|
Log-Analyse und Auswertung: Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
16.11.2013, 23:17 | #1 |
| Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) Seit heute lässt sich mein Firefox nicht mehr starten. Chrome und Internet Explorer funktionieren noch. Seit einiger Zeit bekomme ich - egal in welchem Browser - immer Werbung unten im Browserfenster geöffnet (meistens zwei Fenster), die ich erst schließen muss, bevor ich mit der Seite arbeiten kann, die ich eigentlich aufgerufen habe. Ich habe auch eine TV-Karte von Hauppauge, die ich schon mehrfach neu installieren musste, weil das Programm sich nicht mehr starten lies. Aber beim Firefox hilft nicht mal eine Neuinstallation, um ihn aufzurufen. Der Prozess firefox.exe ist im Taskmanager zu sehen, nicht aber die Anwendung firefox. Ich finde von Avast keine logdatei - ich habe schon nach *.log gesucht. Darum kann ich die nicht anhängen. Die Logfiles von heute: ----------------------------------------------------------------------------- defogger_disable.txt ----------------------------------------------------------------------------- Code:
ATTFilter d e f o g g e r _ d i s a b l e b y j p s h o r t s t u f f ( 2 3 . 0 2 . 1 0 . 1 ) L o g c r e a t e d a t 2 0 : 1 5 o n 1 6 / 1 1 / 2 0 1 3 ( T h o m a s ) C h e c k i n g f o r a u t o s t a r t v a l u e s . . . H K C U \ ~ \ R u n v a l u e s r e t r i e v e d . H K L M \ ~ \ R u n v a l u e s r e t r i e v e d . C h e c k i n g f o r s e r v i c e s / d r i v e r s . . . - = E . O . F = - |
17.11.2013, 01:09 | #2 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) Hallo,
__________________Zitat:
__________________ |
17.11.2013, 11:51 | #3 |
| Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) Nein, es ist nicht gewerblich genutzt. Ich benutze es manchmal (sehr selten) auch, um Sachen, die ich bei der Arbeit nicht geschafft habe, zu Hause anzusehen. Ich leite ehrenamtlich einen Gospelchor, wofür ich auch viel Software benötige. Da habe ich auch schon mal Datenbanken mit Access erstellt. Und nutze das Notebook auch als Videorekorder und erstelle dann DVDs. Das Notebook selber habe ich gebraucht gekauft.
__________________Außerdem gibt es Lizenzen von Microsoft, die auch privat genutzt werden dürfen und überhaupt nicht teuer sind. |
17.11.2013, 21:19 | #4 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit)Zitat:
Aber eine Professional Lizenz ist nunmal teurer als eine Home/Student und deswegen frag ich nach, privat braucht man sowas eher nicht Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
__________________ Logfiles bitte immer in CODE-Tags posten |
19.11.2013, 11:24 | #5 |
| Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) Hier das Ergebnis erster Scan Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.07.0.1007 www.malwarebytes.org Database version: v2013.11.19.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16428 Thomas :: DELL-PC [administrator] 19.11.2013 08:09:46 mbar-log-2013-11-19 (08-09-46).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 311203 Time elapsed: 56 minute(s), 41 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 1 HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs (Rogue.InternetSecurityEssentials) -> Bad: (c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll) Good: () -> Replace on reboot. Folders Detected: 1 C:\ProgramData\IBUpdaterService (Adware.InstallBrain) -> Delete on reboot. Files Detected: 3 C:\ProgramData\BitGuard\2.7.1769.27\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\loader.dll (Rogue.InternetSecurityEssentials) -> Delete on reboot. C:\Users\Thomas\Downloads\CodecPerformerSetup.exe (Adware.InstallBrain) -> Delete on reboot. C:\ProgramData\IBUpdaterService\repository.xml (Adware.InstallBrain) -> Delete on reboot. Physical Sectors Detected: 0 (No malicious items detected) (end) Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.07.0.1007 www.malwarebytes.org Database version: v2013.11.19.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16428 Thomas :: DELL-PC [administrator] 19.11.2013 10:09:14 mbar-log-2013-11-19 (10-09-14).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 310483 Time elapsed: 56 minute(s), 45 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) Geändert von comtom (19.11.2013 um 12:06 Uhr) |
19.11.2013, 13:31 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) Adware/Junkware/Toolbars entfernen 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ --> Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) |
19.11.2013, 16:20 | #7 |
| Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) AdwCleaner AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.012 - Bericht erstellt am 19/11/2013 um 15:47:13 # Updated 11/11/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Thomas - DELL-PC # Gestartet von : C:\Users\Thomas\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** Dienst Gelöscht : BitGuard [#] Dienst Gelöscht : dealplylive [#] Dienst Gelöscht : dealplylivem [#] Dienst Gelöscht : Update Lizardlink ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\BitGuard Ordner Gelöscht : C:\ProgramData\DealPlyLive Ordner Gelöscht : C:\ProgramData\DSearchLink Ordner Gelöscht : C:\ProgramData\simplitec Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Performer Ordner Gelöscht : C:\Program Files (x86)\Conduit Ordner Gelöscht : C:\Program Files (x86)\DealPly Ordner Gelöscht : C:\Program Files (x86)\DealPlyLive Ordner Gelöscht : C:\Program Files (x86)\Delta Ordner Gelöscht : C:\Program Files (x86)\Lizardlink Ordner Gelöscht : C:\Program Files (x86)\PC Performer Ordner Gelöscht : C:\Program Files (x86)\appbarioDE Ordner Gelöscht : C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard Ordner Gelöscht : C:\Users\Thomas\AppData\Local\Conduit Ordner Gelöscht : C:\Users\Thomas\AppData\Local\DealPlyLive Ordner Gelöscht : C:\Users\Thomas\AppData\Local\Temp\CT3312331 Ordner Gelöscht : C:\Users\Thomas\AppData\LocalLow\boost_interprocess Ordner Gelöscht : C:\Users\Thomas\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\Thomas\AppData\LocalLow\Delta Ordner Gelöscht : C:\Users\Thomas\AppData\LocalLow\PriceGong Ordner Gelöscht : C:\Users\Thomas\AppData\LocalLow\appbarioDE Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\BabSolution Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\Delta Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\file scout Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\OpenCandy Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\PerformerSoft Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\simplitec Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\SpeedAnalysis3 Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\Uniblue\DriverScanner Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\CT3312331 Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\Extensions\{e53a26f5-7199-4a5b-86f5-d2e86854b979} Ordner Gelöscht : C:\Program Files (x86)\Mozilla Firefox\Extensions\ffxtlbr@babylon.com Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\Extensions\ffxtlbr@delta.com Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\Extensions\{525ba996-1ce4-4677-91c5-9fc4ead2d245} Ordner Gelöscht : C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkoahcaobjbihehldfimhblmhgalcipm Datei Gelöscht : C:\END Datei Gelöscht : C:\Users\Public\Desktop\PC Performer.lnk Datei Gelöscht : C:\Windows\System32\roboot64.exe Datei Gelöscht : C:\Users\Thomas\AppData\Roaming\speedanalysis.ico Datei Gelöscht : C:\Users\Thomas\Desktop\SpeedAnalysis.lnk Datei Gelöscht : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\bprotector_extensions.sqlite Datei Gelöscht : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\bprotector_prefs.js Datei Gelöscht : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\invalidprefs.js Datei Gelöscht : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\searchplugins\Conduit.xml Datei Gelöscht : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\user.js Datei Gelöscht : C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_app.mam.conduit.com_0.localstorage Datei Gelöscht : C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_app.mam.conduit.com_0.localstorage-journal Datei Gelöscht : C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_storage.conduit.com_0.localstorage Datei Gelöscht : C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_storage.conduit.com_0.localstorage-journal Datei Gelöscht : C:\Windows\System32\Tasks\BackgroundContainer Startup Task Datei Gelöscht : C:\Windows\System32\Tasks\BitGuard Datei Gelöscht : C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job Datei Gelöscht : C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineCore Datei Gelöscht : C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job Datei Gelöscht : C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineUA Datei Gelöscht : C:\Windows\System32\Tasks\DealPlyUpdate Datei Gelöscht : C:\Windows\System32\Tasks\EPUpdater Datei Gelöscht : C:\Windows\Tasks\PC Performer_DEFAULT.job Datei Gelöscht : C:\Windows\System32\Tasks\PC Performer_DEFAULT Datei Gelöscht : C:\Windows\Tasks\PC Performer_UPDATES.job Datei Gelöscht : C:\Windows\System32\Tasks\PC Performer_UPDATES ***** [ Verknüpfungen ] ***** Verknüpfung Desinfiziert : C:\Users\Thomas\Desktop\Search.lnk ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\jainjonnknhmbbkibcbmhihbopigapdm Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\hkoahcaobjbihehldfimhblmhgalcipm Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\hkoahcaobjbihehldfimhblmhgalcipm Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [BackgroundContainer] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\dealplylive.