![]() |
|
Plagegeister aller Art und deren Bekämpfung: Softwareupdater.UI.exeWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() | ![]() Softwareupdater.UI.exe Softwareupdater.UI.exe eingefangen, wahrscheinlich, als ich diesen hässlichen Windowsupdate-Fehler (Code 80246008) fixen wollte. FRST-Scan 1 (ohne Optional Scan Addition.txt) ergibt für FRST.txt: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013 Ran by 7Schläfer (ATTENTION: The logged in user is not administrator) on NOTEBOOK on 16-10-2013 15:15:16 Running from C:\Users\7Schläfer\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (The Eraser Project) C:\Program Files\Eraser\Eraser.exe () C:\Program Files\HP\HP UT\bin\hppusg.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (TrueCrypt Foundation) C:\Program Files\TrueCrypt\TrueCrypt.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (The Privoxy team - www.privoxy.org) C:\Program Files\Privoxy\privoxy.exe (Hauppauge Computer Works, Inc.) C:\Program Files\WinTV\WinTV7\WinTVTray.exe (Dropbox, Inc.) C:\Users\7Schläfer\AppData\Roaming\Dropbox\bin\Dropbox.exe (OpenOffice.org) C:\Program Files\program\soffice.exe (OpenOffice.org) C:\Program Files\program\soffice.bin (Microsoft Corporation) C:\Windows\system32\conime.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\system32\sdclt.exe (Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe (Dominik Reichl) C:\Program Files\KeePass Password Safe 2\KeePass.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12005080 2013-08-28] (Realtek Semiconductor) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [174872 2007-02-12] (Intel Corporation) HKLM\...\Run: [BrStsMon00] - C:\Program Files\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.) HKLM\...\Run: [Eraser] - C:\PROGRA~1\Eraser\Eraser.exe [980920 2012-05-22] (The Eraser Project) HKLM\...\Run: [KeePass 2 PreLoad] - C:\Program Files\KeePass Password Safe 2\KeePass.exe [2010624 2013-07-20] (Dominik Reichl) HKLM\...\Run: [IS CfgWiz] - C:\Program Files\HP\HP UT\bin\hppusg.exe [36864 2008-05-07] () HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM\...\Run: [Kernel and Hardware Abstraction Layer] - C:\Windows\KHALMNPR.EXE [76304 2008-02-29] (Logicool, Inc.) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [KeyScrambler] - C:\Program Files\KeyScrambler\keyscrambler.exe [508048 2013-07-14] (QFX Software Corporation) HKLM\...\RunOnce: [*Restore] - C:\Windows\System32\rstrui.exe /runonce [318464 2008-01-19] (Microsoft Corporation) HKLM\...\RunOnce: [*WerKernelReporting] - %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq [217088 2009-04-11] (Microsoft Corporation) HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [68856 2008-02-23] (Google Inc.) HKCU\...\Run: [ISUSPM Startup] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [249856 2005-08-11] (Macrovision Corporation) HKCU\...\Run: [TrueCrypt] - C:\Program Files\TrueCrypt\TrueCrypt.exe [1516496 2012-11-10] (TrueCrypt Foundation) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation) HKCU\...\Policies\system: [LogonHoursAction] 2 HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 MountPoints2: E - E:\AutoRun.exe MountPoints2: F - F:\AutoRun.exe MountPoints2: {00c5fc83-f8ad-11e0-a35b-00030d7b9df9} - F:\AutoRun.exe MountPoints2: {00c5fc89-f8ad-11e0-a35b-001e101f23a4} - F:\AutoRun.exe MountPoints2: {232397b4-3bc0-11e1-a313-001e101f859f} - F:\AutoRun.exe MountPoints2: {61912a9b-32cb-11e3-9290-00030d7b9df9} - E:\AutoRun.exe MountPoints2: {ba13a240-667c-11de-8a81-00030d7b9df9} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\RECYCLER\Lcass.exe MountPoints2: {bdcab74c-1946-11e2-9740-001e101f7f74} - H:\AutoRun.exe MountPoints2: {c64045be-0169-11e1-bec0-001e101f8aaa} - F:\AutoRun.exe MountPoints2: {d97281b9-30d6-11e1-8c1f-001e101fb45e} - E:\AutoRun.exe MountPoints2: {fdf5093b-0459-11e1-9b3a-001e101fb4df} - F:\AutoRun.exe Startup: C:\Users\7Schläfer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\7Schläfer\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\7Schläfer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\program\quickstart.exe () SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x30478D781211CC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd URLSearchHook: (No Name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - No File URLSearchHook: (No Name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File SearchScopes: HKLM - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://isearch.avg.com/search?cid={972DB1B1-0E03-4403-92D8-16CA42FDBB9A}&mid=531b0adbda4a420fa8e441549aec129c-a1f0e60b1fe61c34d50fea7c058b5375f596e4b9&lang=en&ds=or011&pr=sa&d=2012-06-24 03:50:52&v=12.2.5.32&sap=dsp&q={searchTerms} SearchScopes: HKCU - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://int.search-results.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=NIS&chn=retail&geo=DE&ver=19 SearchScopes: HKCU - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = hxxp://de.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_de&p={searchTerms} BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (Safer Networking Limited) BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll (Symantec Corporation) BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: WebEnhance - {814664b0-d93b-4da6-9216-722c56179397} - C:\Program Files\WebEnhance\webenhance.dll (WebEnhance) BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll (Symantec Corporation) Toolbar: HKCU - No Name - {A057A204-BACC-4D26-9990-79A187E2698E} - No File Toolbar: HKCU - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default FF DefaultSearchEngine: Startpage FF Homepage: https://startpage.com/do/mypage.pl?prf=5ca07097e7f5522e50fdce583ba87d4e FF Keyword.URL: https://isearch.avg.com/search?cid={972DB1B1-0E03-4403-92D8-16CA42FDBB9A}&mid=531b0adbda4a420fa8e441549aec129c-a1f0e60b1fe61c34d50fea7c058b5375f596e4b9&lang=en&ds=or011&pr=sa&d=2012-06-24 03:50:52&v=12.2.5.32&sap=ku&q= FF NetworkProxy: "http", "127.0.0.1" FF NetworkProxy: "http_port", 8118 FF NetworkProxy: "no_proxies_on", "" FF NetworkProxy: "socks_remote_dns", true FF NetworkProxy: "ssl", "127.0.0.1" FF NetworkProxy: "ssl_port", 8118 FF NetworkProxy: "type", 1 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @cambridgesoft.com/Chem3D,version=13.0 - C:\Program Files\CambridgeSoft\ChemOffice2012\Chem3D\npChem3DPlugin.dll (CambridgeSoft Corp.) FF Plugin: @cambridgesoft.com/ChemDraw,version=13.0 - C:\Program Files\CambridgeSoft\ChemOffice2012\ChemDraw\npcdp32.dll (CambridgeSoft Corp.) FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\7Schläfer\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF SearchPlugin: C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\searchplugins\icqplugin.xml FF SearchPlugin: C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\searchplugins\safesearch.xml FF SearchPlugin: C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\searchplugins\startpage-https---deutsch.