013-09-17 05:21 - 13611984 _____ () C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\29.0.1547.76\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/01/2013 05:29:16 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\BRIGITTE\APPDATA\LOCAL\VIRTUALSTORE\WINDOWS\FTPCACHE> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (10/01/2013 04:50:48 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\BRIGITTE\APPDATA\LOCAL\VIRTUALSTORE\WINDOWS\FTPCACHE> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (10/01/2013 04:45:03 PM) (Source: Microsoft Office 12) (User: ) Description: Rejected Safe Mode action : Microsoft Office Outlook. Error: (10/01/2013 02:30:41 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\BRIGITTE\PHONE BROWSER\351680055101855> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (10/01/2013 01:21:52 PM) (Source: Perflib) (User: ) Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4 Error: (10/01/2013 01:21:50 PM) (Source: Perflib) (User: ) Description: EmdCacheC:\Windows\system32\emdmgmt.dll4 Error: (10/01/2013 00:12:21 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Adobe Reader X (10.1.8) - Deutsch - Update "Adobe Reader X (10.1.7)" konnte nicht installiert werden. Fehlercode 1638. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: How to enable Windows Installer logging Error: (10/01/2013 00:12:21 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Adobe Reader X (10.1.8) - Deutsch - Update "Adobe Reader X (10.1.3)" konnte nicht installiert werden. Fehlercode 1638. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: How to enable Windows Installer logging Error: (10/01/2013 00:12:21 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Adobe Reader X (10.1.8) - Deutsch - Update "Adobe Reader X (10.1.4)" konnte nicht installiert werden. Fehlercode 1638. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: How to enable Windows Installer logging Error: (10/01/2013 00:12:21 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Adobe Reader X (10.1.8) - Deutsch - Update "Adobe Reader X (10.1.1)" konnte nicht installiert werden. Fehlercode 1638. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: How to enable Windows Installer logging System errors: ============= Error: (10/01/2013 05:00:10 PM) (Source: Service Control Manager) (User: ) Description: Lbd SBRE UimBus Uim_IM Uim_Vim Error: (10/01/2013 04:58:43 PM) (Source: Service Control Manager) (User: ) Description: 30000Roxio Hard Drive Watcher 9 Error: (10/01/2013 04:58:43 PM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (10/01/2013 04:57:01 PM) (Source: atikmdag) (User: ) Description: Unknown EDID version Error: (10/01/2013 04:54:30 PM) (Source: DCOM) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (10/01/2013 00:25:43 PM) (Source: DCOM) (User: ) Description: C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\iKernel.exe -Embedding740{91814EC0-B5F0-11D2-80B9-00104B1F6CEA} Error: (10/01/2013 11:32:40 AM) (Source: Service Control Manager) (User: ) Description: Apple Mobile Device1600001Neustart des Diensts Error: (10/01/2013 08:41:12 AM) (Source: Service Control Manager) (User: ) Description: 30000Microsoft .NET Framework NGEN v4.0.30319_X86 Error: (10/01/2013 08:38:42 AM) (Source: Service Control Manager) (User: ) Description: Lbd SBRE UimBus Uim_IM Uim_Vim Error: (10/01/2013 08:37:23 AM) (Source: Service Control Manager) (User: ) Description: Windows Search%%1053 Microsoft Office Sessions: ========================= Error: (01/07/2013 09:47:32 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 34 seconds with 0 seconds of active time. This session ended with a crash. Error: (09/29/2012 02:29:53 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 20 seconds with 0 seconds of active time. This session ended with a crash. Error: (09/11/2012 00:55:54 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6661.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 38 seconds with 0 seconds of active time. This session ended with a crash. Error: (07/10/2011 00:51:21 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 126 seconds with 60 seconds of active time. This session ended with a crash. Error: (02/02/2011 11:47:29 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 7341 seconds with 420 seconds of active time. This session ended with a crash. Error: (10/22/2010 10:42:52 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3035 seconds with 2340 seconds of active time. This session ended with a crash. Error: (07/22/2010 07:26:30 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6535.5005, Microsoft Office Version: 12.0.6425.1000. This session lasted 485 seconds with 300 seconds of active time. This session ended with a crash. Error: (02/07/2010 01:08:57 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 6492 seconds with 480 seconds of active time. This session ended with a crash. Error: (01/22/2010 07:42:50 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 690 seconds with 60 seconds of active time. This session ended with a crash. Error: (01/11/2010 04:04:36 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4642 seconds with 720 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2013-09-30 16:45:15.460 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-30 16:45:15.087 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-30 16:45:14.724 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-30 16:45:14.352 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-30 16:43:19.073 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-30 16:43:18.704 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-30 16:43:18.269 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-30 16:43:17.845 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-30 16:18:21.387 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-30 16:18:20.966 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 64% Total physical RAM: 2045.45 MB Available physical RAM: 731.94 MB Total Pagefile: 4336.18 MB Available Pagefile: 2665.28 MB Total Virtual: 2047.88 MB Available Virtual: 1903.63 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:107.31 GB) (Free:42.13 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:69 GB) (Free:24.6 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 186 GB) (Disk ID: E39F5DBD) Partition 1: (Not Active) - (Size=10 GB) - (Type=27) Partition 2: (Active) - (Size=107 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=69 GB) - (Type=07 NTFS) ==================== End Of Log ============================ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-09-2013 01 Ran by Brigitte (administrator) on BRIGITTE-PC on 01-10-2013 17:30:24 Running from C:\Users\Brigitte\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe () C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe () C:\Program Files\Samsung\Samsung Recovery Solution II\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (Agere Systems) C:\Windows\system32\agrsmsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (C-Dilla Ltd) C:\Windows\system32\drivers\CDAC11BA.EXE (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE (Google Inc.) C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Google Inc.) C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\system32\conime.exe (Google Inc.) C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-06] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-09-17] (Apple Inc.) HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [] - [x] HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter ==================== Internet (Whitelisted) ==================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=780A001B9E4E04B7&affID=125155&tsp=5022 SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus&rlz=1I7GZAZ_de BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - No Name - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll No File FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @nokia.com/EnablerPlugin - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin: @RIM.com/WebSLLauncher,version=1.0 - C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll () FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Brigitte\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Brigitte\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10174.dll (Amazon.com, Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\SP_amazonde.