Danke dir
Hier ist es
FRST Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-10-2013 01
Ran by Alex2 (administrator) on ALEX-NB on 26-10-2013 17:25:47
Running from C:\Users\Alex2\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 7
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(UPEK Inc.) C:\Program Files\Common Files\SPBA\upeksvr.exe
(Arachnoid Biometrics Identification Group Corp.) C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Egis Incorporated) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
() C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
(Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Windows\PLFSetI.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\QtZgAcer.EXE
(Arachnoid Biometrics Identification Group Corp.) C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Dropbox, Inc.) C:\Users\Alex2\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
() C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [182808 2008-07-20] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1049896 2008-04-25] (Synaptics, Inc.)
HKLM\...\Run: [PLFSetI] - C:\Windows\PLFSetI.exe [200704 2007-10-23] ()
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [ePower_DMC] - C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [405504 2008-08-01] (Acer Inc.)
HKLM\...\Run: [LManager] - C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE [817672 2008-06-04] (Dritek System Inc.)
HKLM\...\Run: [ZPdtWzdVitaKey MC3000] - C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe [3673600 2011-06-17] (Arachnoid Biometrics Identification Group Corp.)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-01] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\AWinNotifyVitaKey MC3000: C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll (Arachnoid Biometrics Identification Group Corp.)
Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default\...\RunOnce: [AcerScrSav] - C:\Windows\Acer\run_NB.exe [ 2007-08-21] ()
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\RunOnce: [AcerScrSav] - C:\Windows\Acer\run_NB.exe [ 2007-08-21] ()
HKU\TEMP\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
IMEO\Acrobat.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\acrodist.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\decryption.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\edstbmngr.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\formdesigner.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\framework.launcher.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\pdf24-editor.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\pdf24-fax.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\skype.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
Lsa: [Notification Packages] scecli C:\Program Files\Acer\Acer Bio Protection\PwdFilter
Startup: C:\Users\Alex2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Alex2\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=0908&m=aspire_6930g
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://global.acer.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=0908&m=aspire_6930g
SearchScopes: HKLM - DefaultScope value is missing.
BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll (Egis)
BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
Toolbar: HKLM - Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
Toolbar: HKLM - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Alex2\AppData\Roaming\Mozilla\Firefox\Profiles\0ss58y6a.default
FF DefaultSearchEngine: Wikipedia (de)
FF SelectedSearchEngine: Wikipedia (de)
FF Homepage: hxxp://www.t-online.de/
FF Keyword.URL: chrome://browser-region/locale/region.properties
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nullsoft.com/winampDetector;version=1 - C:\Program Files\Winamp Detect\npwachk.dll (Nullsoft, Inc.)
FF Plugin: @real.com/nppl3260;version=6.0.12.448 - C:\Program Files\VistaCodecPack\rm\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.4 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Acrobat - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Alex2\AppData\Roaming\Mozilla\Firefox\Profiles\0ss58y6a.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: em:name="bug489729(Disable detach and tear off tab)" - C:\Users\Alex2\AppData\Roaming\Mozilla\Firefox\Profiles\0ss58y6a.default\Extensions\bug489729@alice0775
FF Extension: Move Media Player - C:\Users\Alex2\AppData\Roaming\Mozilla\Firefox\Profiles\0ss58y6a.default\Extensions\moveplayer@movenetworks.com
FF Extension: No Name - C:\Users\Alex2\AppData\Roaming\Mozilla\Firefox\Profiles\0ss58y6a.default\Extensions\staged
FF Extension: YouTube Unblocker - C:\Users\Alex2\AppData\Roaming\Mozilla\Firefox\Profiles\0ss58y6a.default\Extensions\youtubeunblocker@unblocker.yt
FF Extension: Cookies Manager+ - C:\Users\Alex2\AppData\Roaming\Mozilla\Firefox\Profiles\0ss58y6a.default\Extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d}
FF Extension: raven - C:\Users\Alex2\AppData\Roaming\Mozilla\Firefox\Profiles\0ss58y6a.default\Extensions\raven@sitening.com.xpi
FF Extension: youtube2mp3 - C:\Users\Alex2\AppData\Roaming\Mozilla\Firefox\Profiles\0ss58y6a.default\Extensions\youtube2mp3@mondayx.de.xpi
FF Extension: Adblock Plus - C:\Users\Alex2\AppData\Roaming\Mozilla\Firefox\Profiles\0ss58y6a.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF HKLM\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG)
S4 ETService; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [24576 2008-06-02] ()
R2 IGBASVC; C:\Program Files\Acer\Acer Bio Protection\BASVC.exe [3521024 2011-06-17] ()
S4 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [110592 2007-12-06] ()
S4 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [131072 2008-04-25] ()
S4 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [233472 2008-01-10] (Acer Incorporated)
S2 SBAMSvc; C:\Program Files\Sunbelt Software\CounterSpy\SBAMSvc.exe [2726000 2010-04-19] (Sunbelt Software)
R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [1529152 2012-04-05] (TuneUp Software)
==================== Drivers (Whitelisted) ====================
R0 AlfaFF; C:\Windows\System32\Drivers\AlfaFF.sys [43184 2011-06-17] (Alfa Corporation)
S3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [104512 2009-11-11] (SlySoft, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [89376 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-01] (Avira Operations GmbH & Co. KG)
R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [101248 2008-12-23] (AVM Berlin)
S3 cpudrv; C:\Program Files\SystemRequirementsLab\cpudrv.sys [11336 2009-12-18] ()
R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [25768 2009-09-26] (Elaborate Bytes AG)
R2 int15; C:\Windows\system32\drivers\int15.sys [69632 2007-01-26] ()
R3 L1E; C:\Windows\System32\DRIVERS\L1E60x86.sys [47104 2008-05-19] (Atheros Communications, Inc.)