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DealPlyLive.OneClickCtrl.9 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DealPlyLive.OneClickProcessLauncherMachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DealPlyLive.OneClickProcessLauncherMachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DealPlyLive.Update3WebControl.3 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.CoCreateAsync Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.CoCreateAsync.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dealplyliveupdate.coreclass Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.CoreClass.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.CoreMachineClass Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.CoreMachineClass.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dealplyliveupdate.credentialdialogmachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dealplyliveupdate.credentialdialogmachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dealplyliveupdate.ondemandcomclassmachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.OnDemandCOMClassMachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dealplyliveupdate.ondemandcomclassmachinefallback Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dealplyliveupdate.ondemandcomclassmachinefallback.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.OnDemandCOMClassSvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dealplyliveupdate.ondemandcomclasssvc.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.ProcessLauncher Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.ProcessLauncher.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.Update3COMClassService Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.Update3COMClassService.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3webmachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3webmachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3webmachinefallback Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3webmachinefallback.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3websvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3websvc.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dealplylive.exe Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@tools.dpliveupdate.com/DealPlyLive Update;version=3 Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@tools.dpliveupdate.com/DealPlyLive Update;version=9 Schlüssel Gelöscht : HKCU\Software\9ede8fb439b843 Schlüssel Gelöscht : HKLM\SOFTWARE\9ede8fb439b843 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3312331 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{80FABB17-63AF-4655-9F07-B6509EE37AF2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{F48FC5B2-094A-44C7-B48C-289738C9582D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0D89DE71-3D99-4288-84DC-F18F1047A7D8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1E0C9B2A-6447-452C-B012-2314A0C29412} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{34A8CEB6-89BB-49F1-B5E4-0D0D6C21F3B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3A4DBD3A-98CC-41CE-AD21-352D42B6F754} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4F8A50F6-69DE-4BE3-A33A-A1079B9AC0DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{501CB57A-D4E2-4855-96AD-EDB0A9083395} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6FF2C4DD-77A4-4BB5-BA4C-B42DEFBF9137} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7F1796B2-BEC6-427B-B734-F9C75ED94A80} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80FABB17-63AF-4655-9F07-B6509EE37AF2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{83ABA270-8390-4CA6-AE48-FC089F55629E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8B218A5F-1A3D-4347-94EF-A79575EB8094} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9BDB5E09-4BBA-4422-8C2B-529B281C32B8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9CF699CA-2174-4ED8-BEC1-BA82095EDCE0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C536F080-57B7-46D6-8894-C647553F2889} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CA5D945F-E738-4D0B-A0B5-25AC51C64659} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EB9E4CDF-B007-450C-B0AF-B66467C3D6E0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F48FC5B2-094A-44C7-B48C-289738C9582D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F7698761-4ABA-45C2-A5BB-D2163922C725} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FFCC53E6-2655-47FC-A89B-54E8D7F305D1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{525BA996-1CE4-4677-91C5-9FC4EAD2D245} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4912F6DC-F59A-43E0-9371-D7CC7B3C500A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{17F7D2B4-126F-4567-9FDB-563C2D907A92} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{81B7413C-F330-42D5-9CFC-0ECDF03D8C37} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CF699CA-2174-4ED8-BEC1-BA82095EDCE0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EB9E4CDF-B007-450C-B0AF-B66467C3D6E0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{525BA996-1CE4-4677-91C5-9FC4EAD2D245} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CF699CA-2174-4ED8-BEC1-BA82095EDCE0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EB9E4CDF-B007-450C-B0AF-B66467C3D6E0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{525BA996-1CE4-4677-91C5-9FC4EAD2D245} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CF699CA-2174-4ED8-BEC1-BA82095EDCE0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F1796B2-BEC6-427B-B734-F9C75ED94A80} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4912F6DC-F59A-43E0-9371-D7CC7B3C500A} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F1796B2-BEC6-427B-B734-F9C75ED94A80} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C536F080-57B7-46D6-8894-C647553F2889} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2645E6AF-8A09-4722-9BC1-FB02FF9E2985} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E94504CC-31A2-4ED8-BADA-0131472A6E0C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{82E1477C-B154-48D3-9891-33D83C26BCD3}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{525BA996-1CE4-4677-91C5-9FC4EAD2D245}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{525BA996-1CE4-4677-91C5-9FC4EAD2D245}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{525BA996-1CE4-4677-91C5-9FC4EAD2D245}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{525BA996-1CE4-4677-91C5-9FC4EAD2D245}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{17F7D2B4-126F-4567-9FDB-563C2D907A92} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} Schlüssel Gelöscht : HKCU\Software\BabSolution Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\DataMngr [#] Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar Schlüssel Gelöscht : HKCU\Software\DealPly Schlüssel Gelöscht : HKCU\Software\DealPlyLive Schlüssel Gelöscht : HKCU\Software\Delta Schlüssel Gelöscht : HKCU\Software\filescout Schlüssel Gelöscht : HKCU\Software\Lizardlink Schlüssel Gelöscht : HKCU\Software\PerformerSoft Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\smartbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\appbarioDE Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\Software\DealPly Schlüssel Gelöscht : HKLM\Software\DealPlyLive Schlüssel Gelöscht : HKLM\Software\Delta Schlüssel Gelöscht : HKLM\Software\Lizardlink Schlüssel Gelöscht : HKLM\Software\PerformerSoft Schlüssel Gelöscht : HKLM\Software\Uniblue Schlüssel Gelöscht : HKLM\Software\appbarioDE Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Performer_is1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\appbarioDE Toolbar Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Lizardlink ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v25.0.1 (de) [ Datei : C:\Users\dell\AppData\Roaming\Mozilla\Firefox\Profiles\s8387th6.default\prefs.js ] [ Datei : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\dfaevt7t.default\prefs.js ] [ Datei : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\prefs.js ] Zeile gelöscht : user_pref("CT3312331.FF19Solved", "true"); Zeile gelöscht : user_pref("CT3312331.UserID", "UN40307384681046329"); Zeile gelöscht : user_pref("CT3312331.browser.search.defaultthis.engineName", "true"); Zeile gelöscht : user_pref("CT3312331.fullUserID", "UN40307384681046329.IN.20130922003538"); Zeile gelöscht : user_pref("CT3312331.installDate", "22/09/2013 00:35:46"); Zeile gelöscht : user_pref("CT3312331.installSessionId", "{1C5C7EE6-044B-42BB-9786-04AFC809FEFF}"); Zeile gelöscht : user_pref("CT3312331.installSp", "TRUE"); Zeile gelöscht : user_pref("CT3312331.installerVersion", "1.6.1.2"); Zeile gelöscht : user_pref("CT3312331.keyword", "true"); Zeile gelöscht : user_pref("CT3312331.originalHomepage", "hxxp://www2.delta-search.com/?babsrc=HP_ss&mntrId=B80F00234DE93E13&affID=121565&tt=160913_m3&tsp=5012"); Zeile gelöscht : user_pref("CT3312331.originalSearchAddressUrl", ""); Zeile gelöscht : user_pref("CT3312331.originalSearchEngine", ""); Zeile gelöscht : user_pref("CT3312331.originalSearchEngineName", ""); Zeile gelöscht : user_pref("CT3312331.searchRevert", "false"); Zeile gelöscht : user_pref("CT3312331.searchUserMode", "2"); Zeile gelöscht : user_pref("CT3312331.smartbar.homepage", "true"); Zeile gelöscht : user_pref("CT3312331.versionFromInstaller", "10.20.0.13"); Zeile gelöscht : user_pref("CT3312331.xpeMode", "0"); Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://www2.delta-search.com/?babsrc=NT_ss&mntrId=B80F00234DE93E13&affID=121565&tt=160913_m3&tsp=5012"); Zeile gelöscht : user_pref("browser.search.defaultenginename", "appbarioDE Customized Web Search"); Zeile gelöscht : user_pref("browser.search.defaultthis.engineName", "appbarioDE Customized Web Search"); Zeile gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3312331&CUI=UN40307384681046329&UM=2&SearchSource=3&q={searchTerms}"); Zeile gelöscht : user_pref("extensions.delta.admin", false); Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst"); Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false"); Zeile gelöscht : user_pref("extensions.delta.dfltLng", "de"); Zeile gelöscht : user_pref("extensions.delta.excTlbr", false); Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true); Zeile gelöscht : user_pref("extensions.delta.id", "b80f05d2000000000000000000000000"); Zeile gelöscht : user_pref("extensions.delta.instlDay", "15969"); Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst"); Zeile gelöscht : user_pref("extensions.delta.newTab", false); Zeile gelöscht : user_pref("extensions.delta.prdct", "delta"); Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta"); Zeile gelöscht : user_pref("extensions.delta.rvrt", "false"); Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base"); Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", ""); Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.24.6"); Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.24.60:27:14"); Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.24.6"); Zeile gelöscht : user_pref("extensions.delta_i.babExt", ""); Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=121565&tt=160913_m3&tsp=5012"); Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss"); -\\ Google Chrome v31.0.1650.57 [ Datei : C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht : homepage Gelöscht : icon_url Gelöscht : search_url Gelöscht : keyword Gelöscht : urls_to_restore_on_startup ************************* AdwCleaner[R0].txt - [28502 octets] - [19/11/2013 15:44:02] AdwCleaner[S0].txt - [27510 octets] - [19/11/2013 15:47:13] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [27571 octets] ########## [/code] JRT - habe leider vergessen, die Schutzsoftware zu deaktivieren. Soll ich es noch mal tun? Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Professional x64 Ran by Thomas on 19.11.2013 at 15:58:51,15 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL Suspicious HKCU\..\Run entries found. Trojan:JS/Medfos.B? Value Name Type Value Data ======================================================================================== TBHostSupport REG_SZ "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Thomas\AppData\Local\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2792732775-2869549041-531120149-1003\Software\sweetim Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0F6B179F-EFCF-467F-B649-E6C324DC62E5} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{58B46A7C-B976-4CC5-8F75-E0465861B255} ~~~ Files Successfully deleted: [File] "C:\Users\Thomas\appdata\local\google\chrome\user data\default\local storage\http_pricegong.conduitapps.com_0.localstorage" Successfully deleted: [File] "C:\Users\Thomas\appdata\local\google\chrome\user data\default\local storage\http_pricegong.conduitapps.com_0.localstorage-journal" ~~~ Folders Successfully deleted: [Folder] "C:\Users\Thomas\appdata\local\adawarebp" Successfully deleted: [Folder] "C:\Users\Thomas\appdata\local\cre" Successfully deleted: [Folder] "C:\Program Files (x86)\free video converter" ~~~ FireFox Emptied folder: C:\Users\Thomas\AppData\Roaming\mozilla\firefox\profiles\ou3igakk.default\minidumps [136 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 19.11.2013 at 16:07:54,44 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST.txt FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-11-2013 Ran by Thomas (administrator) on DELL-PC on 19-11-2013 16:12:47 Running from C:\Users\Thomas\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Nokia) C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Hauppauge Computer Works) C:\Program Files (x86)\WinTV\Ir.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Launcher.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe (Hauppauge Computer Works, Inc.) C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\pg_ctl.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe (VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\postgres.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe (Dropbox, Inc.) C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe (sw4you, Siegfried Weckmann) C:\Program Files (x86)\Hardcopy\hardcopy.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE () C:\Program Files (x86)\Hardcopy\HcDLL2_ex.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (VMware, Inc.) C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\postgres.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe (VMware, Inc.) C:\Program Files\VMware\VMware View\Client\Local Mode\vmware-authd.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.) C:\Program Files\VMware\VMware View\Client\bin\wsnm_usbctrl.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe (Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Farbar) C:\Users\Thomas\Downloads\FRST64 (1).exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-07-22] (IDT, Inc.) HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [592240 2011-01-04] (Alps Electric Co., Ltd.) HKLM\...\Run: [NVHotkey] - rundll32.exe C:\Windows\system32\nvHotkey.dll,Start HKCU\...\Run: [HP Officejet Pro 8600 (NET)] - C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2011-01-19] (Hewlett-Packard Company) HKCU\...\Run: [] - [x] HKCU\...\Run: [NokiaSuite.exe] - C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1090912 2013-10-02] (Nokia) HKCU\...\Run: [TBHostSupport] - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Thomas\AppData\Local\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin <===== ATTENTION MountPoints2: E - E:\AutoRun.exe MountPoints2: {3dfd66f3-3494-11e3-90a4-00234de93e13} - E:\AutoRun.exe MountPoints2: {b81eadf5-1eec-11e3-8f2b-f791e49f869d} - F:\AutoRun.exe MountPoints2: {b81eadfc-1eec-11e3-8f2b-f791e49f869d} - F:\AutoRun.exe MountPoints2: {b81eaea5-1eec-11e3-8f2b-f791e49f869d} - E:\AutoRun.exe MountPoints2: {dfd8099e-36e9-11e3-b92b-bf108e606330} - E:\AutoRun.exe HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC) HKLM-x32\...\Run: [FreePDF Assistant] - C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\avastui.exe [3567800 2013-10-24] (AVAST Software) HKU\dell\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKU\dell\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2011-01-19] (Hewlett-Packard Company) Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Hardcopy.LNK ShortcutTarget: Hardcopy.LNK -> C:\Program Files (x86)\Hardcopy\hardcopy.exe (sw4you, Siegfried Weckmann) Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\simplicheck.lnk ShortcutTarget: simplicheck.lnk -> Q:\Program Files (x86)\simplitec\simplicheck\simplicheck.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM - DefaultScope value is missing. BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll (Microsoft Corporation.) Winsock: Catalog9 11 C:\Program Files\VMware\VMware View\Client\Local Mode\vsocklib.dll [346736] (VMware, Inc.) Winsock: Catalog9 12 C:\Program Files\VMware\VMware View\Client\Local Mode\vsocklib.dll [346736] (VMware, Inc.) Winsock: Catalog9-x64 11 C:\Program Files\VMware\VMware View\Client\Local Mode\x64\vsocklib.dll [446576] (VMware, Inc.) Winsock: Catalog9-x64 12 C:\Program Files\VMware\VMware View\Client\Local Mode\x64\vsocklib.dll [446576] (VMware, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.90.1 Tcpip\..