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\SP_preispiraten_de.xml FF Extension: Google Settings - C:\Program Files\Mozilla Firefox\extensions\google-cjk@partners.mozilla.com FF Extension: Google Toolbar for Firefox - C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR RestoreOnStartup: "hxxp://www.google.de/webhp?sourceid=chrome-instant&ie=UTF-8#hl=de&output=search&sclient=psy-ab&q=tarif%20maison%20de%20retraite%20st%20henri%20le%20creusot&oq=&gs_l=&pbx=1&fp=f2a8e9e11ea3a048&bav=on.2,or.r_gc.r_pw.r_qf.,cf.osb&biw=1280&bih=685", "hxxp://www.google.de/", "hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=homepage&toolbarid=adawaretb&v=2_2&u=EABC2F663E19AEFA2C96505079702EC6", "hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=65e5fa31-b18b-4a45-b1c1-28731d52162e&searchtype=hp&installDate=25/02/2013", "hxxp://securedsearch2.lavasoft.com/index.php?pr=vmn&id=adawaretb&v=3_4&ent=hp&u=EABC2F663E19AEFA2C9650523AB8DBBA", "hxxp://www.google.com" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\29.0.1547.76\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\29.0.1547.76\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll No File CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll No File CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10174.dll (Amazon.com, Inc.) CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility for IJ) - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll () CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.149\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (Learn French - Tr\u00E8s Bien) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\aeifanonhefcaphaeeknpklkfnjjmpec\1.46_0 CHR Extension: (Google Docs) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (YoWindow Weather) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\fanogbnclpilemkifpjeglokomebpnef\1.43_0 CHR Extension: () - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\background.html CHR Extension: (Print) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\idfnpgjblkahngbondojabhffkkdekbd\2.0.2.5_0 CHR Extension: (eBay Extension for Google Chrome\u2122 (by eBay)) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\khhckppjhonfmcpegdjdibmngahahhck\3.0.1.5_0 CHR Extension: (Ella Moss) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\klghmpijngbhkpcnbdjpdbognohonimk\2_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR Extension: (Lavasoft NewTab) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\oejkcgajlodefenbbjdnaiahmbnnoole\0.12_0 CHR Extension: (Gmail) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [oejkcgajlodefenbbjdnaiahmbnnoole] - C:\Program Files\Lavasoft\AdAware SecureSearch Toolbar\chrome-newtab-search.crx CHR StartMenuInternet: Google Chrome - C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-06] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-06] (Avira Operations GmbH & Co. KG) R2 C-DillaCdaC11BA; C:\Windows\system32\drivers\CDAC11BA.EXE [39936 2010-10-18] (C-Dilla Ltd) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [171040 2007-01-08] () S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [x] ==================== Drivers (Whitelisted) ==================== R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2012-01-13] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-06] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-06] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-04-01] (Avira Operations GmbH & Co. KG) R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [105728 2013-09-12] (AVM Berlin) R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-09-19] (GFI Software) S3 GigasetGenericUSB; C:\Windows\System32\DRIVERS\GigasetGenericUSB.sys [44032 2013-04-25] (Siemens Home and Office Communication Devices GmbH & Co. KG) R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2007-08-08] (SAMSUNG ELECTRONICS CO., LTD.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2012-01-13] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2013-10-01] (Malwarebytes Corporation) S3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2589184 2006-11-02] (Intel® Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-02-24] (Avira GmbH) S1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [81232 2013-03-15] (Windows (R) 2000 DDK provider) S1 Uim_IM; C:\Windows\System32\Drivers\Uim_IM.sys [452816 2013-03-15] (Paragon) S1 Uim_Vim; C:\Windows\System32\Drivers\Uim_Vim.sys [283600 2013-03-15] (Paragon) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S0 Lbd; system32\DRIVERS\Lbd.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [x] U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-01 17:30 - 2013-10-01 17:30 - 00000000 ____D C:\FRST 2013-10-01 17:29 - 2013-10-01 17:29 - 01086873 _____ (Farbar) C:\Users\Brigitte\Downloads\FRST.exe 2013-10-01 17:08 - 2013-10-01 17:08 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys 2013-10-01 16:56 - 2013-10-01 16:56 - 00011754 _____ C:\Windows\PFRO.log 2013-10-01 13:20 - 2013-10-01 13:20 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\Software4u 2013-10-01 13:20 - 2013-10-01 13:20 - 00000000 ____D C:\ProgramData\Babylon 2013-10-01 13:20 - 2013-10-01 13:20 - 00000000 ____D C:\Program Files\Delta 2013-10-01 11:50 - 2013-10-01 11:50 - 00001664 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-10-01 11:47 - 2013-10-01 11:50 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-10-01 11:47 - 2013-10-01 11:50 - 00000000 ____D C:\Program Files\iTunes 2013-10-01 11:47 - 2013-10-01 11:47 - 00000000 ____D C:\Program Files\iPod 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default\AppData\Roaming\Apple Computer 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default\AppData\Local\Apple Computer 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Apple Computer 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default User\AppData\Local\Apple Computer 2013-10-01 10:51 - 2013-10-01 10:51 - 00000000 ____D C:\Users\Brigitte\AppData\Local\Secunia PSI 2013-10-01 10:50 - 2013-10-01 10:50 - 00000000 ____D C:\Program Files\Secunia 2013-10-01 10:49 - 2013-10-01 10:49 - 03272136 _____ (Secunia) C:\Users\Brigitte\Downloads\PSISetup.exe 2013-09-30 22:37 - 2013-09-30 22:39 - 00001859 _____ C:\DelFix.txt 2013-09-30 22:37 - 2013-09-30 22:37 - 00000000 ____D C:\Windows\ERUNT 2013-09-30 22:13 - 2013-09-30 22:13 - 07912440 _____ (Adobe Systems Inc.) C:\Users\Brigitte\Downloads\Shockwave_Installer_Slim.exe 2013-09-30 22:12 - 2013-09-30 22:12 - 00000000 ____D C:\ProgramData\Oracle 2013-09-30 22:12 - 2013-09-30 22:12 - 00000000 ____D C:\Program Files\Common Files\Java 2013-09-30 22:12 - 2013-09-30 22:10 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-09-30 22:11 - 2013-09-30 22:10 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-09-30 22:11 - 2013-09-30 22:10 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-09-30 22:11 - 2013-09-30 22:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-09-30 22:08 - 2013-09-30 22:08 - 00913832 _____ (Oracle Corporation) C:\Users\Brigitte\Downloads\jre-7u40-windows-i586-iftw.exe 2013-09-30 00:26 - 2013-09-30 00:26 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\Malwarebytes 2013-09-30 00:25 - 2013-09-30 00:25 - 00000906 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-30 00:25 - 2013-09-30 00:25 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-30 00:25 - 2013-09-30 00:25 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-30 00:25 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-30 00:23 - 2013-09-30 00:23 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Brigitte\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-30 00:16 - 2013-09-30 00:17 - 90353424 _____ (Microsoft Corporation) C:\Users\Brigitte\Downloads\msert.exe 2013-09-29 12:26 - 2013-09-29 12:26 - 00000816 _____ C:\Users\Public\Desktop\Slim 310NB.lnk 2013-09-29 12:09 - 2013-09-29 12:09 - 00000000 ____D C:\Program Files\Hewlett-Packard 2013-09-29 12:09 - 2013-09-29 12:09 - 00000000 ____D C:\cpqsystem 2013-09-29 12:05 - 2013-09-29 12:05 - 00000000 ____D C:\Program Files\LSI SoftModem 2013-09-29 12:03 - 2013-09-29 12:03 - 00000000 ____D C:\Windows\Dell 2013-09-29 11:47 - 2013-10-01 16:37 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\Skype 2013-09-29 11:46 - 2013-09-29 11:46 - 00001880 _____ C:\Users\Public\Desktop\Skype.lnk 2013-09-29 11:46 - 2013-09-29 11:46 - 00000000 ___RD C:\Program Files\Skype 2013-09-29 11:46 - 2013-09-29 11:46 - 00000000 ____D C:\Program Files\Common Files\Skype 2013-09-29 11:45 - 2013-09-29 11:46 - 00000000 ____D C:\ProgramData\Skype 2013-09-29 