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\safesearch.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\bug489729@alice0775 FF Extension: No Name - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\counterpixel@jabubo.de FF Extension: Deutsches Wörterbuch - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\de-DE@dictionaries.addons.mozilla.org FF Extension: Dictionary Switcher - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\dictionary-switcher@design-noir.de FF Extension: British English Dictionary - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\en-GB@dictionaries.addons.mozilla.org FF Extension: HTTPS-Everywhere - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\https-everywhere@eff.org FF Extension: Flashblock - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} FF Extension: ChatZilla - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} FF Extension: CookieCuller - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460} FF Extension: CookieSafe - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\{9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD} FF Extension: firefox - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\firefox@ghostery.com.xpi FF Extension: optout - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\optout@google.com.xpi FF Extension: passifox - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\passifox@hanhuy.com.xpi FF Extension: trackmenot - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\trackmenot@mrl.nyu.edu.xpi FF Extension: No Name - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A}.xpi FF Extension: No Name - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\{70F241F6-52AB-4D45-993E-C1C09920095B}.xpi FF Extension: No Name - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF Extension: No Name - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}.xpi FF Extension: No Name - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}.xpi FF Extension: No Name - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi FF Extension: No Name - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi FF Extension: No Name - C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\Extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\IPSFF FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\coFFPlgn\ FF HKLM\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF HKLM\...\Firefox\Extensions: [{38e9e285-5266-4fe2-b5b5-c14c29b0cd45}] - C:\Program Files\WebEnhance\webenhance.xpi FF Extension: No Name - C:\Program Files\WebEnhance\webenhance.xpi ========================== Services (Whitelisted) ================= S3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.) R2 CVPND; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [1528608 2008-06-19] (Cisco Systems, Inc.) R2 DirMngr; C:\Program Files\GNU\GnuPG\dirmngr.exe [224256 2011-03-02] () R2 HauppaugeTVServer; C:\Program Files\WinTV\TVServer\HauppaugeTVServer.exe [581632 2013-05-15] (Hauppauge Computer Works) R2 iphlpsvc; C:\Windows\System32\svchost.exe [21504 2008-01-19] (Microsoft Corporation) R2 lmhosts; C:\Windows\system32\svchost.exe [21504 2008-01-19] (Microsoft Corporation) R2 NIS; C:\Program Files\Norton Internet Security\Engine\19.9.1.14\diMaster.dll [309688 2012-04-13] (Symantec Corporation) R2 NlaSvc; C:\Windows\System32\svchost.exe [21504 2008-01-19] (Microsoft Corporation) R2 nsi; C:\Windows\system32\svchost.exe [21504 2008-01-19] (Microsoft Corporation) S3 OpcEnum; C:\Windows\system32\OpcEnum.exe [98304 2005-11-25] (OPC Foundation) R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S4 SystemStoreService; C:\Program Files\SoftwareUpdater\SystemStore.exe [296448 2013-10-11] () R2 TestHandler; C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe [204800 2006-12-08] (Fujitsu Siemens Computers) S3 VBMQANEGRY; C:\Users\Admin\AppData\Local\Temp\VBMQANEGRY.exe [x] ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [278728 2008-08-09] () R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20131002.001\BHDrvx86.sys [1097304 2013-10-02] (Symantec Corporation) S2 BrukerIR; C:\Windows\System32\Drivers\BrukerIR.sys [19384 2008-12-12] () R1 cbfs3; C:\Windows\system32\drivers\cbfs3.sys [299024 2012-04-09] (EldoS Corporation) R1 ccSet_NIS; C:\Windows\system32\drivers\NIS\1309010.00E\ccSetx86.sys [132768 2012-06-07] (Symantec Corporation) R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation) S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.) R2 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306299 2008-06-19] (Cisco Systems, Inc.) R3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [125328 2008-03-29] (Deterministic Networks, Inc.) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376920 2013-10-05] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [108120 2013-08-27] (Symantec Corporation) S3 ewsercd; C:\Windows\System32\DRIVERS\ewsercd.sys [100224 2010-03-18] (Huawei Technologies Co., Ltd.) S3 hcw95bda; C:\Windows\System32\Drivers\hcw95bda.sys [573952 2013-04-22] (Hauppauge Computer Works, Inc.) S3 hcw95rc; C:\Windows\System32\DRIVERS\hcw95rc.sys [16000 2013-04-22] (Hauppauge Computer Works, Inc.) R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\IPSDefs\20131014.001\IDSvix86.sys [392792 2013-10-08] (Symantec Corporation) S4 JRAID; C:\Windows\system32\drivers\jraid.sys [48256 2007-06-13] (JMicron Technology Corp.) S3 k750bus; C:\Windows\System32\DRIVERS\k750bus.sys [55216 2005-02-11] (MCCI) S3 k750mdfl; C:\Windows\System32\DRIVERS\k750mdfl.sys [6576 2005-02-11] (MCCI) S3 k750mdm; C:\Windows\System32\DRIVERS\k750mdm.sys [89872 2005-02-11] (MCCI) S3 k750mgmt; C:\Windows\System32\DRIVERS\k750mgmt.sys [81728 2005-02-11] (MCCI) S3 k750obex; C:\Windows\System32\DRIVERS\k750obex.sys [79488 2005-02-11] (MCCI) R3 KeyScrambler; C:\Windows\System32\drivers\keyscrambler.sys [209016 2013-05-31] (QFX Software Corporation) R3 LHidFilt; C:\Windows\System32\DRIVERS\LHidFilt.Sys [35472 2008-02-29] (Logicool, Inc.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25416 2008-08-09] () R3 LMouFilt; C:\Windows\System32\DRIVERS\LMouFilt.Sys [37008 2008-02-29] (Logicool, Inc.) R3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [29072 2008-02-29] (Logicool, Inc.) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\VirusDefs\20131015.032\NAVENG.SYS [93272 2013-10-05] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\VirusDefs\20131015.032\NAVEX15.SYS [1612376 2013-10-05] (Symantec Corporation) R3 NETwLv32; C:\Windows\System32\DRIVERS\NETwLv32.sys [6639616 2010-10-07] (Intel Corporation) S3 Rockusb; C:\Windows\System32\DRIVERS\rockusb.sys [45040 2012-10-23] (Fuzhou Rockchip Electronics Co,Ltd.) R0 sfsync04; C:\Windows\System32\drivers\sfsync04.sys [59520 2009-02-03] (Protection Technology (StarForce)) R0 sfvfs02; C:\Windows\System32\drivers\sfvfs02.sys [83320 2007-02-08] (Protection Technology (StarForce)) R3 SRTSP; C:\Windows\System32\Drivers\NIS\1309010.00E\SRTSP.SYS [574112 2012-07-06] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NIS\1309010.00E\SRTSPX.SYS [32928 2012-07-06] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NIS\1309010.00E\SYMDS.SYS [340088 2011-07-25] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NIS\1309010.00E\SYMEFA.SYS [924320 2012-05-22] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [141944 2012-03-27] (Symantec Corporation) R1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [35960 2011-11-24] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NIS\1309010.00E\Ironx86.SYS [149624 2012-04-18] (Symantec Corporation) R1 SYMTDIv; C:\Windows\System32\Drivers\NIS\1309010.00E\SYMTDIV.SYS [345208 2012-04-18] (Symantec Corporation) S4 viamraid; C:\Windows\system32\drivers\viamraid.sys [102912 2006-11-08] (VIA Technologies inc,.ltd) R2 WIBUKEY; C:\Windows\System32\DRIVERS\WibuKey.sys [72704 2009-02-26] (WIBU-SYSTEMS AG) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] U2 wuaserv; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-16 15:00 - 2013-10-15 17:48 - 01087213 _____ (Farbar) C:\Users\7Schläfer\Desktop\FRST.exe 2013-10-16 14:34 - 2013-10-16 14:34 - 00000022 _____ C:\Windows\S.dirmngr 2013-10-15 18:32 - 2013-10-15 18:32 - 00000000 ____D C:\FRST 2013-10-12 11:32 - 2013-10-12 11:34 - 35289176 _____ (Dropbox, Inc.) C:\Users\7Schläfer\Downloads\Dropbox 2.4.2.exe 2013-10-12 02:18 - 2013-10-12 02:18 - 00001350 ____R C:\Windows\MeineTraffic_Uninstall.in 2013-10-12 02:18 - 2013-10-12 02:18 - 00000676 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meine Traffic.lnk 2013-10-12 02:18 - 2013-10-12 02:18 - 00000646 _____ C:\Users\Admin\Desktop\Meine Traffic.lnk 2013-10-12 02:18 - 2013-10-12 02:18 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meine Traffic 2013-10-12 02:18 - 2013-10-12 02:18 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Meine Traffic 2013-10-12 02:18 - 2013-10-12 02:18 - 00000000 ____D C:\Program Files\MT 2013-10-12 02:18 - 2010-06-01 14:30 - 00331136 _____ (Mirko Böer) C:\Windows\MTrUn.EXE 2013-10-12 02:17 - 2013-10-12 02:17 - 00000000 ____D C:\Users\7Schläfer\Downloads\mt(1) 2013-10-12 02:14 - 2013-10-12 02:14 - 00815948 _____ C:\Users\7Schläfer\Downloads\mt(1).zip 2013-10-12 01:22 - 2009-12-08 20:19 - 00113664 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbnet.sys 2013-10-12 01:22 - 2009-12-07 19:53 - 00103168 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys 2013-10-12 01:22 - 2009-10-12 15:22 - 00101120 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbdev.sys 2013-10-12 01:22 - 2007-08-09 04:06 - 00023424 _____ (Huawei Tech. Co., Ltd.) C:\Windows\system32\Drivers\ewdcsc.sys 2013-10-11 23:35 - 2013-10-11 23:35 - 00000182 _____ C:\Windows\WinTVInstall.LOG 2013-10-11 23:35 - 2013-10-11 23:35 - 00000000 ____D C:\Hauppauge 2013-10-11 23:35 - 2013-04-22 09:37 - 00573952 _____ (Hauppauge Computer Works, Inc.) C:\Windows\system32\Drivers\hcw95bda.sys 2013-10-11 23:35 - 2013-04-22 09:37 - 00016000 _____ (Hauppauge Computer Works, Inc.) C:\Windows\system32\Drivers\hcw95rc.sys 2013-10-11 22:14 - 2013-10-11 22:58 - 146116472 _____ C:\Users\7Schläfer\Downloads\WinTV7_CD_2.8a.exe 2013-10-11 17:34 - 2013-10-11 17:38 - 00000000 ____D C:\Windows\system32\MRT 2013-10-11 17:27 - 2013-09-22 12:29 - 12336128 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-11 17:27 - 2013-09-22 12:22 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-11 17:27 - 2013-09-22 12:22 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-11 17:27 - 2013-09-22 12:14 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-10-11 17:27 - 2013-09-22 12:13 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-11 17:27 - 2013-09-22 12:13 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-11 17:27 - 2013-09-22 12:12 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-10-11 17:27 - 2013-09-22 12:09 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-11 17:27 - 2013-09-22 12:08 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-10-11 17:27 - 2013-09-22 12:07 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-11 17:27 - 2013-09-22 12:06 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-10-11 17:27 - 2013-09-22 12:05 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-11 17:27 - 2013-09-22 12:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-11 17:27 - 2013-09-22 12:03 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-11 17:27 - 2013-09-22 12:03 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-10-11 17:27 - 2013-09-22 11:59 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-11 17:07 - 2013-08-27 04:47 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-10-11 17:07 - 2013-08-27 04:47 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-10-11 17:07 - 2013-08-27 04:47 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-10-11 17:07 - 2013-08-27 04:47 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-10-11 17:07 - 2013-08-27 03:52 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-10-11 17:07 - 2013-08-27 03:50 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-10-11 17:07 - 2013-08-27 03:32 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-10-11 17:07 - 2013-08-27 03:28 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-10-11 17:07 - 2013-08-27 03:28 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-10-11 17:07 - 2013-07-17 21:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-10-11 17:07 - 2013-05-02 06:04 - 00443904 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-10-11 17:07 - 2013-05-02 06:03 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\printcom.dll 2013-10-11 17:07 - 2013-03-08 05:52 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-10-11 17:07 - 2012-11-08 05:48 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2013-10-11 17:06 - 2013-08-29 09:36 - 02050048 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-11 17:06 - 2013-08-02 06:09 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-10-11 17:06 - 2013-08-01 05:16 - 00638400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-11 17:06 - 2013-08-01 04:49 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2013-10-11 17:06 - 2013-07-10 11:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-10-11 17:06 - 2013-07-09 14:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-11 17:06 - 2013-07-08 06:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-10-11 17:06 - 2013-07-08 06:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-11 17:06 - 2013-07-05 06:53 