\Interfaces\{361A5F24-DD38-4F2A-812C-45FDC0BCA813}: [NameServer]212.23.115.148 212.23.115.132 FireFox: ======== FF ProfilePath: C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: https://www.google.de/ FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20((shExpMatch(host%2C%20'(*.turntable.fm%7Cturntable.fm)')%20%26%26%20url.indexOf('.css')%20%3D%3D%20-1%20%26%26%20url.indexOf('.js')%20%3D%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*'))%20%7B%20return%20'PROXY%20ab-us18.personalitycores.com%3A8000%3B%20PROXY%20ab-us17.personalitycores.com%3A8000%3B%20PROXY%20ab-us11.personalitycores.com%3A8000%3B%20PROXY%20ab-us12.personalitycores.com%3A8000%3B%20PROXY%20ab-us22.personalitycores.com%3A8000%3B%20PROXY%20ab-us08.personalitycores.com%3A8000%3B%20PROXY%20ab-us07.personalitycores.com%3A8000%3B%20PROXY%20ab-us10.personalitycores.com%3A8000%3B%20PROXY%20ab-us01.personalitycores.com%3A8000%3B%20PROXY%20ab-us14.personalitycores.com%3A8000%3B%20PROXY%20ab-us15.personalitycores.com%3A8000%3B%20PROXY%20ab-us21.personalitycores.com%3A8000%3B%20PROXY%20ab-us09.personalitycores.com%3A8000%3B%20PROXY%20ab-us02.personalitycores.com%3A8000%3B%20PROXY%20ab-us20.personalitycores.com%3A8000%3B%20PROXY%20ab-us13.personalitycores.com%3A8000%3B%20PROXY%20ab-us03.personalitycores.com%3A8000%3B%20PROXY%20ab-us16.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF NetworkProxy: "type", 2 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nokia.com/EnablerPlugin - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\searchplugins\aol-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Lizardlink - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\Extensions\firefox@lizardlink.biz FF Extension: firefox - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\Extensions\firefox@lizardlink.biz.xpi FF Extension: jid1-QpHD8URtZWJC2A - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi FF Extension: speedanalysis03 - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\Extensions\speedanalysis03@SpeedAnalysis.com.xpi FF Extension: Adblock Plus - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF HKLM-x32\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com\ FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com\ FF HKLM-x32\...\Firefox\Extensions: [ytfmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\ FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\ Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR DefaultSearchURL: (Search the web) - hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss_Btisdt7&mntrId=B80F00234DE93E13&affID=121565&tt=160913_m3&tsp=5012 CHR DefaultSuggestURL: (Search the web) - "suggest_url": "", CHR Extension: (Freemake Youtube Download Button) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh\1.0.0_0 CHR Extension: (Freemake Video Converter) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0 CHR Extension: (Google Wallet) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.172_0 CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [kdneagjiboclldmglpjofpeipkbollcf] - C:\Users\Thomas\AppData\Local\CRE\kdneagjiboclldmglpjofpeipkbollcf.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx ==================== Services (Whitelisted) ================= R2 ALDITALKVerbindungsassistent_Service; C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [358968 2013-09-18] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-10-24] (AVAST Software) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-08-26] (Freemake) R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-08-26] (Ellora Assets Corp.) S3 HauppaugeTVServer; C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe [582144 2013-08-31] (Hauppauge Computer Works) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2409272 2013-10-11] (TuneUp Software) S3 ufad-ws60; C:\Program Files\VMware\VMware View\Client\Local Mode\vmware-ufad.exe [191024 2010-08-19] (VMware, Inc.) R2 VMAuthdService; C:\Program Files\VMware\VMware View\Client\Local Mode\vmware-authd.exe [113264 2011-03-26] (VMware, Inc.) R2 postgresql-8.4; C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N "postgresql-8.4" -D "C:/Program Files (x86)/PostgreSQL/8.4/data" -w [x] R2 postgresql-9.2; C:/Program Files (x86)/PostgreSQL/9.2/bin/pg_ctl.exe runservice -N "postgresql-9.2" -D "C:/Program Files (x86)/PostgreSQL/9.2/data" -w [x] S2 Util Lizardlink; "C:\Program Files (x86)\Lizardlink\bin\utilLizardlink.exe" [x] ==================== Drivers (Whitelisted) ==================== R3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31968 2012-10-08] (Wondershare) R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-10-24] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-10-24] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-24] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-24] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-10-24] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-11-08] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-10-24] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-10-24] () R3 AVMCOWAN; C:\Windows\System32\DRIVERS\AVMCOWAN.sys [79872 2009-06-10] (AVM GmbH) S3 azvusb; C:\Windows\System32\DRIVERS\azvusb.sys [54784 2009-08-24] (AzureWave Technologies, Inc.) R3 btaudio; C:\Windows\System32\drivers\btaudio.sys [135208 2008-05-21] (Broadcom Corporation.) R3 BTDriver; C:\Windows\System32\DRIVERS\btport.sys [44200 2008-02-05] (Broadcom Corporation.) R3 BTKRNL; C:\Windows\System32\DRIVERS\btkrnl.sys [1282472 2008-08-08] (Broadcom Corporation.) R3 BTWDNDIS; C:\Windows\System32\DRIVERS\btwdndis.sys [156456 2007-09-20] (Broadcom Corporation.) R3 btwhid; C:\Windows\System32\DRIVERS\btwhid.sys [71592 2008-03-11] (Broadcom Corporation.) R3 btwmodem; C:\Windows\System32\DRIVERS\btwmodem.sys [43944 2008-02-05] (Broadcom Corporation.) R3 BTWUSB; C:\Windows\System32\Drivers\btwusb.sys [56104 2008-08-04] (Broadcom Corporation.) R3 FUS2BASE; C:\Windows\System32\DRIVERS\fus2base.sys [696832 2009-06-10] (AVM Berlin) S3 GigasetGenericUSB_x64; C:\Windows\System32\DRIVERS\GigasetGenericUSB_x64.sys [54272 2009-02-20] (Siemens Home and Office Communication Devices GmbH & Co. KG) R3 hcwD9bda; C:\Windows\System32\drivers\hcwD9bda.sys [526720 2010-12-22] ( ) S3 hwdatacard; C:\Windows\SysWow64\DRIVERS\ewusbmdm.sys [115328 2008-07-24] (Huawei Technologies Co., Ltd.) R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.) S3 PCTV_NTAMD64; C:\Windows\System32\DRIVERS\pctv4XXe_amd64.sys [571552 2007-08-06] (Pinnacle Systems GmbH) S3 TTHID; C:\Windows\System32\DRIVERS\Cinergy_Hybrid-Stick_HID.sys [27944 2012-09-27] (DTV-DVB) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2012-11-16] (TuneUp Software) S3 UDXTTM6010; C:\Windows\System32\DRIVERS\UDXTTM6010.sys [841384 2012-09-27] () R2 vstor2-ws60; C:\Program Files\VMware\VMware View\Client\Local Mode\vstor2-ws60.sys [32816 2010-08-19] (VMware, Inc.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-19 16:11 - 2013-11-19 16:12 - 01957964 _____ (Farbar) C:\Users\Thomas\Downloads\FRST64 (1).exe 2013-11-19 16:07 - 2013-11-19 16:07 - 00002408 _____ C:\Users\Thomas\Desktop\JRT.txt 2013-11-19 15:58 - 2013-11-19 15:58 - 00000000 ____D C:\Windows\ERUNT 2013-11-19 15:57 - 2013-11-19 15:57 - 01034531 _____ (Thisisu) C:\Users\Thomas\Downloads\JRT.exe 2013-11-19 15:54 - 2013-11-19 15:54 - 00027736 _____ C:\Users\Thomas\Desktop\AdwCleaner[S0].txt 2013-11-19 15:43 - 2013-11-19 15:47 - 00000000 ____D C:\AdwCleaner 2013-11-19 15:36 - 2013-11-19 15:36 - 01085542 _____ C:\Users\Thomas\Desktop\adwcleaner.exe 2013-11-19 08:09 - 2013-11-19 10:09 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2013-11-19 08:09 - 2013-11-19 08:09 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-19 08:07 - 2013-11-19 10:08 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-11-19 08:05 - 2013-11-19 11:18 - 00000000 ____D C:\Users\Thomas\Desktop\mbar 2013-11-19 07:58 - 2013-11-19 07:59 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Thomas\Downloads\mbar-1.07.0.1007.exe 2013-11-18 20:19 - 2013-11-18 20:22 - 146279768 _____ C:\Users\Thomas\Downloads\wintv7_cd_3.1a.exe 2013-11-16 23:15 - 2013-11-16 23:16 - 00034957 _____ C:\Users\Thomas\Downloads\logfiles.zip 2013-11-16 21:55 - 2013-11-16 21:55 - 00199379 _____ C:\Users\Thomas\Downloads\Gmer.txt 2013-11-16 21:39 - 2013-11-16 21:39 - 00377856 _____ C:\Users\Thomas\Downloads\gmer_2.1.19163.exe 2013-11-16 21:39 - 2013-11-16 21:39 - 00377856 _____ C:\Users\Thomas\Downloads\1rg9ry1l.exe 2013-11-16 20:20 - 2013-11-16 20:21 - 00044726 _____ C:\Users\Thomas\Downloads\Addition.txt 2013-11-16 20:18 - 2013-11-19 16:12 - 00028097 _____ C:\Users\Thomas\Downloads\FRST.txt 2013-11-16 20:17 - 2013-11-16 20:17 - 01957794 _____ (Farbar) C:\Users\Thomas\Downloads\FRST64.exe 2013-11-16 20:17 - 2013-11-16 20:17 - 00000000 ____D C:\FRST 2013-11-16 20:15 - 2013-11-16 20:15 - 00000474 _____ C:\Users\Thomas\Downloads\defogger_disable.log 2013-11-16 20:15 - 2013-11-16 20:15 - 00000000 _____ C:\Users\Thomas\defogger_reenable 2013-11-16 20:14 - 2013-11-16 20:15 - 00050477 _____ C:\Users\Thomas\Downloads\Defogger.exe 2013-11-16 19:48 - 2013-11-16 19:48 - 25393512 _____ (PortableApps.com) C:\Users\Thomas\Downloads\firefoxportable_25.0_german.paf.exe 2013-11-16 19:17 - 2013-11-16 19:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\WhiteListing 2013-11-16 19:17 - 2013-11-16 19:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\TBHostSupport 2013-11-16 19:17 - 2013-11-16 19:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\NativeMessaging 2013-11-16 19:05 - 2013-11-16 19:05 - 23115760 _____ (Mozilla) C:\Users\Thomas\Downloads\firefox_setup_25.0.1.exe 2013-11-16 18:09 - 2013-11-16 18:09 - 00283184 _____ (Mozilla) C:\Users\Thomas\Downloads\Firefox Setup Stub 25_0_1_exe 2013-11-16 17:47 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2013-11-16 17:47 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2013-11-16 17:47 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2013-11-16 17:47 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2013-11-16 17:47 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2013-11-16 17:47 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-11-16 17:47 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2013-11-16 17:47 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2013-11-16 17:47 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2013-11-16 17:47 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2013-11-16 17:47 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2013-11-16 17:47 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2013-11-16 17:47 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-11-16 17:47 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2013-11-16 17:47 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2013-11-16 17:47 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2013-11-16 17:47 - 2013-10-01 21:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-11-16 17:47 - 2013-10-01 21:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-11-16 17:43 - 2013-09-25 03:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2013-11-16 17:43 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2013-11-14 01:21 - 2013-11-14 01:21 - 00010240 _____ C:\Users\Thomas\Downloads\Doodle(9).xls 2013-11-13 00:57 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-11-13 00:51 - 2013-11-13 00:51 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-13 00:51 - 2013-11-13 00:51 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-13 00:50 - 2013-11-13 00:50 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-13 00:50 - 2013-11-13 00:50 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-13 00:50 - 2013-11-13 00:50 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-13 00:50 - 2013-11-13 00:50 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-13 00:50 - 2013-11-13 00:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-13 00:50 - 2013-11-13 00:50 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-13 00:50 - 2013-11-13 00:50 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-13 00:50 - 2013-11-13 00:50 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-13 00:50 - 2013-11-13 00:50 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-13 00:50 - 2013-11-13 00:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-13 00:47 - 2013-11-13 00:57 - 00010277 _____ C:\Windows\IE11_main.log 2013-11-13 00:33 - 2013-11-19 15:55 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-13 00:05 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-13 00:05 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-13 00:04 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-13 00:04 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-13 00:04 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-13 00:04 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-13 00:04 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-13 00:04 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-13 00:04 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-13 00:04 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-13 00:04 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-13 00:04 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-13 00:04 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-13 00:04 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-13 00:04 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-13 00:04 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-13 00:04 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-13 00:03 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-13 00:03 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-13 00:03 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-13 00:03 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-13 00:03 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-13 00:03 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-13 00:03 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-13 00:03 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-13 00:02 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-13 00:02 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-13 00:02 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-13 00:02 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-13 00:02 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-12 17:56 - 2013-11-12 18:14 - 00028672 _____ C:\Users\Thomas\Downloads\Doodle(8).xls 2013-11-11 11:45 - 2013-11-11 11:45 - 00007168 _____ C:\Users\Thomas\serienbrief_2.xls 2013-11-11 11:38 - 2013-11-11 11:38 - 00034816 _____ C:\Users\Thomas\rp_abgleich_bewerber.xls 2013-11-11 11:37 - 2013-11-11 11:40 - 00038912 _____ C:\Users\Thomas\rp_ka_abgleich_bewerber.xls 2013-11-11 00:09 - 2013-11-11 00:34 - 00000000 ____D C:\Users\Thomas\.freemind 2013-11-11 00:09 - 2013-11-11 00:09 - 00001097 _____ C:\Users\Thomas\Desktop\FreeMind.lnk 2013-11-11 00:09 - 2013-11-11 00:09 - 00000000 ____D C:\Program Files (x86)\FreeMind 2013-11-11 00:02 - 2013-11-11 00:03 - 37618815 _____ ( ) C:\Users\Thomas\Downloads\FreeMind-Windows-Installer-1.0.0-max.exe 2013-11-10 18:59 - 2013-11-10 19:11 - 00011264 ___SH C:\Users\Thomas\AppData\Roaming\Thumbs.db 2013-11-09 20:55 - 2013-11-09 20:55 - 00000000 ____D C:\Program Files (x86)\Sibelius Software 2013-11-09 20:46 - 2013-11-09 20:46 - 22889984 _____ C:\Users\Thomas\Downloads\ScorchAllBrowsersInstaller.msi 2013-11-09 02:46 - 2013-11-09 02:48 - 00292576 _____ C:\Windows\Minidump\110913-33602-01.dmp 2013-11-07 19:42 - 2013-11-07 19:42 - 00003146 _____ C:\Windows\System32\Tasks\{5D59FAC7-C7D9-4C92-A816-88158946F109} 2013-11-07 18:59 - 2013-11-09 02:46 - 948084901 _____ C:\Windows\MEMORY.DMP 2013-11-07 18:59 - 2013-11-07 18:59 - 00262144 _____ C:\Windows\Minidump\110713-33711-01.dmp 2013-11-07 16:47 - 2013-11-07 16:46 - 00009728 _____ C:\Users\Thomas\Downloads\Doodle(7).xls 2013-11-06 13:40 - 2013-11-06 13:40 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\TeamViewer 2013-11-06 13:18 - 2013-11-06 13:18 - 00000000 ____D C:\Users\Thomas\Downloads\PendiqSiliconLabs(1) 2013-11-06 13:09 - 2013-11-06 13:09 - 03484663 _____ C:\Users\Thomas\Downloads\PendiqSiliconLabs(1).zip 2013-11-06 12:25 - 2013-11-06 12:28 - 17664344 _____ C:\Users\Thomas\Downloads\SiDiary_Update_V6(1).exe 2013-11-06 12:23 - 2013-11-06 12:23 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_silabser_01009.Wdf 2013-11-05 18:32 - 2013-11-10 00:07 - 00181208 _____ C:\Users\Thomas\AppData\Local\GDIPFONTCACHEV1.DAT 2013-11-05 18:30 - 2013-11-19 15:52 - 00004208 _____ C:\Windows\setupact.log 2013-11-05 18:30 - 2013-11-11 07:40 - 00589984 _____ C:\Windows\system32\FNTCACHE.DAT 2013-11-05 18:30 - 2013-11-05 18:30 - 00000000 _____ C:\Windows\setuperr.log 2013-11-05 18:29 - 2013-11-19 09:31 - 00005230 _____ C:\Windows\PFRO.log 2013-11-01 22:44 - 2013-11-01 22:44 - 00009216 _____ C:\Users\Thomas\Downloads\Doodle(6).xls 2013-10-30 22:13 - 2013-10-30 22:12 - 03073266 _____ C:\Users\Thomas\Downloads\mobackup_0421205-790[680].zip 2013-10-28 08:03 - 2013-10-28 08:03 - 00000000 ____D C:\Users\dell\AppData\Roaming\TuneUp Software 2013-10-27 21:41 - 2013-10-27 21:41 - 00000000 ____D C:\Program Files (x86)\Silabs 2013-10-27 21:40 - 2013-10-27 21:41 - 00000000 ____D C:\Users\Thomas\Downloads\PendiqSiliconLabs 2013-10-27 21:40 - 2013-10-27 21:40 - 03484663 _____ C:\Users\Thomas\Downloads\PendiqSiliconLabs.zip 2013-10-27 21:31 - 2013-10-27 21:31 - 00001013 _____ C:\Users\Public\Desktop\Audacity.lnk 2013-10-25 16:09 - 2013-10-25 16:09 - 00000000 ____D C:\Users\dell\AppData\Roaming\AVAST Software 2013-10-25 16:08 - 2013-10-25 16:08 - 00000000 ____D C:\Users\dell\AppData\Roaming\Adobe 2013-10-25 16:06 - 2013-10-25 16:06 - 00000000 ____D C:\Users\dell\AppData\Local\Google 2013-10-24 19:12 - 2013-10-24 19:14 - 106320416 _____ C:\Users\Thomas\Downloads\Nokia_Suite_webinstaller_ALL(1).exe 2013-10-24 16:19 - 2013-10-24 16:19 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\AVAST Software 2013-10-22 11:26 - 2013-10-22 11:26 - 22180353 _____ (Audacity Team ) C:\Users\Thomas\Downloads\audacity-win-2.0.5.exe ==================== One Month Modified Files and Folders ======= 2013-11-19 16:13 - 2013-11-16 20:18 - 00028097 _____ C:\Users\Thomas\Downloads\FRST.txt 2013-11-19 16:12 - 2013-11-19 16:11 - 01957964 _____ (Farbar) C:\Users\Thomas\Downloads\FRST64 (1).exe 2013-11-19 16:07 - 2013-11-19 16:07 - 00002408 _____ C:\Users\Thomas\Desktop\JRT.txt 2013-11-19 16:02 - 2009-07-14 05:45 - 00021504 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-19 16:02 - 2009-07-14 05:45 - 00021504 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-19 16:00 - 2013-02-07 03:04 - 00703102 _____ C:\Windows\system32\perfh007.dat 2013-11-19 16:00 - 2013-02-07 03:04 - 00150392 _____ C:\Windows\system32\perfc007.dat 2013-11-19 16:00 - 2009-07-14 06:13 - 01629362 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-19 15:58 - 2013-11-19 15:58 - 00000000 ____D C:\Windows\ERUNT 2013-11-19 15:57 - 2013-11-19 15:57 - 01034531 _____ (Thisisu) C:\Users\Thomas\Downloads\JRT.exe 2013-11-19 15:56 - 2013-03-08 20:37 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Dropbox 2013-11-19 15:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\tracing 2013-11-19 15:55 - 2013-11-13 00:33 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-19 15:55 - 2013-02-08 13:27 - 00000000 ___RD C:\Users\Thomas\Dropbox 2013-11-19 15:54 - 2013-11-19 15:54 - 00027736 _____ C:\Users\Thomas\Desktop\AdwCleaner[S0].txt 2013-11-19 15:54 - 2013-03-17 18:24 - 00000000 ____D C:\ProgramData\VMware 2013-11-19 15:52 - 2013-11-05 18:30 - 00004208 _____ C:\Windows\setupact.log 2013-11-19 15:52 - 2013-03-08 23:38 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-19 15:52 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-19 15:51 - 2013-02-06 18:10 - 01803723 _____ C:\Windows\WindowsUpdate.log 2013-11-19 15:47 - 2013-11-19 15:43 - 00000000 ____D C:\AdwCleaner 2013-11-19 15:47 - 2013-09-21 23:27 - 00000601 _____ C:\Users\Thomas\Desktop\Search.lnk 2013-11-19 15:38 - 2013-02-07 03:56 - 00000000 ____D C:\Users\Thomas\Documents\Outlook-Dateien 2013-11-19 15:36 - 2013-11-19 15:36 - 01085542 _____ C:\Users\Thomas\Desktop\adwcleaner.exe 2013-11-19 11:18 - 2013-11-19 08:05 - 00000000 ____D C:\Users\Thomas\Desktop\mbar 2013-11-19 10:09 - 2013-11-19 08:09 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2013-11-19 10:08 - 2013-11-19 08:07 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-11-19 10:07 - 2013-02-07 03:54 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\vlc 2013-11-19 09:36 - 2013-02-22 00:20 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\dvdcss 2013-11-19 09:32 - 2013-03-01 10:49 - 00000000 ____D C:\Users\postgres 2013-11-19 09:31 - 2013-11-05 18:29 - 00005230 _____ C:\Windows\PFRO.log 2013-11-19 09:31 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\addins 2013-11-19 08:09 - 2013-11-19 08:09 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-19 07:59 - 2013-11-19 07:58 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Thomas\Downloads\mbar-1.07.0.1007.exe 2013-11-19 04:52 - 2013-03-08 23:09 - 00000502 _____ C:\Windows\Tasks\Personal Backup VideoAudioNachNAS.job 2013-11-19 03:36 - 2013-02-08 12:44 - 00000156 _____ C:\Users\Thomas\AppData\Roaming\default.rss 2013-11-19 02:10 - 2013-02-12 01:53 - 00000506 _____ C:\Windows\Tasks\Personal Backup DateienThomasNachZ3.job 2013-11-18 22:24 - 2013-08-12 22:27 - 00001093 _____ C:\Users\Public\Desktop\WinTV 7.lnk 2013-11-18 22:24 - 2013-02-14 15:52 - 00000401 _____ C:\Windows\ODBCINST.INI 2013-11-18 22:24 - 2013-02-14 15:52 - 00000135 _____ C:\Windows\ODBC.INI 2013-11-18 22:23 - 2013-03-08 21:50 - 00000000 ____D C:\ProgramData\Package Cache 2013-11-18 22:19 - 2013-08-12 22:24 - 00000000 ____D C:\Users\Public\WinTV 2013-11-18 22:19 - 2013-02-14 17:09 - 00000000 ____D C:\Program Files (x86)\WinTV 2013-11-18 22:19 - 2010-01-18 13:42 - 00037639 _____ C:\Windows\Irremote.ini 2013-11-18 22:18 - 2013-08-12 22:24 - 00003124 _____ C:\Windows\HCWPNP.INI 2013-11-18 22:18 - 2013-02-14 15:46 - 00426047 _____ C:\hcwDriverInstall.txt 2013-11-18 22:18 - 2013-02-06 18:20 - 00000000 ____D C:\Program Files (x86)\InstallShield Installation Information 2013-11-18 22:17 - 2009-07-14 03:34 - 00000246 _____ C:\Windows\system.ini 2013-11-18 22:16 - 2013-02-14 16:28 - 00000000 ____D C:\Hauppauge 2013-11-18 20:22 - 2013-11-18 20:19 - 146279768 _____ C:\Users\Thomas\Downloads\wintv7_cd_3.1a.exe 2013-11-18 06:23 - 2013-02-06 20:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-17 04:30 - 2013-02-07 03:54 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\PersBackup5 2013-11-16 23:16 - 2013-11-16 23:15 - 00034957 _____ C:\Users\Thomas\Downloads\logfiles.zip 2013-11-16 21:55 - 2013-11-16 21:55 - 00199379 _____ C:\Users\Thomas\Downloads\Gmer.txt 2013-11-16 21:39 - 2013-11-16 21:39 - 00377856 _____ C:\Users\Thomas\Downloads\gmer_2.1.19163.exe 2013-11-16 21:39 - 2013-11-16 21:39 - 00377856 _____ C:\Users\Thomas\Downloads\1rg9ry1l.exe 2013-11-16 21:14 - 2013-02-12 01:12 - 00002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-11-16 21:11 - 2013-02-23 18:03 - 00000000 ____D C:\Users\Thomas\AppData\Local\FreePDF_XP 2013-11-16 20:21 - 2013-11-16 20:20 - 00044726 _____ C:\Users\Thomas\Downloads\Addition.txt 2013-11-16 20:17 - 2013-11-16 20:17 - 01957794 _____ (Farbar) C:\Users\Thomas\Downloads\FRST64.exe 2013-11-16 20:17 - 2013-11-16 20:17 - 00000000 ____D C:\FRST 2013-11-16 20:15 - 2013-11-16 20:15 - 00000474 _____ C:\Users\Thomas\Downloads\defogger_disable.log 2013-11-16 20:15 - 2013-11-16 20:15 - 00000000 _____ C:\Users\Thomas\defogger_reenable 2013-11-16 20:15 - 2013-11-16 20:14 - 00050477 _____ C:\Users\Thomas\Downloads\Defogger.exe 2013-11-16 20:15 - 2013-02-07 07:23 - 00000000 ____D C:\Users\Thomas 2013-11-16 19:48 - 2013-11-16 19:48 - 25393512 _____ (PortableApps.com) C:\Users\Thomas\Downloads\firefoxportable_25.0_german.paf.exe 2013-11-16 19:46 - 2013-06-27 09:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-16 19:46 - 2013-02-06 20:15 - 00001153 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-11-16 19:17 - 2013-11-16 19:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\WhiteListing 2013-11-16 19:17 - 2013-11-16 19:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\TBHostSupport 2013-11-16 19:17 - 2013-11-16 19:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\NativeMessaging 2013-11-16 19:05 - 2013-11-16 19:05 - 23115760 _____ (Mozilla) C:\Users\Thomas\Downloads\firefox_setup_25.0.1.exe 2013-11-16 18:52 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-16 18:09 - 2013-11-16 18:09 - 00283184 _____ (Mozilla) C:\Users\Thomas\Downloads\Firefox Setup Stub 25_0_1_exe 2013-11-14 01:21 - 2013-11-14 01:21 - 00010240 _____ C:\Users\Thomas\Downloads\Doodle(9).xls 2013-11-13 06:32 - 2013-02-07 07:24 - 00001427 _____ C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-13 06:23 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-13 00:57 - 2013-11-13 00:47 - 00010277 _____ C:\Windows\IE11_main.log 2013-11-13 00:51 - 2013-11-13 00:51 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-13 00:51 - 2013-11-13 00:51 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-13 00:50 - 2013-11-13 00:50 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-13 00:50 - 2013-11-13 00:50 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-13 00:50 - 2013-11-13 00:50 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-13 00:50 - 2013-11-13 00:50 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-13 00:50 - 2013-11-13 00:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-13 00:50 - 2013-11-13 00:50 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-13 00:50 - 2013-11-13 00:50 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-13 00:50 - 2013-11-13 00:50 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-13 00:50 - 2013-11-13 00:50 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-13 00:50 - 2013-11-13 00:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-13 00:32 - 2013-02-07 03:06 - 00000000 ____D C:\Windows\Panther 2013-11-13 00:23 - 2013-02-06 23:25 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-13 00:18 - 2013-07-12 21:19 - 00000000 ____D C:\Windows\system32\MRT 2013-11-13 00:11 - 2013-02-06 19:48 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-12 19:41 - 2013-02-07 03:54 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Audacity 2013-11-12 18:14 - 2013-11-12 17:56 - 00028672 _____ C:\Users\Thomas\Downloads\Doodle(8).xls 2013-11-12 17:42 - 2013-02-07 03:54 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\FileZilla 2013-11-11 11:52 - 2013-02-07 03:54 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\postgresql 2013-11-11 11:45 - 2013-11-11 11:45 - 00007168 _____ C:\Users\Thomas\serienbrief_2.xls 2013-11-11 11:40 - 2013-11-11 11:37 - 00038912 _____ C:\Users\Thomas\rp_ka_abgleich_bewerber.xls 2013-11-11 11:40 - 2013-07-24 16:37 - 00014848 _____ C:\Users\Thomas\bewerber.xls 2013-11-11 11:38 - 2013-11-11 11:38 - 00034816 _____ C:\Users\Thomas\rp_abgleich_bewerber.xls 2013-11-11 07:40 - 2013-11-05 18:30 - 00589984 _____ C:\Windows\system32\FNTCACHE.DAT 2013-11-11 00:34 - 