11:44 - 2013-09-29 11:44 - 32776560 _____ (Skype Technologies S.A.) C:\Users\Brigitte\Downloads\SkypeSetupFull.exe 2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\Users\Brigitte\Documents\Freemium Driver Utilities 2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\ProgramData\DriversGalaxy 2013-09-29 11:42 - 2013-09-29 11:42 - 00675952 _____ C:\Users\Brigitte\Downloads\SkypeSetup.exe 2013-09-29 11:31 - 2013-09-29 11:31 - 00000000 ____D C:\Users\Brigitte\AppData\Local\DriverTuner 2013-09-28 08:38 - 2013-09-28 08:38 - 00000000 ____D C:\Users\Brigitte\AppData\Local\Adobe_Systems_Incorporate 2013-09-28 08:37 - 2013-09-30 23:06 - 00000000 ____D C:\Users\Brigitte\Documents\My Digital Editions 2013-09-28 08:34 - 2013-09-28 08:34 - 05892496 _____ (Adobe Systems Incorporated) C:\Users\Brigitte\Downloads\ADE_2.0_Installer.exe 2013-09-19 10:42 - 2013-09-19 10:42 - 00000105 _____ C:\prefs.js 2013-09-19 10:42 - 2013-09-19 10:42 - 00000000 ____D C:\Users\Brigitte\AppData\Local\adawarebp 2013-09-19 10:42 - 2013-09-19 10:42 - 00000000 ____D C:\ProgramData\Downloaded Installations 2013-09-19 10:42 - 2013-09-19 10:42 - 00000000 ____D C:\Program Files\Toolbar Cleaner 2013-09-19 10:22 - 2013-09-19 10:38 - 00013560 _____ (GFI Software) C:\Windows\system32\Drivers\gfibto.sys 2013-09-12 20:25 - 2013-09-14 11:30 - 00000000 ____D C:\Users\Brigitte\Documents\Fritzbox 2013-09-12 19:35 - 2013-09-12 19:35 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRITZ!Box 2013-09-12 19:35 - 2013-09-12 19:34 - 00105728 _____ (AVM Berlin) C:\Windows\system32\Drivers\avmaura.sys 2013-09-12 18:01 - 2013-09-12 18:01 - 00127356 _____ C:\Users\Brigitte\Downloads\speedportw900v.export 2013-09-12 09:25 - 2013-07-31 12:30 - 12335104 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-12 09:25 - 2013-07-31 12:05 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-12 09:25 - 2013-07-31 12:00 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-12 09:25 - 2013-07-31 11:53 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-12 09:25 - 2013-07-31 11:52 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-09-12 09:25 - 2013-07-31 11:52 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-12 09:25 - 2013-07-31 11:51 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-09-12 09:25 - 2013-07-31 11:49 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-12 09:25 - 2013-07-31 11:48 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-12 09:25 - 2013-07-31 11:48 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-09-12 09:25 - 2013-07-31 11:48 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-09-12 09:25 - 2013-07-31 11:47 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-12 09:25 - 2013-07-31 11:46 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-12 09:25 - 2013-07-31 11:45 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-12 09:25 - 2013-07-31 11:45 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-09-12 09:25 - 2013-07-31 11:42 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-11 13:26 - 2013-09-11 13:40 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\PhotoScape 2013-09-11 13:26 - 2013-09-11 13:26 - 00000828 _____ C:\Users\Brigitte\Desktop\PhotoScape.lnk 2013-09-11 13:26 - 2013-09-11 13:26 - 00000000 ____D C:\Program Files\PhotoScape 2013-09-11 13:14 - 2013-08-08 03:45 - 02049536 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-11 13:14 - 2013-07-16 06:35 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll 2013-09-11 12:56 - 2013-09-11 12:56 - 00004266 _____ C:\Users\Brigitte\AppData\Local\recently-used.xbel 2013-09-09 09:04 - 2013-09-09 09:05 - 08164297 _____ (J. Rathlev ) C:\Users\Brigitte\Documents\pb-setup-5.4.0802.exe 2013-09-09 08:47 - 2013-09-11 12:58 - 00000000 ____D C:\Users\Brigitte\.gimp-2.8 2013-09-07 06:33 - 2013-09-07 08:48 - 96496803 _____ C:\Windows\system32\Ḭˆ 2013-09-02 16:07 - 2013-09-02 16:07 - 00000000 ____D C:\Users\Brigitte\AppData\Local\FUJIdirekt Bestellsoftware 2013-09-02 16:02 - 2013-09-02 16:02 - 00000918 _____ C:\Users\Public\Desktop\FUJIdirekt Bestellsoftware.lnk 2013-09-02 16:01 - 2013-09-02 16:07 - 00000000 ____D C:\Program Files\FUJIdirekt Bestellsoftware 2013-09-02 16:01 - 2013-09-02 16:01 - 00000000 ____D C:\ProgramData\FUJIdirekt Bestellsoftware 2013-09-02 15:57 - 2013-09-02 15:59 - 125481064 _____ ( ) C:\Users\Brigitte\Downloads\FUJIdirekt.exe 2013-09-01 14:13 - 2013-09-01 14:13 - 00000000 ____D C:\Users\Brigitte\AppData\Local\webkit 2013-09-01 14:09 - 2013-09-11 12:56 - 00000000 ____D C:\Users\Brigitte\AppData\Local\gtk-2.0 2013-09-01 14:09 - 2013-09-01 14:09 - 00000000 ____D C:\Users\Brigitte\.thumbnails 2013-09-01 14:03 - 2013-09-01 14:03 - 00000000 ____D C:\Users\Brigitte\AppData\Local\gegl-0.2 2013-09-01 13:53 - 2013-09-01 13:54 - 90116160 _____ (The GIMP Team ) C:\Users\Brigitte\Downloads\gimp-2.8.6-setup.exe ==================== One Month Modified Files and Folders ======= 2013-10-01 17:32 - 2008-10-16 06:57 - 00000416 ____H C:\Windows\Tasks\SupBackGroundTask.job 2013-10-01 17:30 - 2013-10-01 17:30 - 00000000 ____D C:\FRST 2013-10-01 17:29 - 2013-10-01 17:29 - 01086873 _____ (Farbar) C:\Users\Brigitte\Downloads\FRST.exe 2013-10-01 17:26 - 2012-06-04 11:48 - 00001132 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3801056569-3724766084-3036744875-1003UA.job 2013-10-01 17:11 - 2012-06-01 19:03 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-01 17:08 - 2013-10-01 17:08 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys 2013-10-01 16:57 - 2012-06-01 19:03 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-01 16:57 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-01 16:57 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-01 16:57 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-01 16:56 - 2013-10-01 16:56 - 00011754 _____ C:\Windows\PFRO.log 2013-10-01 16:55 - 2012-07-23 09:18 - 01404250 _____ C:\Windows\WindowsUpdate.log 2013-10-01 16:55 - 2007-08-08 00:21 - 00000012 _____ C:\Windows\bthservsdp.dat 2013-10-01 16:55 - 2006-11-02 15:01 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-10-01 16:52 - 2013-08-27 22:19 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-01 16:37 - 2013-09-29 11:47 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\Skype 2013-10-01 13:21 - 2007-09-30 10:32 - 00000000 ____D C:\Users\Brigitte 2013-10-01 13:20 - 2013-10-01 13:20 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\Software4u 2013-10-01 13:20 - 2013-10-01 13:20 - 00000000 ____D C:\ProgramData\Babylon 2013-10-01 13:20 - 2013-10-01 13:20 - 00000000 ____D C:\Program Files\Delta 2013-10-01 11:50 - 2013-10-01 11:50 - 00001664 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-10-01 11:50 - 2013-10-01 11:47 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-10-01 11:50 - 2013-10-01 11:47 - 00000000 ____D C:\Program Files\iTunes 2013-10-01 11:47 - 2013-10-01 11:47 - 00000000 ____D C:\Program Files\iPod 2013-10-01 11:47 - 2008-08-04 13:34 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default\AppData\Roaming\Apple Computer 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default\AppData\Local\Apple Computer 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Apple Computer 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default User\AppData\Local\Apple Computer 2013-10-01 11:31 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default 2013-10-01 10:51 - 2013-10-01 10:51 - 00000000 ____D C:\Users\Brigitte\AppData\Local\Secunia PSI 2013-10-01 10:50 - 2013-10-01 10:50 - 00000000 ____D C:\Program Files\Secunia 2013-10-01 10:49 - 2013-10-01 10:49 - 03272136 _____ (Secunia) C:\Users\Brigitte\Downloads\PSISetup.exe 2013-10-01 08:26 - 2012-06-04 11:48 - 00001080 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3801056569-3724766084-3036744875-1003Core.job 2013-09-30 23:06 - 2013-09-28 08:37 - 00000000 ____D C:\Users\Brigitte\Documents\My Digital Editions 2013-09-30 23:06 - 2008-12-31 14:18 - 00000000 ____D C:\Program Files\Adobe 2013-09-30 22:39 - 2013-09-30 22:37 - 00001859 _____ C:\DelFix.txt 2013-09-30 22:37 - 2013-09-30 22:37 - 00000000 ____D C:\Windows\ERUNT 2013-09-30 22:14 - 2008-09-13 17:06 - 00000000 ____D C:\Windows\system32\Adobe 2013-09-30 22:13 - 2013-09-30 22:13 - 07912440 _____ (Adobe Systems Inc.) C:\Users\Brigitte\Downloads\Shockwave_Installer_Slim.exe 2013-09-30 22:12 - 2013-09-30 22:12 - 00000000 ____D C:\ProgramData\Oracle 2013-09-30 22:12 - 2013-09-30 22:12 - 00000000 ____D C:\Program Files\Common Files\Java 2013-09-30 22:10 - 2013-09-30 