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-11 17:06 - 2013-07-04 06:21 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-11 17:06 - 2013-06-29 04:07 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-11 17:06 - 2013-06-29 04:07 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-11 17:06 - 2013-06-29 04:07 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-11 17:06 - 2013-06-29 04:06 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-11 17:06 - 2013-06-27 01:01 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-11 17:06 - 2013-06-15 15:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll 2013-10-11 17:06 - 2013-06-15 13:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-10-11 17:06 - 2013-04-24 06:00 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2013-10-11 17:06 - 2013-04-24 03:46 - 00812544 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-10-11 17:06 - 2013-04-17 14:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-10-11 17:06 - 2013-03-09 05:45 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-10-11 17:06 - 2013-03-09 03:28 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-10-11 17:06 - 2013-03-03 21:07 - 01082232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2013-10-11 17:06 - 2011-05-05 15:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-11 17:05 - 2013-07-20 12:44 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-11 17:05 - 2013-07-16 06:35 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll 2013-10-11 17:05 - 2013-07-12 11:04 - 00073344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys 2013-10-11 17:05 - 2013-07-03 04:10 - 00025472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-11 17:05 - 2013-06-04 06:16 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-11 17:05 - 2013-06-04 03:49 - 00293376 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-11 17:05 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-10-11 17:05 - 2013-03-08 05:53 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-10-11 17:05 - 2013-02-12 03:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2013-10-11 16:57 - 2013-07-08 06:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-10-11 16:57 - 2013-07-08 06:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-10-11 16:57 - 2013-07-08 06:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-10-11 16:57 - 2013-07-08 06:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-10-11 16:48 - 2013-10-11 16:48 - 01273160 _____ C:\Users\Admin\Downloads\KeyScrambler_Setup.exe 2013-10-11 16:20 - 2009-02-26 11:05 - 00398336 _____ (Intel(R) Corporation) C:\Windows\system32\TVWizudlg.exe 2013-10-11 16:20 - 2009-02-26 11:04 - 00140288 _____ () C:\Windows\system32\igfxtvcx.dll 2013-10-11 16:02 - 2013-10-11 16:02 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_LUsbFilt_01005.Wdf 2013-10-11 16:00 - 2008-02-29 11:12 - 00029072 _____ (Logicool, Inc.) C:\Windows\system32\Drivers\LUsbFilt.sys 2013-10-11 15:55 - 2013-10-11 16:20 - 00000000 ____D C:\Windows\system32\Lang 2013-10-11 15:12 - 2013-08-05 11:50 - 00053248 _____ (Windows XP Bundled build C-Centric Single User) C:\Windows\system32\CSVer.dll 2013-10-11 15:08 - 2013-10-11 15:08 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_LMouFilt_01005.Wdf 2013-10-11 15:08 - 2008-02-29 12:00 - 01419232 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01005.dll 2013-10-11 15:08 - 2008-02-29 11:12 - 00076304 _____ (Logicool, Inc.) C:\Windows\KHALMNPR.Exe 2013-10-11 15:08 - 2008-02-29 11:12 - 00037008 _____ (Logicool, Inc.) C:\Windows\system32\Drivers\LMouFilt.Sys 2013-10-11 15:08 - 2008-02-29 11:12 - 00035472 _____ (Logicool, Inc.) C:\Windows\system32\Drivers\LHidFilt.Sys 2013-10-11 15:07 - 2013-10-11 15:07 - 00000000 ____H C:\ProgramData\DP45977C.lfl 2013-10-11 15:06 - 2013-10-11 15:06 - 00000000 ____D C:\Program Files\Realtek 2013-10-11 15:00 - 2013-10-11 15:00 - 00001736 _____ C:\Windows\DPINST.LOG 2013-10-11 14:51 - 2013-10-11 21:41 - 00000000 ____D C:\ProgramData\DriversGalaxy 2013-10-11 14:51 - 2013-10-11 14:51 - 00000000 ____D C:\Users\Admin\Documents\Freemium Driver Utilities 2013-10-11 14:50 - 2013-10-11 14:51 - 00000000 ____D C:\Program Files\SoftwareUpdater 2013-10-11 14:50 - 2013-10-11 14:50 - 00000000 ____D C:\Program Files\WebEnhance 2013-10-11 14:50 - 2013-10-11 14:50 - 00000000 ____D C:\Program Files\Covus Freemium 2013-10-11 14:49 - 2013-10-11 23:48 - 00000000 ____D C:\ProgramData\Package Cache 2013-10-11 14:49 - 2013-10-11 14:49 - 00000169 _____ C:\Users\Admin\Desktop\Zalando.url 2013-10-11 14:48 - 2013-10-11 14:49 - 00000000 ____D C:\Users\Admin\AppData\Local\DownloadGuide 2013-10-11 14:48 - 2013-10-11 14:48 - 00444400 _____ C:\Users\Admin\Downloads\DLG_free-driver-scout_chip_de-DE.exe 2013-10-11 14:44 - 2013-10-11 14:44 - 00000000 ____D C:\ProgramData\Uniblue 2013-10-11 14:42 - 2013-10-11 14:43 - 05712008 _____ (Uniblue Systems Ltd ) C:\Users\Admin\Downloads\driverscanner.exe 2013-10-11 13:59 - 2013-10-11 13:59 - 01528184 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\GenuineCheck.exe 2013-09-30 14:27 - 2013-10-11 19:03 - 00000000 ____D C:\Program Files\Mozilla Thunderbird 2013-09-30 14:26 - 2013-10-11 14:00 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-25 20:20 - 2013-09-25 20:20 - 00008288 _____ C:\Users\7Schläfer\.recently-used.xbel 2013-09-20 22:07 - 2013-09-20 22:07 - 00002552 _____ C:\{60A54E3E-9BF6-4BF4-954C-880ACD5E123E} ==================== One Month Modified Files and Folders ======= 2013-10-16 15:07 - 2012-12-23 03:08 - 00019086 _____ C:\Users\7Schläfer\Documents\NewDatabase.kdbx 2013-10-16 15:04 - 2006-11-02 12:33 - 01470534 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-16 14:50 - 2012-03-02 12:31 - 00000000 ____D C:\Users\7Schläfer\AppData\Roaming\Dropbox 2013-10-16 14:38 - 2008-02-22 22:02 - 01182379 _____ C:\Windows\WindowsUpdate.log 2013-10-16 14:34 - 2013-10-16 14:34 - 00000022 _____ C:\Windows\S.dirmngr 2013-10-16 14:33 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-16 14:33 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-16 14:33 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-16 01:30 - 2006-11-02 15:01 - 00032534 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-10-16 01:28 - 2012-12-23 03:01 - 00000000 ____D C:\Users\7Schläfer\AppData\Roaming\KeePass 2013-10-16 01:24 - 2012-06-15 15:13 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-15 18:32 - 2013-10-15 18:32 - 00000000 ____D C:\FRST 2013-10-15 18:22 - 2010-04-24 12:20 - 00000000 ____D C:\Windows\pss 2013-10-15 17:48 - 2013-10-16 15:00 - 01087213 _____ (Farbar) C:\Users\7Schläfer\Desktop\FRST.exe 2013-10-15 14:52 - 2011-08-21 18:20 - 00000000 ____D C:\Users\7Schläfer\AppData\Roaming\gnupg 2013-10-14 17:33 - 2013-04-22 00:26 - 2137468297 _____ C:\Windows\MEMORY.DMP 2013-10-14 17:33 - 2009-10-22 21:39 - 00000000 ____D