2013-11-11 00:09 - 00000000 ____D C:\Users\Thomas\.freemind 2013-11-11 00:09 - 2013-11-11 00:09 - 00001097 _____ C:\Users\Thomas\Desktop\FreeMind.lnk 2013-11-11 00:09 - 2013-11-11 00:09 - 00000000 ____D C:\Program Files (x86)\FreeMind 2013-11-11 00:09 - 2013-02-08 12:50 - 00001121 _____ C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\FreeMind.lnk 2013-11-11 00:03 - 2013-11-11 00:02 - 37618815 _____ ( ) C:\Users\Thomas\Downloads\FreeMind-Windows-Installer-1.0.0-max.exe 2013-11-10 20:12 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2013-11-10 20:11 - 2013-02-07 03:54 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\VMware 2013-11-10 19:11 - 2013-11-10 18:59 - 00011264 ___SH C:\Users\Thomas\AppData\Roaming\Thumbs.db 2013-11-10 19:00 - 2013-02-08 01:44 - 00002850 _____ C:\Users\Thomas\Documents\pgadmin.log 2013-11-10 18:53 - 2013-03-17 18:29 - 00000000 ____D C:\Program Files (x86)\svpbw10 2013-11-10 18:29 - 2013-02-07 03:54 - 00000000 ____D C:\Users\Thomas\AppData\Local\Microsoft Help 2013-11-10 00:07 - 2013-11-05 18:32 - 00181208 _____ C:\Users\Thomas\AppData\Local\GDIPFONTCACHEV1.DAT 2013-11-09 20:55 - 2013-11-09 20:55 - 00000000 ____D C:\Program Files (x86)\Sibelius Software 2013-11-09 20:46 - 2013-11-09 20:46 - 22889984 _____ C:\Users\Thomas\Downloads\ScorchAllBrowsersInstaller.msi 2013-11-09 02:48 - 2013-11-09 02:46 - 00292576 _____ C:\Windows\Minidump\110913-33602-01.dmp 2013-11-09 02:46 - 2013-11-07 18:59 - 948084901 _____ C:\Windows\MEMORY.DMP 2013-11-09 02:46 - 2013-02-14 15:56 - 00000000 ____D C:\Windows\Minidump 2013-11-08 19:05 - 2013-02-07 00:42 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2013-11-08 14:03 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-11-08 13:33 - 2013-10-17 21:39 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\LavasoftStatistics 2013-11-07 19:42 - 2013-11-07 19:42 - 00003146 _____ C:\Windows\System32\Tasks\{5D59FAC7-C7D9-4C92-A816-88158946F109} 2013-11-07 18:59 - 2013-11-07 18:59 - 00262144 _____ C:\Windows\Minidump\110713-33711-01.dmp 2013-11-07 16:46 - 2013-11-07 16:47 - 00009728 _____ C:\Users\Thomas\Downloads\Doodle(7).xls 2013-11-06 13:40 - 2013-11-06 13:40 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\TeamViewer 2013-11-06 13:18 - 2013-11-06 13:18 - 00000000 ____D C:\Users\Thomas\Downloads\PendiqSiliconLabs(1) 2013-11-06 13:09 - 2013-11-06 13:09 - 03484663 _____ C:\Users\Thomas\Downloads\PendiqSiliconLabs(1).zip 2013-11-06 12:28 - 2013-11-06 12:25 - 17664344 _____ C:\Users\Thomas\Downloads\SiDiary_Update_V6(1).exe 2013-11-06 12:24 - 2013-02-10 16:58 - 00000000 ____D C:\Windows\Downloaded Installations 2013-11-06 12:23 - 2013-11-06 12:23 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_silabser_01009.Wdf 2013-11-05 18:30 - 2013-11-05 18:30 - 00000000 _____ C:\Windows\setuperr.log 2013-11-05 18:29 - 2013-03-11 17:48 - 00000000 ____D C:\Users\Thomas\.thumbnails 2013-11-05 15:21 - 2013-06-28 08:34 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Nero 2013-11-01 22:44 - 2013-11-01 22:44 - 00009216 _____ C:\Users\Thomas\Downloads\Doodle(6).xls 2013-10-30 22:12 - 2013-10-30 22:13 - 03073266 _____ C:\Users\Thomas\Downloads\mobackup_0421205-790[680].zip 2013-10-28 08:11 - 2013-02-06 23:25 - 00000000 ____D C:\Users\dell\AppData\Local\Microsoft Help 2013-10-28 08:03 - 2013-10-28 08:03 - 00000000 ____D C:\Users\dell\AppData\Roaming\TuneUp Software 2013-10-27 21:41 - 2013-10-27 21:41 - 00000000 ____D C:\Program Files (x86)\Silabs 2013-10-27 21:41 - 2013-10-27 21:40 - 00000000 ____D C:\Users\Thomas\Downloads\PendiqSiliconLabs 2013-10-27 21:40 - 2013-10-27 21:40 - 03484663 _____ C:\Users\Thomas\Downloads\PendiqSiliconLabs.zip 2013-10-27 21:31 - 2013-10-27 21:31 - 00001013 _____ C:\Users\Public\Desktop\Audacity.lnk 2013-10-27 21:31 - 2013-02-15 06:26 - 00000000 ____D C:\Program Files (x86)\Audacity 2013-10-25 16:09 - 2013-10-25 16:09 - 00000000 ____D C:\Users\dell\AppData\Roaming\AVAST Software 2013-10-25 16:09 - 2013-02-19 06:18 - 00167488 _____ C:\Users\dell\AppData\Local\GDIPFONTCACHEV1.DAT 2013-10-25 16:08 - 2013-10-25 16:08 - 00000000 ____D C:\Users\dell\AppData\Roaming\Adobe 2013-10-25 16:08 - 2013-02-06 18:18 - 00001427 _____ C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-10-25 16:08 - 2013-02-06 18:18 - 00000000 ___RD C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-25 16:08 - 2013-02-06 18:18 - 00000000 ___RD C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-10-25 16:06 - 2013-10-25 16:06 - 00000000 ____D C:\Users\dell\AppData\Local\Google 2013-10-24 21:48 - 2013-10-11 14:31 - 00002095 _____ C:\Users\Public\Desktop\Nokia Suite.lnk 2013-10-24 19:14 - 2013-10-24 19:12 - 106320416 _____ C:\Users\Thomas\Downloads\Nokia_Suite_webinstaller_ALL(1).exe 2013-10-24 16:34 - 2013-06-30 08:35 - 00016384 ___SH C:\Users\Thomas\Thumbs.db 2013-10-24 16:19 - 2013-10-24 16:19 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\AVAST Software 2013-10-24 01:39 - 2013-03-16 10:32 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-10-24 01:39 - 2013-03-16 10:32 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-10-24 01:39 - 2013-02-07 00:42 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-10-24 01:39 - 2013-02-07 00:42 - 00001972 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-10-24 01:39 - 2013-02-07 00:41 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-10-24 01:39 - 2013-02-07 00:41 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-10-24 01:39 - 2013-02-07 00:41 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-10-24 01:39 - 2013-02-07 00:41 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-10-24 01:39 - 2013-02-07 00:41 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-10-24 01:39 - 2013-02-07 00:40 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-10-24 01:37 - 2013-02-07 00:40 - 00000000 ____D C:\ProgramData\AVAST Software 2013-10-24 01:36 - 2013-02-07 00:41 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-10-23 09:47 - 2013-02-14 23:34 - 00000000 ____D C:\ProgramData\PC Suite 2013-10-22 23:34 - 2013-10-17 21:53 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-22 11:26 - 2013-10-22 11:26 - 22180353 _____ (Audacity Team ) C:\Users\Thomas\Downloads\audacity-win-2.0.5.exe Some content of TEMP: ==================== C:\Users\Thomas\AppData\Local\Temp\NOSEventMessages.dll C:\Users\Thomas\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-11 08:44 ==================== End Of Log ============================ |
19.11.2013, 16:44 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM) Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
20.11.2013, 21:35 | #9 |
| Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) das war ein Akt - habe törichter Weise nach 6 Stunden pausieren lassen wollen - ok, dass es das bei ESET nicht gibt weiß ich jetzt auch :-( Erst der Output von MBAM: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.19.07 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16428 Thomas :: DELL-PC [Administrator] 19.11.2013 17:10:22 mbam-log-2013-11-19 (17-10-22).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 279413 Laufzeit: 7 Minute(n), 13 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 5 C:\Users\Thomas\AppData\Local\Temp\mt_ffx\Delta (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Thomas\AppData\Local\Temp\mt_ffx\Delta\delta (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Thomas\AppData\Local\Temp\mt_ffx\Delta\delta\1.8.24.6 (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Thomas\AppData\Local\Temp\ct3288691 (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Thomas\AppData\Local\Temp\ct3297861 (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 7 C:\ministub.exe (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\dell\AppData\Local\Temp\71FE.tmp (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Thomas\Downloads\ASUSP8P67rev30AtherosAW_AR3011BluetoothDriverPackage_downloader_by_Downloadsourcede.exe (PUP.Optional.Somoto) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Thomas\Downloads\FreemakeVideoConverter_4.0.1.1(1).exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Thomas\Downloads\FreemakeVideoConverter_4.0.1.1(2).exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Thomas\Downloads\FreemakeVideoConverter_4.0.1.1.exe.part (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Thomas\Downloads\winamp564_full_emusic-7plus_de-de.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter ESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: Can not open internet# version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=e3251cf40a5dbe4fbb028ae15998bcf3 # engine=15946 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-11-19 10:40:37 # local_time=2013-11-19 11:40:37 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 83 1490490 161610709 0 0 # compatibility_mode=5893 16776573 100 94 27181 136530687 0 0 # scanned=890611 # found=1 # cleaned=0 # scan_time=21133 sh=53C11B5207C601089B069C33B7FBB6FBC8992360 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\2fb167cd-269772e6" ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=e3251cf40a5dbe4fbb028ae15998bcf3 # engine=15952 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-11-20 08:22:47 # local_time=2013-11-20 09:22:47 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 83 1568620 161688839 0 0 # compatibility_mode=5893 16776573 100 94 108911 136608817 0 0 # scanned=2194033 # found=4 # cleaned=0 # scan_time=64714 sh=53C11B5207C601089B069C33B7FBB6FBC8992360 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\2fb167cd-269772e6" sh=D95A3376A7C44D70C7458A674F16698FC03F597E ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="Z:\WIN_7\LWC\LwC\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\2fb167cd-269772e6.gz" sh=41450DA145E8D20C56990B71E74551320E3F5692 ft=0 fh=0000000000000000 vn="HTML/ScrInject.B.Gen virus" ac=I fn="Z:\WIN_7\LWC\Users\thomas\AppData\Local\Mozilla\Firefox\Profiles\dfaevt7t.default\Cache\4\C5\B7069d01.gz" sh=0C69EC11D15518161108F2445877D852F5C2BC9B ft=0 fh=0000000000000000 vn="Win32/Adware.Bundlore application" ac=I fn="Z:\WIN_7\LWC\Users\thomas\AppData\Local\Temp\hWUK+BdG.exe.part.gz" |