22:12 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-09-30 22:10 - 2013-09-30 22:11 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-09-30 22:10 - 2013-09-30 22:11 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-09-30 22:10 - 2013-09-30 22:11 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-09-30 22:10 - 2012-06-01 11:22 - 00868264 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-09-30 22:10 - 2010-05-13 10:52 - 00790440 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-09-30 22:08 - 2013-09-30 22:08 - 00913832 _____ (Oracle Corporation) C:\Users\Brigitte\Downloads\jre-7u40-windows-i586-iftw.exe 2013-09-30 22:03 - 2007-12-22 19:56 - 00000000 ____D C:\Users\Brigitte\AppData\Local\Adobe 2013-09-30 16:21 - 2012-12-30 08:53 - 00000000 ____D C:\Program Files\Uniblue 2013-09-30 13:28 - 2012-11-07 15:50 - 00000000 ____D C:\Windows\Downloaded Installations 2013-09-30 12:41 - 2007-12-05 18:45 - 00000000 ____D C:\Users\Brigitte\Documents\Unzipped 2013-09-30 08:46 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\SchCache 2013-09-30 08:46 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Help 2013-09-30 00:44 - 2012-12-30 08:52 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\DVDVideoSoft 2013-09-30 00:44 - 2009-03-23 14:56 - 00000000 ____D C:\Program Files\Unlocker 2013-09-30 00:26 - 2013-09-30 00:26 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\Malwarebytes 2013-09-30 00:25 - 2013-09-30 00:25 - 00000906 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-30 00:25 - 2013-09-30 00:25 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-30 00:25 - 2013-09-30 00:25 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-30 00:23 - 2013-09-30 00:23 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Brigitte\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-30 00:17 - 2013-09-30 00:16 - 90353424 _____ (Microsoft Corporation) C:\Users\Brigitte\Downloads\msert.exe 2013-09-29 17:49 - 2011-02-12 16:00 - 00000000 ____D C:\Windows\pss 2013-09-29 12:26 - 2013-09-29 12:26 - 00000816 _____ C:\Users\Public\Desktop\Slim 310NB.lnk 2013-09-29 12:26 - 2007-11-24 17:27 - 00000000 ____D C:\Program Files\Common Files\snpstd3 2013-09-29 12:09 - 2013-09-29 12:09 - 00000000 ____D C:\Program Files\Hewlett-Packard 2013-09-29 12:09 - 2013-09-29 12:09 - 00000000 ____D C:\cpqsystem 2013-09-29 12:05 - 2013-09-29 12:05 - 00000000 ____D C:\Program Files\LSI SoftModem 2013-09-29 12:03 - 2013-09-29 12:03 - 00000000 ____D C:\Windows\Dell 2013-09-29 11:46 - 2013-09-29 11:46 - 00001880 _____ C:\Users\Public\Desktop\Skype.lnk 2013-09-29 11:46 - 2013-09-29 11:46 - 00000000 ___RD C:\Program Files\Skype 2013-09-29 11:46 - 2013-09-29 11:46 - 00000000 ____D C:\Program Files\Common Files\Skype 2013-09-29 11:46 - 2013-09-29 11:45 - 00000000 ____D C:\ProgramData\Skype 2013-09-29 11:44 - 2013-09-29 11:44 - 32776560 _____ (Skype Technologies S.A.) C:\Users\Brigitte\Downloads\SkypeSetupFull.exe 2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\Users\Brigitte\Documents\Freemium Driver Utilities 2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\ProgramData\DriversGalaxy 2013-09-29 11:42 - 2013-09-29 11:42 - 00675952 _____ C:\Users\Brigitte\Downloads\SkypeSetup.exe 2013-09-29 11:31 - 2013-09-29 11:31 - 00000000 ____D C:\Users\Brigitte\AppData\Local\DriverTuner 2013-09-28 08:38 - 2013-09-28 08:38 - 00000000 ____D C:\Users\Brigitte\AppData\Local\Adobe_Systems_Incorporate 2013-09-28 08:34 - 2013-09-28 08:34 - 05892496 _____ (Adobe Systems Incorporated) C:\Users\Brigitte\Downloads\ADE_2.0_Installer.exe 2013-09-21 06:53 - 2013-08-27 22:19 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-09-21 06:53 - 2012-01-20 15:18 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-09-19 13:35 - 2013-05-02 09:01 - 00002098 _____ C:\Users\Brigitte\Desktop\Google Chrome.lnk 2013-09-19 10:42 - 2013-09-19 10:42 - 00000105 _____ C:\prefs.js 2013-09-19 10:42 - 2013-09-19 10:42 - 00000000 ____D C:\Users\Brigitte\AppData\Local\adawarebp 2013-09-19 10:42 - 2013-09-19 10:42 - 00000000 ____D C:\ProgramData\Downloaded Installations 2013-09-19 10:42 - 2013-09-19 10:42 - 00000000 ____D C:\Program Files\Toolbar Cleaner 2013-09-19 10:42 - 2008-03-18 15:45 - 00000000 ____D C:\Program Files\Lavasoft 2013-09-19 10:38 - 2013-09-19 10:22 - 00013560 _____ (GFI Software) C:\Windows\system32\Drivers\gfibto.sys 2013-09-19 07:05 - 2009-04-21 08:03 - 00007858 _____ C:\Windows\system32\dmlg.dat 2013-09-18 11:57 - 2012-10-13 14:52 - 00000384 _____ C:\Windows\Tasks\Ad-Aware Update (Weekly).job 2013-09-14 11:30 - 2013-09-12 20:25 - 00000000 ____D C:\Users\Brigitte\Documents\Fritzbox 2013-09-14 09:08 - 2007-08-08 01:20 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-12 22:15 - 2012-06-01 19:02 - 00000000 ____D C:\Users\Brigitte\AppData\Local\Deployment 2013-09-12 19:35 - 2013-09-12 19:35 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRITZ!Box 2013-09-12 19:34 - 2013-09-12 19:35 - 00105728 _____ (AVM Berlin) C:\Windows\system32\Drivers\avmaura.sys 2013-09-12 18:03 - 2007-10-23 15:13 - 00000000 ____D C:\Users\Brigitte\Documents\Speedport sicherung 2013-09-12 18:01 - 2013-09-12 18:01 - 00127356 _____ C:\Users\Brigitte\Downloads\speedportw900v.export 2013-09-12 12:51 - 2006-11-02 14:47 - 00420384 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 09:14 - 2013-07-11 09:03 - 00000000 ____D C:\Windows\system32\MRT 2013-09-12 08:53 - 2006-11-02 12:24 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-09-11 13:40 - 2013-09-11 13:26 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\PhotoScape 2013-09-11 13:26 - 2013-09-11 13:26 - 00000828 _____ C:\Users\Brigitte\Desktop\PhotoScape.lnk 2013-09-11 13:26 - 2013-09-11 13:26 - 00000000 ____D C:\Program Files\PhotoScape 2013-09-11 12:58 - 2013-09-09 08:47 - 00000000 ____D C:\Users\Brigitte\.gimp-2.8 2013-09-11 12:56 - 2013-09-11 12:56 - 00004266 _____ C:\Users\Brigitte\AppData\Local\recently-used.xbel 2013-09-11 12:56 - 2013-09-01 14:09 - 00000000 ____D C:\Users\Brigitte\AppData\Local\gtk-2.0 2013-09-09 09:05 - 2013-09-09 09:04 - 08164297 _____ (J. Rathlev ) C:\Users\Brigitte\Documents\pb-setup-5.4.0802.exe 2013-09-09 09:05 - 2013-07-02 07:06 - 00000877 _____ C:\Users\Public\Desktop\Personal Backup 5.lnk 2013-09-09 09:05 - 2013-07-02 07:06 - 00000000 ____D C:\Program Files\Personal Backup 5 2013-09-09 09:05 - 2006-11-02 12:33 - 01718870 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-09 07:44 - 2010-04-11 10:57 - 00000000 ____D C:\Users\Brigitte\Documents\Brigitte 2013-09-07 08:48 - 2013-09-07 06:33 - 96496803 _____ C:\Windows\system32\Ḭˆ 2013-09-06 06:28 - 2013-02-24 14:04 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-09-06 06:28 - 2013-02-24 14:04 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-09-05 12:36 - 2007-12-05 18:23 - 00000000 ____D C:\Users\Brigitte\Documents\Telekom 2013-09-02 18:25 - 2008-09-04 00:15 - 00000000 ____D C:\Users\Brigitte\.jordan 2013-09-02 16:07 - 2013-09-02 16:07 - 00000000 ____D C:\Users\Brigitte\AppData\Local\FUJIdirekt Bestellsoftware 2013-09-02 16:07 - 2013-09-02 16:01 - 00000000 ____D C:\Program Files\FUJIdirekt Bestellsoftware 2013-09-02 16:02 - 2013-09-02 16:02 - 00000918 _____ C:\Users\Public\Desktop\FUJIdirekt Bestellsoftware.lnk 2013-09-02 16:01 - 2013-09-02 16:01 - 00000000 ____D C:\ProgramData\FUJIdirekt Bestellsoftware 2013-09-02 15:59 - 2013-09-02 15:57 - 125481064 _____ ( ) C:\Users\Brigitte\Downloads\FUJIdirekt.exe 2013-09-01 14:13 - 2013-09-01 14:13 - 00000000 ____D C:\Users\Brigitte\AppData\Local\webkit 2013-09-01 14:09 - 2013-09-01 14:09 - 00000000 ____D C:\Users\Brigitte\.thumbnails 2013-09-01 14:03 - 2013-09-01 14:03 - 00000000 ____D C:\Users\Brigitte\AppData\Local\gegl-0.2 2013-09-01 13:54 - 2013-09-01 13:53 - 90116160 _____ (The GIMP Team ) C:\Users\Brigitte\Downloads\gimp-2.8.6-setup.exe Files to move or delete: ==================== C:\Users\Brigitte\AppData\Roaming\desktop.ini Some content of TEMP: ==================== C:\Users\Brigitte\AppData\Local\Temp\DeltaTB.exe C:\Users\Brigitte\AppData\Local\Temp\Quarantine.exe C:\Users\Brigitte\AppData\Local\Temp\secuniasi2581677952182163719.dll C:\Users\Brigitte\AppData\Local\Temp\tmpB5AD.tmp.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-01 17:06 ==================== End Of Log ============================ Hat alles gut gemeint... LG |
01.10.2013, 16:44 | #24 |
/// TB-Ausbilder | Softwareupdater.Ui.exe und Malwarebytes Anti-Malware Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Starte noch einmal FRST.