C:\Windows\Minidump 2013-10-13 16:22 - 2010-04-08 15:09 - 00000370 _____ C:\Windows\Tasks\Ad-Aware Update (Weekly).job 2013-10-13 12:16 - 2010-02-06 17:12 - 00001052 _____ C:\Windows\Tasks\Google Software Updater.job 2013-10-12 11:37 - 2013-08-20 02:19 - 00000000 ____D C:\Users\7Schläfer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-10-12 11:34 - 2013-10-12 11:32 - 35289176 _____ (Dropbox, Inc.) C:\Users\7Schläfer\Downloads\Dropbox 2.4.2.exe 2013-10-12 10:13 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-10-12 02:18 - 2013-10-12 02:18 - 00001350 ____R C:\Windows\MeineTraffic_Uninstall.in 2013-10-12 02:18 - 2013-10-12 02:18 - 00000676 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meine Traffic.lnk 2013-10-12 02:18 - 2013-10-12 02:18 - 00000646 _____ C:\Users\Admin\Desktop\Meine Traffic.lnk 2013-10-12 02:18 - 2013-10-12 02:18 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meine Traffic 2013-10-12 02:18 - 2013-10-12 02:18 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Meine Traffic 2013-10-12 02:18 - 2013-10-12 02:18 - 00000000 ____D C:\Program Files\MT 2013-10-12 02:17 - 2013-10-12 02:17 - 00000000 ____D C:\Users\7Schläfer\Downloads\mt(1) 2013-10-12 02:14 - 2013-10-12 02:14 - 00815948 _____ C:\Users\7Schläfer\Downloads\mt(1).zip 2013-10-12 01:22 - 2011-10-25 16:46 - 00000000 ____D C:\Program Files\Mobile Partner 2013-10-12 01:22 - 2008-02-23 00:12 - 00000000 ____D C:\Users\Admin 2013-10-11 23:49 - 2013-03-19 22:24 - 00000401 _____ C:\Windows\ODBCINST.INI 2013-10-11 23:49 - 2010-03-08 15:49 - 00001153 _____ C:\Windows\ODBC.INI 2013-10-11 23:48 - 2013-10-11 14:49 - 00000000 ____D C:\ProgramData\Package Cache 2013-10-11 23:47 - 2013-03-19 22:24 - 00037639 _____ C:\Windows\Irremote.ini 2013-10-11 23:47 - 2013-03-19 22:23 - 00000000 ____D C:\Users\Public\WinTV 2013-10-11 23:47 - 2013-03-19 22:23 - 00000000 ____D C:\Program Files\WinTV 2013-10-11 23:46 - 2013-03-19 22:23 - 00000000 ____D C:\ProgramData\Hauppauge 2013-10-11 23:46 - 2008-02-23 19:13 - 00000000 ____D C:\Program Files\InstallShield Installation Information 2013-10-11 23:41 - 2013-03-19 22:22 - 00007390 _____ C:\Windows\HCWPNP.INI 2013-10-11 23:40 - 2013-03-19 22:20 - 00094911 _____ C:\hcwDriverInstall.txt 2013-10-11 23:35 - 2013-10-11 23:35 - 00000182 _____ C:\Windows\WinTVInstall.LOG 2013-10-11 23:35 - 2013-10-11 23:35 - 00000000 ____D C:\Hauppauge 2013-10-11 23:35 - 2013-03-19 22:19 - 00000000 ____D C:\Users\Admin\AppData\Local\autorun 2013-10-11 22:58 - 2013-10-11 22:14 - 146116472 _____ C:\Users\7Schläfer\Downloads\WinTV7_CD_2.8a.exe 2013-10-11 22:22 - 2008-07-29 15:40 - 00000000 ___RD C:\Users\7Schläfer\Desktop\tools 2013-10-11 22:22 - 2008-06-22 20:08 - 00000664 _____ C:\Users\7Schläfer\Documents\grstyles.stl 2013-10-11 21:41 - 2013-10-11 14:51 - 00000000 ____D C:\ProgramData\DriversGalaxy 2013-10-11 21:41 - 2009-10-26 13:24 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-11 21:41 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\spool 2013-10-11 21:41 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\registration 2013-10-11 20:50 - 2012-07-30 11:05 - 00030332 _____ C:\Windows\PFRO.log 2013-10-11 19:03 - 2013-09-30 14:27 - 00000000 ____D C:\Program Files\Mozilla Thunderbird 2013-10-11 18:26 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache 2013-10-11 18:08 - 2006-11-02 14:47 - 00431184 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-11 18:05 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer 2013-10-11 18:05 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal 2013-10-11 18:05 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE 2013-10-11 18:04 - 2013-05-28 20:20 - 00004922 _____ C:\Windows\setupact.log 2013-10-11 17:38 - 2013-10-11 17:34 - 00000000 ____D C:\Windows\system32\MRT 2013-10-11 16:48 - 2013-10-11 16:48 - 01273160 _____ C:\Users\Admin\Downloads\KeyScrambler_Setup.exe 2013-10-11 16:48 - 2009-11-18 18:05 - 00000000 ____D C:\Program Files\KeyScrambler 2013-10-11 16:20 - 2013-10-11 15:55 - 00000000 ____D C:\Windows\system32\Lang 2013-10-11 16:20 - 2010-03-21 00:11 - 00000000 ____D C:\Program Files\Intel 2013-10-11 16:02 - 2013-10-11 16:02 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_LUsbFilt_01005.Wdf 2013-10-11 15:11 - 2008-02-28 22:12 - 00000000 ____D C:\Intel 2013-10-11 15:08 - 2013-10-11 15:08 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_LMouFilt_01005.Wdf 2013-10-11 15:07 - 2013-10-11 15:07 - 00000000 ____H C:\ProgramData\DP45977C.lfl 2013-10-11 15:06 - 2013-10-11 15:06 - 00000000 ____D C:\Program Files\Realtek 2013-10-11 15:06 - 2008-01-16 06:29 - 00000000 ____D C:\Windows\system32\RTCOM 2013-10-11 15:00 - 2013-10-11 15:00 - 00001736 _____ C:\Windows\DPINST.LOG 2013-10-11 14:51 - 2013-10-11 14:51 - 00000000 ____D C:\Users\Admin\Documents\Freemium Driver Utilities 2013-10-11 14:51 - 2013-10-11 14:50 - 00000000 ____D C:\Program Files\SoftwareUpdater 2013-10-11 14:50 - 2013-10-11 14:50 - 00000000 ____D C:\Program Files\WebEnhance 2013-10-11 14:50 - 2013-10-11 14:50 - 00000000 ____D C:\Program Files\Covus Freemium 2013-10-11 14:49 - 2013-10-11 14:49 - 00000169 _____ C:\Users\Admin\Desktop\Zalando.url 2013-10-11 14:49 - 2013-10-11 14:48 - 00000000 ____D C:\Users\Admin\AppData\Local\DownloadGuide 2013-10-11 14:48 - 2013-10-11 14:48 - 00444400 _____ C:\Users\Admin\Downloads\DLG_free-driver-scout_chip_de-DE.exe 2013-10-11 14:47 - 2010-03-20 17:52 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Uniblue 2013-10-11 14:47 - 2010-03-20 17:48 - 00000000 ____D C:\Program Files\Uniblue 2013-10-11 14:44 - 2013-10-11 14:44 - 00000000 ____D C:\ProgramData\Uniblue 2013-10-11 14:43 - 2013-10-11 14:42 - 05712008 _____ (Uniblue Systems Ltd ) C:\Users\Admin\Downloads\driverscanner.exe 2013-10-11 14:00 - 2013-09-30 14:26 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-11 14:00 - 2010-04-08 15:45 - 00000000 ____D C:\Program Files\Norton Utilities 14 2013-10-11 14:00 - 2009-01-13 09:36 - 00000000 ____D C:\Users\7Schläfer\Desktop\communication 2013-10-11 13:59 - 2013-10-11 13:59 - 01528184 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\GenuineCheck.exe 2013-10-09 01:25 - 2012-04-04 12:43 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-10-09 01:25 - 2011-05-19 15:51 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-10-06 17:53 - 2010-04-08 14:07 - 00000000 ____D C:\Users\Public\Downloads\Norton 2013-10-06 17:53 - 2010-03-24 14:20 - 00000000 ____D C:\ProgramData\Norton 2013-10-01 17:51 - 2012-04-27 15:47 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-09-26 02:19 - 2006-11-02 12:24 - 78106760 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-09-26 01:18 - 2008-06-14 19:19 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Skype 2013-09-25 21:23 - 2011-03-02 15:52 - 00000000 ____D C:\Users\Admin\AppData\Local\CrashDumps 2013-09-25 