R3 NETwNv32; C:\Windows\System32\DRIVERS\NETwNv32.sys [6959616 2010-10-18] (Intel Corporation)
S3 NPF; C:\Windows\System32\drivers\npf.sys [34064 2011-01-04] (CACE Technologies)
R2 PStrip; C:\Windows\System32\drivers\pstrip.sys [27992 2007-07-15] (EnTech Taiwan)
R2 sbapifs; C:\Windows\System32\DRIVERS\sbapifs.sys [69936 2009-05-13] (Sunbelt Software)
S3 SBRE; C:\Windows\system32\drivers\SBREdrv.sys [95024 2009-10-13] (Sunbelt Software)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2008-11-18] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-03-12] (Avira GmbH)
R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [10064 2012-03-29] (TuneUp Software)
R3 winbondcir; C:\Windows\System32\DRIVERS\winbondcir.sys [43008 2007-03-28] (Winbond Electronics Corporation)
S3 ZD1211U(ZyXEL); C:\Windows\System32\DRIVERS\zd1211u.sys [237568 2004-11-23] (ZyDAS Technology Corporation)
U3 abtb3n01; C:\Windows\System32\Drivers\abtb3n01.sys [0 ] (Microsoft Corporation)
S3 Andbus; system32\DRIVERS\lgandbus.sys [x]
S3 AndDiag; system32\DRIVERS\lganddiag.sys [x]
S3 AndGps; system32\DRIVERS\lgandgps.sys [x]
S3 ANDModem; system32\DRIVERS\lgandmodem.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2008-05-02] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-26 17:25 - 2013-10-26 17:25 - 01089001 _____ (Farbar) C:\Users\Alex2\Desktop\FRST.exe
2013-10-26 13:12 - 2013-10-26 13:15 - 2346728084 _____ C:\Users\Alex2\Desktop\Fussball_13.10.23_20-25_zdf_170_TVOON_DE.mpg.avi
2013-10-25 21:29 - 2013-10-25 21:30 - 400835754 _____ C:\Users\Alex2\Desktop\Gute_Zeiten_schlechte_Zeiten_13.10.24_19-40_rtl_35_TVOON_DE.mpg.avi
2013-10-24 19:00 - 2013-10-24 19:00 - 00000000 ____D C:\Users\Alex2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in
2013-10-24 19:00 - 2013-10-24 19:00 - 00000000 ____D C:\Program Files\Winamp Detect
2013-10-24 18:39 - 2013-10-24 18:39 - 00000000 ____D C:\Windows\ERUNT
2013-10-24 18:33 - 2013-10-26 10:49 - 00119512 _____ C:\Windows\PFRO.log
2013-10-24 18:26 - 2013-10-24 18:26 - 00000000 _____ C:\Windows\setuperr.log
2013-10-24 18:26 - 2013-10-24 18:26 - 00000000 _____ C:\Windows\setupact.log
2013-10-24 16:16 - 2013-10-24 16:16 - 00000000 ____D C:\Program Files\Defraggler
2013-10-24 15:42 - 2013-10-24 15:46 - 00000000 ____D C:\AdwCleaner
2013-10-24 15:16 - 2013-10-24 15:16 - 00000000 ____D C:\ProgramData\Oracle
2013-10-24 15:15 - 2013-10-24 15:15 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-24 15:15 - 2013-10-24 15:15 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-24 15:15 - 2013-10-24 15:15 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-24 15:15 - 2013-10-24 15:15 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-21 19:33 - 2013-10-21 19:33 - 00000000 ____D C:\FRST
2013-10-13 12:30 - 2013-10-24 14:37 - 00014061 _____ C:\Users\Alex2\Desktop\Prüfungsleistungen.xlsx
2013-10-11 15:22 - 2013-09-24 05:07 - 06119424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-11 15:22 - 2013-09-24 05:07 - 03625984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-11 15:22 - 2013-09-24 05:07 - 01177600 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-11 15:22 - 2013-09-24 05:07 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-11 15:22 - 2013-09-24 05:07 - 00671232 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2013-10-11 15:22 - 2013-09-24 05:07 - 00498688 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-11 15:22 - 2013-09-24 05:07 - 00479744 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-10-11 15:22 - 2013-09-24 05:07 - 00380928 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-10-11 15:22 - 2013-09-24 05:07 - 00271872 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-11 15:22 - 2013-09-24 05:07 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-10-11 15:22 - 2013-09-24 05:07 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-11 15:22 - 2013-09-24 05:07 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-10-11 15:22 - 2013-09-24 05:07 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-11 15:22 - 2013-09-24 05:06 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll
2013-10-11 15:22 - 2013-09-23 22:13 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-10-11 15:22 - 2013-09-23 22:01 - 01383424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-10 11:31 - 2013-08-29 09:36 - 02050048 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-10 11:31 - 2013-08-27 04:47 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-10-10 11:31 - 2013-08-27 04:47 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-10-10 11:31 - 2013-08-27 04:47 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-10-10 11:31 - 2013-08-27 04:47 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-10-10 11:31 - 2013-08-27 03:52 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-10-10 11:31 - 2013-08-27 03:50 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-10-10 11:31 - 2013-08-27 03:32 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-10-10 11:31 - 2013-08-27 03:28 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-10-10 11:31 - 2013-08-27 03:28 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-10-10 11:31 - 2013-08-01 05:16 - 00638400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-10 11:31 - 2013-08-01 04:49 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2013-10-10 11:31 - 2013-07-20 12:44 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 11:31 - 2013-07-12 11:04 - 00134272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2013-10-10 11:31 - 2013-07-04 06:21 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-10 11:31 - 2013-07-03 04:10 - 00025472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-10 11:31 - 2013-06-29 04:07 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-10 11:31 - 2013-06-29 04:07 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-10 11:31 - 2013-06-29 04:07 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-10 11:31 - 2013-06-29 04:06 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-10 11:31 - 2013-06-27 01:01 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-10 11:31 - 2013-06-04 06:16 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-10 11:31 - 2013-06-04 03:49 - 00293376 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-10 11:31 - 2011-05-05 15:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-10 11:31 - 2011-05-05 15:54 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-09-30 23:44 - 2013-10-01 10:31 - 00000000 ____D C:\Program Files\Mozilla Firefox
==================== One Month Modified Files and Folders =======
2013-10-26 17:25 - 2013-10-26 17:25 - 01089001 _____ (Farbar) C:\Users\Alex2\Desktop\FRST.exe
2013-10-26 17:17 - 2012-07-04 10:29 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-26 16:49 - 2006-11-02 14:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-26 16:49 - 2006-11-02 14:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-26 14:16 - 2011-08-13 21:35 - 00000000 ____D C:\Users\Alex2\AppData\Roaming\Dropbox
2013-10-26 14:16 - 2008-09-22 05:37 - 00000000 ____D C:\Program Files\Launch Manager
2013-10-26 13:16 - 2010-08-04 14:58 - 00000000 ____D C:\Users\Alex2\AppData\Roaming\vlc
2013-10-26 13:15 - 2013-10-26 13:12 - 2346728084 _____ C:\Users\Alex2\Desktop\Fussball_13.10.23_20-25_zdf_170_TVOON_DE.mpg.avi
2013-10-26 12:58 - 2008-09-22 05:24 - 02085072 _____ C:\Windows\WindowsUpdate.log
2013-10-26 12:03 - 2008-11-17 21:41 - 00000069 _____ C:\Windows\NeroDigital.ini
2013-10-26 10:52 - 2011-08-13 21:41 - 00000000 ___RD C:\Users\Alex2\Desktop\Dropbox
2013-10-26 10:49 - 2013-10-24 18:33 - 00119512 _____ C:\Windows\PFRO.log
2013-10-26 10:49 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-26 01:37 - 2006-11-02 15:01 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-26 00:46 - 2010-08-06 11:39 - 00000000 ____D C:\Program Files\Avidemux 2.5
2013-10-25 21:30 - 2013-10-25 21:29 - 400835754 _____ C:\Users\Alex2\Desktop\Gute_Zeiten_schlechte_Zeiten_13.10.24_19-40_rtl_35_TVOON_DE.mpg.avi
2013-10-25 20:58 - 2012-05-10 22:25 - 00000000 ____D C:\Users\Alex2\AppData\Roaming\TV-Browser
2013-10-25 14:44 - 2012-12-04 17:54 - 00002339 _____ C:\Users\Public\Desktop\Skype.lnk
2013-10-25 14:44 - 2009-10-04 20:37 - 00000000 ____D C:\Users\Alex2\AppData\Roaming\Skype