__________________ cheers, Leo |
01.10.2013, 17:00 | #25 |
| Softwareupdater.Ui.exe und Malwarebytes Anti-Malware Im quarantäne bei Avira steht:TR/Drop.softomat.ANAdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.006 - Bericht erstellt am 01/10/2013 um 17:48:31 # Updated 01/10/2013 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : Brigitte - BRIGITTE-PC # Gestartet von : C:\Users\Brigitte\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\Program Files\Delta Ordner Gelöscht : C:\Users\Brigitte\AppData\Roaming\software4u Datei Gelöscht : C:\Windows\System32\Tasks\EPUpdater ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02773C0A-6385-4205-9357-EB57C584A801} [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{02773C0A-6385-4205-9357-EB57C584A801} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gelöscht : HKCU\Software\BabSolution Schlüssel Gelöscht : HKCU\Software\Delta Schlüssel Gelöscht : HKCU\Software\Somoto Schlüssel Gelöscht : HKLM\Software\Delta Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\bi_uninstaller Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta Chrome Toolbar Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\FilesFrog Update Checker ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16506 -\\ Mozilla Firefox v13.0 (de) [ Datei : C:\Users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\3brre5rw.Brigitte\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht : urls_to_restore_on_startup ************************* AdwCleaner[R0].txt - [4415 octets] - [01/10/2013 17:47:01] AdwCleaner[S0].txt - [4373 octets] - [01/10/2013 17:48:31] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4433 octets] ########## FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-09-2013 01 Ran by Brigitte (administrator) on BRIGITTE-PC on 01-10-2013 17:56:21 Running from C:\Users\Brigitte\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe () C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe () C:\Program Files\Samsung\Samsung Recovery Solution II\WCScheduler.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Agere Systems) C:\Windows\system32\agrsmsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (C-Dilla Ltd) C:\Windows\system32\drivers\CDAC11BA.EXE (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avcenter.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Google Inc.) C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE (Google Inc.) C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Google Inc.) C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe (Farbar) C:\Users\Brigitte\Downloads\FRST (1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-06] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-09-17] (Apple Inc.) HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [] - [x] HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter ==================== Internet (Whitelisted) ==================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus&rlz=1I7GZAZ_de BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - No Name - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll No File FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @nokia.com/EnablerPlugin - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin: @RIM.com/WebSLLauncher,version=1.0 - C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll () FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Brigitte\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Brigitte\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10174.dll (Amazon.com, Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\SP_amazonde.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\SP_preispiraten_de.xml FF Extension: Google Settings - C:\Program Files\Mozilla Firefox\extensions\google-cjk@partners.mozilla.com FF Extension: Google Toolbar for Firefox - C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR RestoreOnStartup: "hxxp://www.google.de/webhp?sourceid=chrome-instant&ie=UTF-8#hl=de&output=search&sclient=psy-ab&q=tarif%20maison%20de%20retraite%20st%20henri%20le%20creusot&oq=&gs_l=&pbx=1&fp=f2a8e9e11ea3a048&bav=on.2,or.r_gc.r_pw.r_qf.,cf.osb&biw=1280&bih=685", "hxxp://www.google.de/", "hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=homepage&toolbarid=adawaretb&v=2_2&u=EABC2F663E19AEFA2C96505079702EC6", "hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=65e5fa31-b18b-4a45-b1c1-28731d52162e&searchtype=hp&installDate=25/02/2013", "hxxp://securedsearch2.lavasoft.com/index.php?pr=vmn&id=adawaretb&v=3_4&ent=hp&u=EABC2F663E19AEFA2C9650523AB8DBBA", "hxxp://www.google.com" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\29.0.1547.76\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\29.0.1547.76\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll No File CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll No File CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10174.dll (Amazon.com, Inc.) CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility for IJ) - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll () CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.149\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (Learn French - Tr\u00E8s Bien) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\aeifanonhefcaphaeeknpklkfnjjmpec\1.46_0 CHR Extension: (Google Docs) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (YoWindow Weather) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\fanogbnclpilemkifpjeglokomebpnef\1.43_0 CHR Extension: () - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\background.html CHR Extension: (Print) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\idfnpgjblkahngbondojabhffkkdekbd\2.0.2.5_0 CHR Extension: (eBay Extension for Google Chrome\u2122 (by eBay)) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\khhckppjhonfmcpegdjdibmngahahhck\3.0.1.5_0 CHR Extension: (Ella Moss) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\klghmpijngbhkpcnbdjpdbognohonimk\2_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR Extension: (Lavasoft NewTab) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\oejkcgajlodefenbbjdnaiahmbnnoole\0.12_0 CHR Extension: (Gmail) - C:\Users\Brigitte\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [oejkcgajlodefenbbjdnaiahmbnnoole] - C:\Program Files\Lavasoft\AdAware SecureSearch Toolbar\chrome-newtab-search.crx CHR StartMenuInternet: Google Chrome - C:\Users\Brigitte\AppData\Local\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-06] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-06] (Avira Operations GmbH & Co. KG) R2 C-DillaCdaC11BA; C:\Windows\system32\drivers\CDAC11BA.EXE [39936 2010-10-18] (C-Dilla Ltd) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [171040 2007-01-08] () S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [x] ==================== Drivers (Whitelisted) ==================== R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2012-01-13] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-06] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-06] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-04-01] (Avira Operations GmbH & Co. KG) R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [105728 2013-09-12] (AVM Berlin) R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-09-19] (GFI Software) S3 GigasetGenericUSB; C:\Windows\System32\DRIVERS\GigasetGenericUSB.sys [44032 2013-04-25] (Siemens Home and Office Communication Devices GmbH & Co. KG) R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2007-08-08] (SAMSUNG ELECTRONICS CO., LTD.