20:30 - 2008-12-12 01:56 - 00000000 ___HD C:\Users\7Schläfer\.gimp-2.6 2013-09-25 20:20 - 2013-09-25 20:20 - 00008288 _____ C:\Users\7Schläfer\.recently-used.xbel 2013-09-25 20:20 - 2008-02-23 12:16 - 00000000 ____D C:\Users\7Schläfer 2013-09-25 14:47 - 2008-12-12 02:05 - 00000000 ____D C:\Users\7Schläfer\AppData\Roaming\gtk-2.0 2013-09-24 11:10 - 2012-10-31 13:07 - 00000000 ____D C:\Users\7Schläfer\AppData\Roaming\.purple 2013-09-22 12:29 - 2013-10-11 17:27 - 12336128 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-22 12:22 - 2013-10-11 17:27 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-22 12:22 - 2013-10-11 17:27 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-22 12:14 - 2013-10-11 17:27 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-09-22 12:13 - 2013-10-11 17:27 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-22 12:13 - 2013-10-11 17:27 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-22 12:12 - 2013-10-11 17:27 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-09-22 12:09 - 2013-10-11 17:27 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-22 12:08 - 2013-10-11 17:27 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-09-22 12:07 - 2013-10-11 17:27 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-22 12:06 - 2013-10-11 17:27 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-09-22 12:05 - 2013-10-11 17:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-22 12:03 - 2013-10-11 17:27 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-22 12:03 - 2013-10-11 17:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-22 12:03 - 2013-10-11 17:27 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-09-22 11:59 - 2013-10-11 17:27 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-21 20:50 - 2012-11-10 03:13 - 00000000 ____D C:\Users\7Schläfer\AppData\Local\Eraser 6 2013-09-20 22:07 - 2013-09-20 22:07 - 00002552 _____ C:\{60A54E3E-9BF6-4BF4-954C-880ACD5E123E} 2013-09-17 03:31 - 2010-03-26 16:05 - 00000000 ____D C:\Users\7Schläfer\AppData\Local\CrashDumps Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\AskSLib.dll C:\Users\Admin\AppData\Local\Temp\CLI.exe C:\Users\Admin\AppData\Local\Temp\GenericWndApi.dll C:\Users\Admin\AppData\Local\Temp\jre-6u38-windows-i586-iftw.exe C:\Users\Admin\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe C:\Users\Admin\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe C:\Users\Admin\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Admin\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Admin\AppData\Local\Temp\pdf24-creator-update.exe C:\Users\Admin\AppData\Local\Temp\SkypeSetup.exe C:\Users\Admin\AppData\Local\Temp\TrekstorDevice.dll C:\Users\Admin\AppData\Local\Temp\UNINSTALL.EXE C:\Users\Admin\AppData\Local\Temp\Update.exe C:\Users\Admin\AppData\Local\Temp\vcredist_x86.exe C:\Users\7Schläfer\AppData\Local\Temp\0a50e25a83046228c11dcaa7eeed09bb.exe C:\Users\7Schläfer\AppData\Local\Temp\DataCard_Setup.exe C:\Users\7Schläfer\AppData\Local\Temp\DivXSetup.exe C:\Users\7Schläfer\AppData\Local\Temp\drm_dialogs.dll C:\Users\7Schläfer\AppData\Local\Temp\drm_dyndata_7370014.dll C:\Users\7Schläfer\AppData\Local\Temp\Foxit Updater.exe C:\Users\7Schläfer\AppData\Local\Temp\proxy_util_w32.dll C:\Users\7Schläfer\AppData\Local\Temp\ResetDevice.exe C:\Users\7Schläfer\AppData\Local\Temp\SkypeSetup.exe C:\Users\7Schläfer\AppData\Local\Temp\vlc-2.0.2-win32.exe C:\Users\7Schläfer\AppData\Local\Temp\vlc-2.0.6-win32.exe C:\Users\7Schläfer\AppData\Local\Temp\vlc-2.0.8-win32.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== End Of Log ============================ FRST-Scan 2 (mit Optional Scan Addition.txt) ergibt für Addition.txt: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 03-10-2013 Ran by 7Schläfer at 2013-10-16 15:44:05 Running from C:\Users\7Schläfer\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Norton Internet Security (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Internet Security (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} ==================== Installed Programs ====================== 32 Bit HP CIO Components Installer (Version: 2.1.4) ACD/Labs Software in C:\Program Files\ACDFREE11\ (Version: v11.00, FREE) Adobe Digital Editions Adobe Flash Player 11 Plugin (Version: 11.9.900.117) Adobe Flash Player 9 ActiveX (Version: 9) Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8) ALTools Update (Version: v11.4.28.1) ALZip 8.51 (Version: v8.51) Amazon Kindle Apple Software Update (Version: 2.1.1.116) Battlecruiser Millennium FREEWARE (Version: 1.09.03) Broken Sword 2.5 CambridgeSoft ChemBioDraw Ultra 13.0 (Version: 13.0) Capture Setup CCleaner (Version: 2.30) Celtx (2.7) (Version: 2.7 (de)) C-evo Chinese Simplified Fonts Support For Adobe Reader 9 (Version: 9.0.0) Cisco AnyConnect VPN Client (Version: 2.5.3055) Cisco Systems VPN Client 5.0.03.0560 (Version: 5.0.3) Citavi (Version: 3.2.0.0) Civilization: Call To Power Core Temp 1.0 RC4 (Version: 1.0) CustomerResearchQFolder (Version: 1.00.0000) DAVE 2.0 (Version: 2.0) Dev-C++ 5 beta 9 release (4.9.9.2) Diablo II Diamond 3 (Version: 3.0.0) DivX Version Checker (Version: 7.1.0.9) DP Hash 1.0 (Version: 1.0) Dropbox (HKCU Version: 2.4.2) DSL Connection Manager (Version: 1.1.1116) enCIFer (Version: 1.4) Eraser 6.0.10.2620 (Version: 6.0.2620) FirstSteps Diagnostics (Version: 1.00) Foxit Reader (Version: 5.4.3.920) Free Audio CD Burner version 1.2 Free Driver Scout (Version: 1.0.0.0) FSCLounge (Version: 1.0.0) GIMP 2.6.3 Google Earth (Version: 4.3.7284.3916) Google Updater (Version: 2.4.2432.1652) Gothic II Gpg4win (2.1.0) (Version: 2.1.0) GPL Ghostscript 8.62 GPL Ghostscript Fonts GSview 4.9 Guitar Pro 3.0 Guitar Pro 5.2 Hauppauge WinTV 7 (Version: v7.0.31161 (CD 2.8a)) HijackThis 2.0.2 (Version: 2.0.2) HL-2240 (Version: 1.0.6.0) HP Customer Participation Program 10.0 (Version: 10.0) HP LaserJet P2050 Series 2.0 (Version: 2.0) HP Update (Version: 4.000.007.003) hppFonts (Version: 001.001.00061) hppManualsP2050 (Version: 000.002.00033) hppPQVideoP2050 (Version: 000.002.00033) hppQFolderP2050 (Version: 1.00.0000) hppTLBXFXP2050 (Version: 000.105.00098) hppusgP2050 (Version: 000.000.00006) hpzTLBXFX (Version: 004.014.00150) ICQ7.5 (HKCU Version: 7.5) ICQ7.6 (HKCU Version: 7.6) Inkscape 0.48.2 (Version: 0.48.2) Intel(R) Graphics Media Accelerator Driver Intel(R) Matrix Storage Manager Intel(R) TV Wizard Japanese Fonts Support For Adobe Reader 9 (Version: 9.0.0) Java 7 Update 25 (Version: 7.0.250) Java Auto Updater (Version: 2.1.9.5) Java(TM) 6 Update 3 (Version: 1.6.0.30) Java(TM) 6 Update 5 (Version: 1.6.0.50) Java(TM) 6 Update 7 (Version: 1.6.0.70) KeePass Password Safe 2.23 KeyScrambler (Version: 3.2.0.3) Malwarebytes' Anti-Malware MarketResearch (Version: 100.0.170.000) Meine Traffic 2.20 MestReNova LITE 5.2.5-5780 (Version: 5.2.5-5780) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft PowerPoint Viewer (Version: 14.0.4763.1000) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (Version: 9.0.21022.218) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (Version: 11.0.51106.1) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (Version: 11.0.51106) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (Version: 11.0.51106) Microsoft Works (Version: 9.7.0621) MiKTeX 2.9 (Version: 2.9) Miro (Version: 5.0.4) Mobile Partner (Version: 16.001.06.03.52) Motorola SM56 Speakerphone Modem (Version: 6.12.25.06) Mozilla Firefox 24.0 (x86 de) (Version: 24.0) Mozilla Maintenance Service (Version: 24.0) Mozilla Thunderbird 24.0 (x86 de) (Version: 24.0) Mozilla Thunderbird 24.0.1 (x86 de) (HKCU Version: 24.0.1) MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) MTX (Version: 1.0.0) Nero 7 Essentials (Version: 7.02.5851) Norton Bootable Recovery Tool Wizard (Version: 3.0.0.66) Norton Internet Security (Version: 19.9.1.14) Norton Utilities (Version: 14.5) NVIDIA WDM Drivers OPC Core Components 2.00 Redistributable (Version: 2.00.230) OpenAL OpenOffice.org 3.4.1 (Version: 3.41.9593) OPUS_65 (Version: 6.5.97) Ortep for Windows v2.02 (Version: 2.02) PDF24 Creator 5.2.0 PDFCreator (Version: 0.9.5) PDF-Viewer (Version: 2.0.41.5) PDF-XChange Shell Extentions (Version: 2.0.41.5) Pidgin (Version: 2.10.6) pidgin-otr 4.0.0-1 (Version: 4.0.0-1) POV-Ray for Windows v3.6.1c (Version: 3.6) POV-Ray for Windows v3.62 (Version: 3.62) Prince of Persia T2T Privateer Privoxy (remove only) QuickTime (Version: 7.71.80.42) Realtek High Definition Audio Driver (Version: 6.0.1.7026) Sacred SciFinder Scholar 2007 SciFinder Scholar Toolbar Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002) (Version: 1.0.0) Sid Meier's Civilization IV Colonization (Version: 1.01) Simple Sudoku 4.2 Skype Click to Call (Version: 5.9.9216) Skype™ 6.6 (Version: 6.6.106) Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0) SpinWorks_3 (Version: 3.1.6) Spybot - Search & Destroy (Version: 1.6.2) TeXnicCenter Version 1 Beta 7.50 (Version: Version 1 Beta 7.50) TrekStor eReaderSuite TrueCrypt (Version: 7.1a) UFO:AI 2.4 (Version: 2.4) Uniblue ProcessScanner Uninstall WinGX (HKCU Version: 1.80.05) Unity Web Player (HKCU Version: ) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3) Update Manager (Version: 4.60) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0) Visual C++ 2008 x86 Runtime - (v9.0.30729) (Version: 9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 (Version: 9.0.30729.01) VLC media player 2.0.8 (Version: 2.0.8) WebEnhance WebReg (Version: 100.0.170.000) WIBU-KEY Setup (WIBU-KEY Remove) (Version: Version 5.20a of 2006-Dec-01 (Setup)) Widelands Build14 (Version: Widelands Build14) Windows Media Player Firefox Plugin (Version: 1.0.0.8) Wuala (HKCU Version: 1.0.428.0) Wuala CBFS (Version: 3.2.107.0) Xvid 1.1.3 final uninstall (Version: 1.1) Zak McKracken - Between Time and Space ==================== Restore Points ========================= Could not list Restore Points. ==================== Hosts content: ========================== 2012-08-26 21:02 - 2012-08-26 21:06 - 00356813 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1001namen.com 127.0.0.1 1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 100sexlinks.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 123haustiereundmehr.com 127.0.0.1 www.123haustiereundmehr.com 127.0.0.1 123moviedownload.com 127.0.0.1 www.123moviedownload.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: C:\Windows\Tasks\Ad-Aware Update (Weekly).job => ? Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ? Task: C:\Windows\Tasks\Google Software Updater.job => ? ==================== Loaded Modules (whitelisted) ============= 2011-03-02 17:18 - 2011-03-02 17:18 - 00656384 _____ () C:\Program Files\GNU\GnuPG\gpgex.dll 2008-05-07 10:38 - 2008-05-07 10:38 - 00057344 _____ () C:\Program Files\HP\HP UT\bin\HPUsageTracking.dll 2008-05-07 10:38 - 2008-05-07 10:38 - 00069632 _____ () C:\Program Files\HP\HP UT\bin\HPTools.dll 2008-05-07 10:38 - 2008-05-07 10:38 - 00114688 _____ () C:\Program Files\HP\HP UT\bin\HPToolkit.dll 2008-05-07 10:38 - 2008-05-07 10:38 - 00040960 _____ () C:\Program Files\HP\HP UT\bin\Enumeration.dll 2010-11-14 14:25 - 2010-11-14 14:25 - 00086528 _____ () C:\Program Files\Privoxy\mgwz.dll 2013-03-19 22:23 - 2013-05-15 13:15 - 00025600 _____ () C:\Program Files\WinTV\TVServer\HauppaugeTVServerps.dll 2013-03-13 22:48 - 2013-03-13 22:48 - 24978944 _____ () C:\Users\7Schläfer\AppData\Roaming\Dropbox\bin\libcef.dll 2012-08-10 16:51 - 2012-08-10 16:51 - 00985088 _____ () C:\Program Files\program\libxml2.dll 2013-09-30 14:26 - 2013-09-30 14:27 - 03279768 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2013-09-30 14:27 - 2013-10-11 19:03 - 03008112 _____ () C:\Program Files\Mozilla Thunderbird\mozjs.dll 2013-09-30 14:27 - 2013-10-11 19:03 - 00158832 _____ () C:\Program Files\Mozilla Thunderbird\NSLDAP32V60.dll 2013-09-30 14:27 - 2013-10-11 19:03 - 00023152 _____ () C:\Program Files\Mozilla Thunderbird\NSLDAPPR32V60.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:8AB6C1D7 AlternateDataStreams: C:\ProgramData\TEMP:C8B8CEBD AlternateDataStreams: C:\ProgramData\TEMP:D287FACF AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2 ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Cisco Systems VPN Adapter Description: Cisco Systems VPN Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: CVirtA Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Cisco AnyConnect VPN Virtual Miniport Adapter for Windows Description: Cisco AnyConnect VPN Virtual Miniport Adapter for Windows Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (10/16/2013 00:00:07 AM) (Source: Windows Backup) (User: ) Description: Die Dateisicherung ist aufgrund eines Fehlers beim Schreiben in das Sicherungsziel J:\ fehlgeschlagen. Fehler: Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (10/15/2013 07:08:27 PM) (Source: Software Licensing Service) (User: ) Description: Fehler beim Starten des Softwarelizenzierungsdienstes. hr=0x80070002, [2, 4] Error: (10/15/2013 06:30:40 PM) (Source: Software Licensing Service) (User: ) Description: Fehler beim Starten des Softwarelizenzierungsdienstes. hr=0x80070002, [2, 4] Error: (10/15/2013 00:00:07 AM) (Source: Windows Backup) (User: ) Description: Die Dateisicherung ist aufgrund eines Fehlers beim Schreiben in das Sicherungsziel J:\ fehlgeschlagen. Fehler: Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (10/14/2013 05:39:19 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\7Schläfer\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\RF8QBPRM.DEFAULT\SAFEBROWSING-TO_DELETE> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (10/14/2013 05:39:19 