2013-10-24 19:10 - 2009-04-29 11:44 - 00212992 _____ C:\Users\Alex2\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-10-24 19:03 - 2009-05-01 13:17 - 00000000 ____D C:\Users\Alex2\AppData\Roaming\Winamp
2013-10-24 19:03 - 2008-10-10 17:38 - 00000740 _____ C:\Users\Public\Desktop\Winamp.lnk
2013-10-24 19:03 - 2008-10-10 17:33 - 00000000 ____D C:\Program Files\Winamp
2013-10-24 19:00 - 2013-10-24 19:00 - 00000000 ____D C:\Users\Alex2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in
2013-10-24 19:00 - 2013-10-24 19:00 - 00000000 ____D C:\Program Files\Winamp Detect
2013-10-24 18:59 - 2010-11-21 14:48 - 00000000 ____D C:\Program Files\Common Files\PX Storage Engine
2013-10-24 18:47 - 2009-04-28 18:34 - 00000000 ____D C:\Users\Alex2
2013-10-24 18:39 - 2013-10-24 18:39 - 00000000 ____D C:\Windows\ERUNT
2013-10-24 18:26 - 2013-10-24 18:26 - 00000000 _____ C:\Windows\setuperr.log
2013-10-24 18:26 - 2013-10-24 18:26 - 00000000 _____ C:\Windows\setupact.log
2013-10-24 18:24 - 2012-02-05 00:21 - 00000000 ____D C:\Program Files\Steam
2013-10-24 18:24 - 2008-10-08 19:56 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-10-24 16:16 - 2013-10-24 16:16 - 00000000 ____D C:\Program Files\Defraggler
2013-10-24 15:46 - 2013-10-24 15:42 - 00000000 ____D C:\AdwCleaner
2013-10-24 15:40 - 2013-01-03 08:13 - 00000000 ____D C:\Users\Alex2\AppData\Local\PokerStars.EU
2013-10-24 15:40 - 2012-05-27 11:00 - 00000000 ____D C:\Program Files\PokerStars
2013-10-24 15:38 - 2012-09-05 03:58 - 00001912 _____ C:\Windows\epplauncher.mif
2013-10-24 15:33 - 2008-07-30 03:22 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-10-24 15:16 - 2013-10-24 15:16 - 00000000 ____D C:\ProgramData\Oracle
2013-10-24 15:15 - 2013-10-24 15:15 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-24 15:15 - 2013-10-24 15:15 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-24 15:15 - 2013-10-24 15:15 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-24 15:15 - 2013-10-24 15:15 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-24 15:15 - 2008-10-07 12:29 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-24 15:14 - 2008-10-07 12:29 - 00000000 ____D C:\Program Files\Java
2013-10-24 15:07 - 2008-10-07 23:51 - 00000000 ____D C:\Windows\system32\Adobe
2013-10-24 14:37 - 2013-10-13 12:30 - 00014061 _____ C:\Users\Alex2\Desktop\Prüfungsleistungen.xlsx
2013-10-21 19:33 - 2013-10-21 19:33 - 00000000 ____D C:\FRST
2013-10-15 13:04 - 2008-01-21 09:16 - 01445546 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-13 18:29 - 2011-08-13 21:36 - 00000000 ____D C:\Users\Alex2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-11 19:20 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-10-11 15:35 - 2006-11-02 14:47 - 02224072 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-11 15:33 - 2010-10-01 13:14 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-11 15:25 - 2008-07-30 04:17 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-11 15:16 - 2013-08-16 10:45 - 00000000 ____D C:\Windows\system32\MRT
2013-10-11 07:54 - 2006-11-02 12:24 - 78106760 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-10-09 00:18 - 2012-03-30 10:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-09 00:18 - 2011-05-18 12:43 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-01 10:40 - 2012-04-25 08:25 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-01 10:36 - 2013-03-12 12:28 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-10-01 10:36 - 2013-03-12 12:28 - 00089376 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-10-01 10:36 - 2013-03-12 12:28 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-10-01 10:31 - 2013-09-30 23:44 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-28 15:36 - 2013-06-27 12:36 - 00000000 ____D C:\Program Files\PDFCreator
Some content of TEMP:
====================
C:\Users\Alex2\AppData\Local\Temp\avgnt.exe
C:\Users\Alex2\AppData\Local\Temp\Quarantine.exe
C:\Users\Alex2\AppData\Local\Temp\_unps.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-26 10:56
==================== End Of Log ============================
--- --- ---