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2012-01-13] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2589184 2006-11-02] (Intel® Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-02-24] (Avira GmbH) S1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [81232 2013-03-15] (Windows (R) 2000 DDK provider) S1 Uim_IM; C:\Windows\System32\Drivers\Uim_IM.sys [452816 2013-03-15] (Paragon) S1 Uim_Vim; C:\Windows\System32\Drivers\Uim_Vim.sys [283600 2013-03-15] (Paragon) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S0 Lbd; system32\DRIVERS\Lbd.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [x] U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-01 17:55 - 2013-10-01 17:56 - 01086873 _____ (Farbar) C:\Users\Brigitte\Downloads\FRST (1).exe 2013-10-01 17:45 - 2013-10-01 17:48 - 00000000 ____D C:\AdwCleaner 2013-10-01 17:45 - 2013-10-01 17:45 - 01045226 _____ C:\Users\Brigitte\Downloads\adwcleaner.exe 2013-10-01 17:33 - 2013-10-01 17:34 - 00033777 _____ C:\Users\Brigitte\Downloads\Addition.txt 2013-10-01 17:30 - 2013-10-01 17:30 - 00000000 ____D C:\FRST 2013-10-01 17:29 - 2013-10-01 17:29 - 01086873 _____ (Farbar) C:\Users\Brigitte\Downloads\FRST.exe 2013-10-01 16:56 - 2013-10-01 16:56 - 00011754 _____ C:\Windows\PFRO.log 2013-10-01 11:50 - 2013-10-01 11:50 - 00001664 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-10-01 11:47 - 2013-10-01 11:50 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-10-01 11:47 - 2013-10-01 11:50 - 00000000 ____D C:\Program Files\iTunes 2013-10-01 11:47 - 2013-10-01 11:47 - 00000000 ____D C:\Program Files\iPod 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default\AppData\Roaming\Apple Computer 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default\AppData\Local\Apple Computer 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Apple Computer 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default User\AppData\Local\Apple Computer 2013-10-01 10:51 - 2013-10-01 10:51 - 00000000 ____D C:\Users\Brigitte\AppData\Local\Secunia PSI 2013-10-01 10:50 - 2013-10-01 10:50 - 00000000 ____D C:\Program Files\Secunia 2013-10-01 10:49 - 2013-10-01 10:49 - 03272136 _____ (Secunia) C:\Users\Brigitte\Downloads\PSISetup.exe 2013-09-30 22:37 - 2013-09-30 22:39 - 00001859 _____ C:\DelFix.txt 2013-09-30 22:37 - 2013-09-30 22:37 - 00000000 ____D C:\Windows\ERUNT 2013-09-30 22:13 - 2013-09-30 22:13 - 07912440 _____ (Adobe Systems Inc.) C:\Users\Brigitte\Downloads\Shockwave_Installer_Slim.exe 2013-09-30 22:12 - 2013-09-30 22:12 - 00000000 ____D C:\ProgramData\Oracle 2013-09-30 22:12 - 2013-09-30 22:12 - 00000000 ____D C:\Program Files\Common Files\Java 2013-09-30 22:12 - 2013-09-30 22:10 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-09-30 22:11 - 2013-09-30 22:10 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-09-30 22:11 - 2013-09-30 22:10 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-09-30 22:11 - 2013-09-30 22:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-09-30 22:08 - 2013-09-30 22:08 - 00913832 _____ (Oracle Corporation) C:\Users\Brigitte\Downloads\jre-7u40-windows-i586-iftw.exe 2013-09-30 00:26 - 2013-09-30 00:26 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\Malwarebytes 2013-09-30 00:25 - 2013-09-30 00:25 - 00000906 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-30 00:25 - 2013-09-30 00:25 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-30 00:25 - 2013-09-30 00:25 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-30 00:25 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-30 00:23 - 2013-09-30 00:23 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Brigitte\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-30 00:16 - 2013-09-30 00:17 - 90353424 _____ (Microsoft Corporation) C:\Users\Brigitte\Downloads\msert.exe 2013-09-29 12:26 - 2013-09-29 12:26 - 00000816 _____ C:\Users\Public\Desktop\Slim 310NB.lnk 2013-09-29 12:09 - 2013-09-29 12:09 - 00000000 ____D C:\Program Files\Hewlett-Packard 2013-09-29 12:09 - 2013-09-29 12:09 - 00000000 ____D C:\cpqsystem 2013-09-29 12:05 - 2013-09-29 12:05 - 00000000 ____D C:\Program Files\LSI SoftModem 2013-09-29 12:03 - 2013-09-29 12:03 - 00000000 ____D C:\Windows\Dell 2013-09-29 11:47 - 2013-10-01 16:37 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\Skype 2013-09-29 11:46 - 2013-09-29 11:46 - 00001880 _____ C:\Users\Public\Desktop\Skype.lnk 2013-09-29 11:46 - 2013-09-29 11:46 - 00000000 ___RD C:\Program Files\Skype 2013-09-29 11:46 - 2013-09-29 11:46 - 00000000 ____D C:\Program Files\Common Files\Skype 2013-09-29 11:45 - 2013-09-29 11:46 - 00000000 ____D C:\ProgramData\Skype 2013-09-29 11:44 - 2013-09-29 11:44 - 32776560 _____ (Skype Technologies S.A.) C:\Users\Brigitte\Downloads\SkypeSetupFull.exe 2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\Users\Brigitte\Documents\Freemium Driver Utilities 2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\ProgramData\DriversGalaxy 2013-09-29 11:42 - 2013-09-29 11:42 - 00675952 _____ C:\Users\Brigitte\Downloads\SkypeSetup.exe 2013-09-29 11:31 - 2013-09-29 11:31 - 00000000 ____D C:\Users\Brigitte\AppData\Local\DriverTuner 2013-09-28 08:38 - 2013-09-28 08:38 - 00000000 ____D C:\Users\Brigitte\AppData\Local\Adobe_Systems_Incorporate 2013-09-28 08:37 - 2013-09-30 23:06 - 00000000 ____D C:\Users\Brigitte\Documents\My Digital Editions 2013-09-28 08:34 - 2013-09-28 08:34 - 05892496 _____ (Adobe Systems Incorporated) C:\Users\Brigitte\Downloads\ADE_2.0_Installer.exe 2013-09-19 10:42 - 2013-09-19 10:42 - 00000105 _____ C:\prefs.js 2013-09-19 10:42 - 2013-09-19 10:42 - 00000000 ____D C:\Users\Brigitte\AppData\Local\adawarebp 2013-09-19 10:42 - 2013-09-19 10:42 - 00000000 ____D C:\ProgramData\Downloaded Installations 2013-09-19 10:42 - 2013-09-19 10:42 - 00000000 ____D C:\Program Files\Toolbar Cleaner 2013-09-19 10:22 - 2013-09-19 10:38 - 00013560 _____ (GFI Software) C:\Windows\system32\Drivers\gfibto.sys 2013-09-12 20:25 - 2013-09-14 11:30 - 00000000 ____D C:\Users\Brigitte\Documents\Fritzbox 2013-09-12 19:35 - 2013-09-12 19:35 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRITZ!Box 2013-09-12 19:35 - 2013-09-12 19:34 - 00105728 _____ (AVM Berlin) C:\Windows\system32\Drivers\avmaura.sys 2013-09-12 18:01 - 2013-09-12 18:01 - 00127356 _____ C:\Users\Brigitte\Downloads\speedportw900v.export 2013-09-12 09:25 - 2013-07-31 12:30 - 12335104 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-12 09:25 - 2013-07-31 12:05 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-12 09:25 - 2013-07-31 12:00 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-12 09:25 - 2013-07-31 11:53 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-12 09:25 - 2013-07-31 11:52 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-09-12 09:25 - 2013-07-31 11:52 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-12 09:25 - 2013-07-31 11:51 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-09-12 09:25 - 2013-07-31 11:49 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-12 09:25 - 2013-07-31 11:48 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-12 09:25 - 2013-07-31 11:48 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-09-12 09:25 - 2013-07-31 11:48 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-09-12 09:25 - 2013-07-31 11:47 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-12 09:25 - 2013-07-31 11:46 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-12 09:25 - 2013-07-31 11:45 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-12 09:25 - 2013-07-31 11:45 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-09-12 09:25 - 2013-07-31 11:42 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-11 