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\7Schläfer\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\RF8QBPRM.DEFAULT\SAFEBROWSING-BACKUP> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (10/14/2013 00:00:22 AM) (Source: Windows Backup) (User: ) Description: Die Dateisicherung ist aufgrund eines Fehlers beim Schreiben in das Sicherungsziel J:\ fehlgeschlagen. Fehler: Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (10/13/2013 09:03:49 AM) (Source: Windows Backup) (User: ) Description: Die Dateisicherung ist aufgrund eines Fehlers beim Schreiben in das Sicherungsziel J:\ fehlgeschlagen. Fehler: Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (10/12/2013 01:22:48 AM) (Source: System Restore) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts auf dem Volume (Prozess = C:\Windows\system32\DrvInst.exe "4" "0" "C:\Users\Admin\{2874574f-9a9a-4162-91fb-8c7e3afb82fb}\ewusbdev.inf" "0" "6b443b833" "00000534" "WinSta0\Default" "00000524" "208" "C:\Program Files\Mobile Partner\driver\WinVista"; Beschreibung = Gerätetreiber-Paketinstallation: HUAWEI Incorporated Anschlüsse (COM & LPT); Hr = 0x8000ffff). Error: (10/12/2013 01:22:48 AM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "CoCreateInstance" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070422. Vorgang: VSS-Server wird instanziiert System errors: ============= Error: (10/16/2013 02:34:52 PM) (Source: Dhcp) (User: ) Description: Die IP-Adresslease 192.168.0.101 für die Netzwerkkarte mit der Netzwerkadresse 001B77E0FB33 wurde durch den DHCP-Server 192.168.0.1 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet). Error: (10/16/2013 02:34:12 PM) (Source: Service Control Manager) (User: ) Description: cdrom Error: (10/16/2013 02:34:09 PM) (Source: Service Control Manager) (User: ) Description: Bruker FTIR Driver%%87 Error: (10/15/2013 10:11:03 PM) (Source: Service Control Manager) (User: ) Description: 30000vpnagent Error: (10/15/2013 10:11:03 PM) (Source: Service Control Manager) (User: ) Description: Bruker FTIR Driver%%87 Error: (10/15/2013 07:25:58 PM) (Source: Dhcp) (User: ) Description: Die IP-Adresslease 10.112.153.138 für die Netzwerkkarte mit der Netzwerkadresse 001E101F8ED0 wurde durch den DHCP-Server 10.114.253.105 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet). Error: (10/15/2013 07:22:29 PM) (Source: Dhcp) (User: ) Description: Die IP-Adresslease 10.109.56.195 für die Netzwerkkarte mit der Netzwerkadresse 001E101F2B52 wurde durch den DHCP-Server 10.112.153.137 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet). Error: (10/15/2013 07:14:32 PM) (Source: Service Control Manager) (User: ) Description: cdrom Error: (10/15/2013 07:14:24 PM) (Source: Service Control Manager) (User: ) Description: 30000vpnagent Error: (10/15/2013 07:14:24 PM) (Source: Service Control Manager) (User: ) Description: Bruker FTIR Driver%%87 Microsoft Office Sessions: ========================= Error: (10/16/2013 00:00:07 AM) (Source: Windows Backup)(User: ) Description: J:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (10/15/2013 07:08:27 PM) (Source: Software Licensing Service)(User: ) Description: hr=0x80070002, [2, 4] Error: (10/15/2013 06:30:40 PM) (Source: Software Licensing Service)(User: ) Description: hr=0x80070002, [2, 4] Error: (10/15/2013 00:00:07 AM) (Source: Windows Backup)(User: ) Description: J:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (10/14/2013 05:39:19 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\7Schläfer\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\RF8QBPRM.DEFAULT\SAFEBROWSING-TO_DELETE Error: (10/14/2013 05:39:19 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\7Schläfer\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\RF8QBPRM.DEFAULT\SAFEBROWSING-BACKUP Error: (10/14/2013 00:00:22 AM) (Source: Windows Backup)(User: ) Description: J:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (10/13/2013 09:03:49 AM) (Source: Windows Backup)(User: ) Description: J:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (10/12/2013 01:22:48 AM) (Source: System Restore)(User: ) Description: C:\Windows\system32\DrvInst.exe "4" "0" "C:\Users\Admin\{2874574f-9a9a-4162-91fb-8c7e3afb82fb}\ewusbdev.inf" "0" "6b443b833" "00000534" "WinSta0\Default" "00000524" "208" "C:\Program Files\Mobile Partner\driver\WinVista"Gerätetreiber-Paketinstallation: HUAWEI Incorporated Anschlüsse (COM & LPT)0x8000ffff Error: (10/12/2013 01:22:48 AM) (Source: VSS)(User: ) Description: CoCreateInstance0x80070422 Vorgang: VSS-Server wird instanziiert CodeIntegrity Errors: =================================== Date: 2013-10-16 15:36:31.662 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-10-16 15:36:31.459 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-10-16 15:36:31.241 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-10-16 15:36:31.038 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-10-16 15:36:29.135 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20131002.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-10-16 15:36:28.932 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20131002.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-10-16 15:36:28.713 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20131002.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-10-16 15:36:28.511 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20131002.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-10-16 15:18:19.488 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-10-16 15:18:19.285 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 61% Total physical RAM: 2037.7 MB Available physical RAM: 780.5 MB Total Pagefile: 4316.4 MB Available Pagefile: 2441.78 MB Total Virtual: 2047.88 MB Available Virtual: 1895.68 MB ==================== Drives ================================ Drive c: (SYSTEM) (Fixed) (Total:148.1 GB) (Free:18 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (DATA) (Fixed) (Total:73.07 GB) (Free:32.32 GB) NTFS Drive h: (NBRT) (Removable) (Total:1.87 GB) (Free:1.46 GB) FAT32 ==================== MBR & Partition Table ================== ==================== End Of Log ============================ P.S.: In der hosts-Datei werden bekannte urls von Malware-Seiten nur auf die 127.0.0.1 umgebogen. Keine anderen IPs drin. Geändert von 7schläfer (16.10.2013 um 15:29 Uhr) Grund: P.S. |
Themen zu Softwareupdater.UI.exe |
0x8007042, 4d36e972-e325-11ce-bfc1-08002be10318, ad-aware, browser, computer, diagnostics, explorer, farbar, farbar recovery scan tool, firefox, flash player, freemium, google, home, homepage, hosts-datei, installation, mozilla, plug-in, prozess, realtek, rundll, safer networking, security, services.exe, softwareupdater.ui.exe, spyware.passwords, starten, svchost.exe, symantec, system, temp, trojan/jmgengeneric.boe, vcredist, windows xp |