13:26 - 2013-09-11 13:40 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\PhotoScape 2013-09-11 13:26 - 2013-09-11 13:26 - 00000828 _____ C:\Users\Brigitte\Desktop\PhotoScape.lnk 2013-09-11 13:26 - 2013-09-11 13:26 - 00000000 ____D C:\Program Files\PhotoScape 2013-09-11 13:14 - 2013-08-08 03:45 - 02049536 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-11 13:14 - 2013-07-16 06:35 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll 2013-09-11 12:56 - 2013-09-11 12:56 - 00004266 _____ C:\Users\Brigitte\AppData\Local\recently-used.xbel 2013-09-09 09:04 - 2013-09-09 09:05 - 08164297 _____ (J. Rathlev ) C:\Users\Brigitte\Documents\pb-setup-5.4.0802.exe 2013-09-09 08:47 - 2013-09-11 12:58 - 00000000 ____D C:\Users\Brigitte\.gimp-2.8 2013-09-07 06:33 - 2013-09-07 08:48 - 96496803 _____ C:\Windows\system32\Ḭˆ 2013-09-02 16:07 - 2013-09-02 16:07 - 00000000 ____D C:\Users\Brigitte\AppData\Local\FUJIdirekt Bestellsoftware 2013-09-02 16:02 - 2013-09-02 16:02 - 00000918 _____ C:\Users\Public\Desktop\FUJIdirekt Bestellsoftware.lnk 2013-09-02 16:01 - 2013-09-02 16:07 - 00000000 ____D C:\Program Files\FUJIdirekt Bestellsoftware 2013-09-02 16:01 - 2013-09-02 16:01 - 00000000 ____D C:\ProgramData\FUJIdirekt Bestellsoftware 2013-09-02 15:57 - 2013-09-02 15:59 - 125481064 _____ ( ) C:\Users\Brigitte\Downloads\FUJIdirekt.exe 2013-09-01 14:13 - 2013-09-01 14:13 - 00000000 ____D C:\Users\Brigitte\AppData\Local\webkit 2013-09-01 14:09 - 2013-09-11 12:56 - 00000000 ____D C:\Users\Brigitte\AppData\Local\gtk-2.0 2013-09-01 14:09 - 2013-09-01 14:09 - 00000000 ____D C:\Users\Brigitte\.thumbnails 2013-09-01 14:03 - 2013-09-01 14:03 - 00000000 ____D C:\Users\Brigitte\AppData\Local\gegl-0.2 2013-09-01 13:53 - 2013-09-01 13:54 - 90116160 _____ (The GIMP Team ) C:\Users\Brigitte\Downloads\gimp-2.8.6-setup.exe ==================== One Month Modified Files and Folders ======= 2013-10-01 17:56 - 2013-10-01 17:55 - 01086873 _____ (Farbar) C:\Users\Brigitte\Downloads\FRST (1).exe 2013-10-01 17:55 - 2013-08-27 22:19 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-01 17:50 - 2012-06-01 19:03 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-01 17:50 - 2008-10-16 06:57 - 00000416 ____H C:\Windows\Tasks\SupBackGroundTask.job 2013-10-01 17:50 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-01 17:50 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-01 17:50 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-01 17:49 - 2012-07-23 09:18 - 01405576 _____ C:\Windows\WindowsUpdate.log 2013-10-01 17:49 - 2007-08-08 00:21 - 00000012 _____ C:\Windows\bthservsdp.dat 2013-10-01 17:49 - 2006-11-02 15:01 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-10-01 17:48 - 2013-10-01 17:45 - 00000000 ____D C:\AdwCleaner 2013-10-01 17:45 - 2013-10-01 17:45 - 01045226 _____ C:\Users\Brigitte\Downloads\adwcleaner.exe 2013-10-01 17:34 - 2013-10-01 17:33 - 00033777 _____ C:\Users\Brigitte\Downloads\Addition.txt 2013-10-01 17:30 - 2013-10-01 17:30 - 00000000 ____D C:\FRST 2013-10-01 17:29 - 2013-10-01 17:29 - 01086873 _____ (Farbar) C:\Users\Brigitte\Downloads\FRST.exe 2013-10-01 17:26 - 2012-06-04 11:48 - 00001132 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3801056569-3724766084-3036744875-1003UA.job 2013-10-01 17:11 - 2012-06-01 19:03 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-01 16:56 - 2013-10-01 16:56 - 00011754 _____ C:\Windows\PFRO.log 2013-10-01 16:37 - 2013-09-29 11:47 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\Skype 2013-10-01 13:21 - 2007-09-30 10:32 - 00000000 ____D C:\Users\Brigitte 2013-10-01 11:50 - 2013-10-01 11:50 - 00001664 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-10-01 11:50 - 2013-10-01 11:47 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-10-01 11:50 - 2013-10-01 11:47 - 00000000 ____D C:\Program Files\iTunes 2013-10-01 11:47 - 2013-10-01 11:47 - 00000000 ____D C:\Program Files\iPod 2013-10-01 11:47 - 2008-08-04 13:34 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default\AppData\Roaming\Apple Computer 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default\AppData\Local\Apple Computer 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Apple Computer 2013-10-01 11:43 - 2013-10-01 11:43 - 00000000 ____D C:\Users\Default User\AppData\Local\Apple Computer 2013-10-01 11:31 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default 2013-10-01 10:51 - 2013-10-01 10:51 - 00000000 ____D C:\Users\Brigitte\AppData\Local\Secunia PSI 2013-10-01 10:50 - 2013-10-01 10:50 - 00000000 ____D C:\Program Files\Secunia 2013-10-01 10:49 - 2013-10-01 10:49 - 03272136 _____ (Secunia) C:\Users\Brigitte\Downloads\PSISetup.exe 2013-10-01 08:26 - 2012-06-04 11:48 - 00001080 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3801056569-3724766084-3036744875-1003Core.job 2013-09-30 23:06 - 2013-09-28 08:37 - 00000000 ____D C:\Users\Brigitte\Documents\My Digital Editions 2013-09-30 23:06 - 2008-12-31 14:18 - 00000000 ____D C:\Program Files\Adobe 2013-09-30 22:39 - 2013-09-30 22:37 - 00001859 _____ C:\DelFix.txt 2013-09-30 22:37 - 2013-09-30 22:37 - 00000000 ____D C:\Windows\ERUNT 2013-09-30 22:14 - 2008-09-13 17:06 - 00000000 ____D C:\Windows\system32\Adobe 2013-09-30 22:13 - 2013-09-30 22:13 - 07912440 _____ (Adobe Systems Inc.) C:\Users\Brigitte\Downloads\Shockwave_Installer_Slim.exe 2013-09-30 22:12 - 2013-09-30 22:12 - 00000000 ____D C:\ProgramData\Oracle 2013-09-30 22:12 - 2013-09-30 22:12 - 00000000 ____D C:\Program Files\Common Files\Java 2013-09-30 22:10 - 2013-09-30 22:12 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-09-30 22:10 - 2013-09-30 22:11 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-09-30 22:10 - 2013-09-30 22:11 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-09-30 22:10 - 2013-09-30 22:11 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-09-30 22:10 - 2012-06-01 11:22 - 00868264 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-09-30 22:10 - 2010-05-13 10:52 - 00790440 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-09-30 22:08 - 2013-09-30 22:08 - 00913832 _____ (Oracle Corporation) C:\Users\Brigitte\Downloads\jre-7u40-windows-i586-iftw.exe 2013-09-30 22:03 - 2007-12-22 19:56 - 00000000 ____D C:\Users\Brigitte\AppData\Local\Adobe 2013-09-30 16:21 - 2012-12-30 08:53 - 00000000 ____D C:\Program Files\Uniblue 2013-09-30 13:28 - 2012-11-07 15:50 - 00000000 ____D C:\Windows\Downloaded Installations 2013-09-30 12:41 - 2007-12-05 18:45 - 00000000 ____D C:\Users\Brigitte\Documents\Unzipped 2013-09-30 08:46 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\SchCache 2013-09-30 08:46 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Help 2013-09-30 00:44 - 2012-12-30 08:52 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\DVDVideoSoft 2013-09-30 00:44 - 2009-03-23 14:56 - 00000000 ____D C:\Program Files\Unlocker 2013-09-30 00:26 - 2013-09-30 00:26 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\Malwarebytes 2013-09-30 00:25 - 2013-09-30 00:25 - 00000906 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-30 00:25 - 2013-09-30 00:25 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-30 00:25 - 2013-09-30 00:25 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-30 00:23 - 2013-09-30 00:23 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Brigitte\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-30 00:17 - 2013-09-30 00:16 - 90353424 _____ (Microsoft Corporation) C:\Users\Brigitte\Downloads\msert.exe 2013-09-29 17:49 - 2011-02-12 16:00 - 00000000 ____D C:\Windows\pss 2013-09-29 12:26 - 2013-09-29 12:26 - 00000816 _____ C:\Users\Public\Desktop\Slim 310NB.lnk 2013-09-29 12:26 - 2007-11-24 17:27 - 00000000 ____D C:\Program Files\Common Files\snpstd3 2013-09-29 12:09 - 2013-09-29 12:09 - 00000000 ____D C:\Program Files\Hewlett-Packard 2013-09-29 12:09 - 2013-09-29 12:09 - 00000000 ____D C:\cpqsystem 2013-09-29 12:05 - 2013-09-29 12:05 - 00000000 ____D C:\Program Files\LSI SoftModem 2013-09-29 12:03 - 2013-09-29 12:03 - 00000000 ____D C:\Windows\Dell 2013-09-29 11:46 - 2013-09-29 11:46 - 00001880 _____ C:\Users\Public\Desktop\Skype.lnk 2013-09-29 11:46 - 2013-09-29 11:46 - 00000000 ___RD C:\Program Files\Skype 2013-09-29 11:46 - 2013-09-29 11:46 - 00000000 ____D C:\Program Files\Common Files\Skype 2013-09-29 11:46 - 2013-09-29 11:45 - 00000000 ____D C:\ProgramData\Skype 2013-09-29 11:44 - 2013-09-29 11:44 - 32776560 _____ (Skype Technologies S.A.) C:\Users\Brigitte\Downloads\SkypeSetupFull.exe 2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\Users\Brigitte\Documents\Freemium Driver Utilities 2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\ProgramData\DriversGalaxy 2013-09-29 11:42 - 2013-09-29 11:42 - 00675952 _____ C:\Users\Brigitte\Downloads\SkypeSetup.exe 2013-09-29 11:31 - 2013-09-29 11:31 - 00000000 ____D C:\Users\Brigitte\AppData\Local\DriverTuner 2013-09-28 08:38 - 2013-09-28 08:38 - 00000000 ____D C:\Users\Brigitte\AppData\Local\Adobe_Systems_Incorporate 2013-09-28 08:34 - 2013-09-28 08:34 - 05892496 _____ (Adobe Systems Incorporated) C:\Users\Brigitte\Downloads\ADE_2.0_Installer.exe 2013-09-21 06:53 - 2013-08-27 22:19 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-09-21 06:53 - 2012-01-20 15:18 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-09-19 13:35 - 2013-05-02 09:01 - 00002098 _____ C:\Users\Brigitte\Desktop\Google Chrome.lnk 2013-09-19 10:42 - 2013-09-19 10:42 - 00000105 _____ C:\prefs.js 2013-09-19 10:42 - 2013-09-19 10:42 - 00000000 ____D C:\Users\Brigitte\AppData\Local\adawarebp 2013-09-19 10:42 - 2013-09-19 10:42 - 00000000 ____D C:\ProgramData\Downloaded Installations 2013-09-19 10:42 - 2013-09-19 10:42 - 00000000 ____D C:\Program Files\Toolbar Cleaner 2013-09-19 10:42 - 2008-03-18 15:45 - 00000000 ____D C:\Program Files\Lavasoft 2013-09-19 10:38 - 2013-09-19 10:22 - 00013560 _____ (GFI Software) C:\Windows\system32\Drivers\gfibto.sys 2013-09-19 07:05 - 2009-04-21 08:03 - 00007858 _____ C:\Windows\system32\dmlg.dat 2013-09-18 11:57 - 2012-10-13 14:52 - 00000384 _____ C:\Windows\Tasks\Ad-Aware Update (Weekly).job 2013-09-14 11:30 - 2013-09-12 20:25 - 00000000 ____D C:\Users\Brigitte\Documents\Fritzbox 2013-09-14 09:08 - 2007-08-08 01:20 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-12 22:15 - 2012-06-01 19:02 - 00000000 ____D C:\Users\Brigitte\AppData\Local\Deployment 2013-09-12 19:35 - 2013-09-12 19:35 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRITZ!Box 2013-09-12 19:34 - 2013-09-12 19:35 - 00105728 _____ (AVM Berlin) C:\Windows\system32\Drivers\avmaura.sys 2013-09-12 18:03 - 2007-10-23 15:13 - 00000000 ____D C:\Users\Brigitte\Documents\Speedport sicherung 2013-09-12 18:01 - 2013-09-12 18:01 - 00127356 _____ C:\Users\Brigitte\Downloads\speedportw900v.export 2013-09-12 12:51 - 2006-11-02 14:47 - 00420384 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 09:14 - 2013-07-11 09:03 - 00000000 ____D C:\Windows\system32\MRT 2013-09-12 08:53 - 2006-11-02 12:24 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-09-11 13:40 - 2013-09-11 13:26 - 00000000 ____D C:\Users\Brigitte\AppData\Roaming\PhotoScape 2013-09-11 13:26 - 2013-09-11 13:26 - 00000828 _____ C:\Users\Brigitte\Desktop\PhotoScape.lnk 2013-09-11 13:26 - 2013-09-11 13:26 - 00000000 ____D C:\Program Files\PhotoScape 2013-09-11 12:58 - 2013-09-09 08:47 - 00000000 ____D C:\Users\Brigitte\.gimp-2.8 2013-09-11 12:56 - 2013-09-11 12:56 - 00004266 _____ C:\Users\Brigitte\AppData\Local\recently-used.xbel 2013-09-11 12:56 - 2013-09-01 14:09 - 00000000 ____D C:\Users\Brigitte\AppData\Local\gtk-2.0 2013-09-09 09:05 - 2013-09-09 09:04 - 08164297 _____ (J. Rathlev ) C:\Users\Brigitte\Documents\pb-setup-5.4.0802.exe 2013-09-09 09:05 - 2013-07-02 07:06 - 00000877 _____ C:\Users\Public\Desktop\Personal Backup 5.lnk 2013-09-09 09:05 - 2013-07-02 07:06 - 00000000 ____D C:\Program Files\Personal Backup 5 2013-09-09 09:05 - 2006-11-02 12:33 - 01718870 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-09 07:44 - 2010-04-11 10:57 - 00000000 ____D C:\Users\Brigitte\Documents\Brigitte 2013-09-07 08:48 - 2013-09-07 06:33 - 96496803 _____ C:\Windows\system32\Ḭˆ 2013-09-06 06:28 - 2013-02-24 14:04 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-09-06 06:28 - 2013-02-24 14:04 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-09-05 12:36 - 2007-12-05 18:23 - 00000000 ____D C:\Users\Brigitte\Documents\Telekom 2013-09-02 18:25 - 2008-09-04 00:15 - 00000000 ____D C:\Users\Brigitte\.jordan 2013-09-02 16:07 - 2013-09-02 16:07 - 00000000 ____D C:\Users\Brigitte\AppData\Local\FUJIdirekt Bestellsoftware 2013-09-02 16:07 - 2013-09-02 16:01 - 00000000 ____D C:\Program Files\FUJIdirekt Bestellsoftware 2013-09-02 16:02 - 2013-09-02 16:02 - 00000918 _____ C:\Users\Public\Desktop\FUJIdirekt Bestellsoftware.lnk 2013-09-02 16:01 - 2013-09-02 16:01 - 00000000 ____D C:\ProgramData\FUJIdirekt Bestellsoftware 2013-09-02 15:59 - 2013-09-02 15:57 - 125481064 _____ ( ) C:\Users\Brigitte\Downloads\FUJIdirekt.exe 2013-09-01 14:13 - 2013-09-01 14:13 - 00000000 ____D C:\Users\Brigitte\AppData\Local\webkit 2013-09-01 14:09 - 2013-09-01 14:09 - 00000000 ____D C:\Users\Brigitte\.thumbnails 2013-09-01 14:03 - 2013-09-01 14:03 - 00000000 ____D C:\Users\Brigitte\AppData\Local\gegl-0.2 2013-09-01 13:54 - 2013-09-01 13:53 - 90116160 _____ (The GIMP Team ) C:\Users\Brigitte\Downloads\gimp-2.8.6-setup.exe Files to move or delete: ==================== C:\Users\Brigitte\AppData\Roaming\desktop.ini Some content of TEMP: ==================== C:\Users\Brigitte\AppData\Local\Temp\DeltaTB.exe C:\Users\Brigitte\AppData\Local\Temp\Quarantine.exe C:\Users\Brigitte\AppData\Local\Temp\secuniasi2581677952182163719.dll C:\Users\Brigitte\AppData\Local\Temp\tmpB5AD.tmp.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-01 17:06 ==================== End Of Log ============================ --- --- --- |
01.10.2013, 17:01 | #26 |
/// TB-Ausbilder | Softwareupdater.Ui.exe und Malwarebytes Anti-Malware So, jetzt sollte es wieder in Ordnung sein.
__________________ cheers, Leo |
01.10.2013, 17:07 | #27 |
| Softwareupdater.Ui.exe und Malwarebytes Anti-Malware Mehr nicht, applaus und danke ;-)))) Ich vermeide download, versprochen LG BrigittePS kann ich quarantäne malwaebytes und avira löschen ??? |
01.10.2013, 17:21 | #28 |
/// TB-Ausbilder | Softwareupdater.Ui.exe und Malwarebytes Anti-Malware Quarantäne kannst du löschen, wenn du willst. Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Ich bekomme somit keine Benachrichtigung mehr über neue Antworten. Solltest du das Thema erneut brauchen, schicke mir bitte eine PM und wir machen hier weiter. Jeder andere bitte diese Anleitung lesen und einen eigenen Thread erstellen.
__________________ cheers, Leo |
Themen zu Softwareupdater.Ui.exe und Malwarebytes Anti-Malware |
.dll, administrator, adware.clicker, adware.packed.ranver, anti-malware, autostart, b.exe, freemium, gelöscht, install.exe, löschen, malwarebytes, pup.chromepasswordtool, pup.optional., pup.optional.babylon.a, pup.optional.crossrider, pup.optional.crossrider.a, pup.optional.delta.a, pup.optional.netdata.a, pup.optional.opencandy, pup.optional.plushd.a, pup.optional.smartbar.a, pup.optional.snapdo, smartbar, uninstall.exe, unlocker |