20.11.2013, 21:59 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) Nur Reste. Bitte mal TFC ausführen TFC - Temp File Cleaner Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
20.11.2013, 22:40 | #11 |
| Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) Noch eine Frage zu ESET: Der hat 4 Fehler gemeldet, sie aber nicht behoben. Sollte ich da nicht noch tätig werden? TFC ist gelaufen Code:
ATTFilter Getting user folders. Stopping running processes. Emptying Temp folders. User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: dell ->Temp folder emptied: 16746 bytes ->Temporary Internet Files folder emptied: 1832161 bytes ->FireFox cache emptied: 14455185 bytes User: postgres ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: Thomas ->Temp folder emptied: 57311159 bytes ->Temporary Internet Files folder emptied: 207711753 bytes ->Java cache emptied: 201926 bytes ->FireFox cache emptied: 247897310 bytes ->Google Chrome cache emptied: 102070538 bytes ->Flash cache emptied: 35052 bytes User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 6090663 bytes %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 44708 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 95605 bytes Emptying RecycleBin. Do not interrupt. RecycleBin emptied: 41674055394 bytes Process complete! Total Files Cleaned = 40.352,00 mb |
20.11.2013, 23:06 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) Nein wurde mit TFC gelöscht Sieht soweit ok aus Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat. Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie ) Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird. Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________ Logfiles bitte immer in CODE-Tags posten |
21.11.2013, 02:23 | #13 |
| Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) Danke, da ist wirklich viel rausgeflogen. Aber - die Werbung taucht immer noch im Firefox auf. Nennt sich lizardlinks.Ads und hat sich von den Aktionen bisher noch nicht beeindrucken lassen. Ein Fenster zeigt Werbung, die offensichtlich weiß, auf was für Seiten ich schon war (das wechslet). Das andere redet dauernd vom Abnehmen und überdeckt das erste. Solange ich die Fenster nicht geschlossen habe, kann ich meistens nichts vernünftiges mit den Seiten anfangen. Das hatte ich auch beim Internet Explorer und bei Chrome. Jetzt beim Trojanerboard kommt das nicht. Außerdem öffnet sich immer noch eine Seite mit related searches, was ich bisher auch nicht kannte und was die Fläche doch störend einschränkt. Ebenso kommen auf der rechten Seite immer noch Werbebilder. Ich habe jetzt mal bei add ons nachgesehen. Da ist ein lizardlink, den ich jetzt entfernt habe. Beim Start von firefox gibt es aber irgendein Programm, das dieses add wieder installieren will. Da weiß ich nicht, wo ich das abschalten kann. Außerdem habe ich noch adblock Plus aktiviert - allerdings funktionieren damit viele Websites nicht. Geändert von comtom (21.11.2013 um 02:47 Uhr) |
21.11.2013, 11:23 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) Die Werbepest nimmt kein Ende Lizard-Müll scheint wohl nich nicht in der DB vom adwCleaner zu sein und auch nicht in JRT. Pste bitte mal ein frisches FRST-Log
__________________ Logfiles bitte immer in CODE-Tags posten |
21.11.2013, 17:11 | #15 |
| Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) Vorbemerkung: Ich habe jetzt adblock Plus wieder deaktiviert. Die Aufforderung zur Neuinstallation von lizardlink kommt jetzt auch nicht mehr. Ebenso kommen im Moment die unerwünschten Werbungen und Suchanfragen rechts und links auf den Websites nicht mehr :-) Vielleicht fehlte ein Neustart... Und - wenn du noch fragst, ob es weitere Probleme gibt - ist da jetzt nur noch, dass das Runterfahren schlappe 130 Sekunden und der Neustart bis zur ersten Unterbrechung der Festplattenbewegungen 170 Sekunden brauchen. Und dass - wenn ich das zugegebenermaßen mit sehr großen Datenmengen befüllte Outlook starte, erst mal kein anderes Programm noch Ressourcen bekommt. Ich dachte, dass ein Computer mit Core 2 Duo Prozessor und 2,54GHz das besser verteilen könnte. Hier das aktuelle FRST: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-11-2013 Ran by Thomas (administrator) on DELL-PC on 21-11-2013 17:00:46 Running from C:\Users\Thomas\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe (Nokia) C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\pg_ctl.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (Hauppauge Computer Works) C:\Program Files (x86)\WinTV\Ir.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\postgres.exe (shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.2\bin\postgres.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Launcher.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (Hauppauge Computer Works, Inc.) C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe (Dropbox, Inc.) C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe (sw4you, Siegfried Weckmann) C:\Program Files (x86)\Hardcopy\hardcopy.exe () C:\Program Files (x86)\Hardcopy\HcDLL2_ex.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe (VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe (J. Rathlev, IEAP, Uni-Kiel) C:\Program Files\Personal Backup 5\Persbackup.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (VMware, Inc.) C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe (VMware, Inc.) C:\Program Files\VMware\VMware View\Client\Local Mode\vmware-authd.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.) C:\Program Files\VMware\VMware View\Client\bin\wsnm_usbctrl.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe (Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Farbar) C:\Users\Thomas\Downloads\FRST64 (2).exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-07-22] (IDT, Inc.) HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [592240 2011-01-04] (Alps Electric Co., Ltd.) HKLM\...\Run: [NVHotkey] - rundll32.exe C:\Windows\system32\nvHotkey.dll,Start HKCU\...\Run: [HP Officejet Pro 8600 (NET)] - C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2011-01-19] (Hewlett-Packard Company) HKCU\...\Run: [] - [x] HKCU\...\Run: [NokiaSuite.exe] - C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1090912 2013-10-02] (Nokia) HKCU\...\Run: [TBHostSupport] - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Thomas\AppData\Local\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin <===== ATTENTION MountPoints2: E - E:\AutoRun.exe MountPoints2: {3dfd66f3-3494-11e3-90a4-00234de93e13} - E:\AutoRun.exe MountPoints2: {b81eadf5-1eec-11e3-8f2b-f791e49f869d} - F:\AutoRun.exe MountPoints2: {b81eadfc-1eec-11e3-8f2b-f791e49f869d} - F:\AutoRun.exe MountPoints2: {b81eaea5-1eec-11e3-8f2b-f791e49f869d} - E:\AutoRun.exe MountPoints2: {dfd8099e-36e9-11e3-b92b-bf108e606330} - E:\AutoRun.exe HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC) HKLM-x32\...\Run: [FreePDF Assistant] - C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\avastui.exe [3567800 2013-10-24] (AVAST Software) HKU\dell\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKU\dell\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2011-01-19] (Hewlett-Packard Company) Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Hardcopy.LNK ShortcutTarget: Hardcopy.LNK -> C:\Program Files (x86)\Hardcopy\hardcopy.exe (sw4you, Siegfried Weckmann) Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Persbackup.lnk ShortcutTarget: Persbackup.lnk -> C:\Program Files\Personal Backup 5\Persbackup.exe (J. Rathlev, IEAP, Uni-Kiel) Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\simplicheck.lnk ShortcutTarget: simplicheck.lnk -> Q:\Program Files (x86)\simplitec\simplicheck\simplicheck.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM - DefaultScope value is missing. BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll (Microsoft Corporation.) Winsock: Catalog9 11 C:\Program Files\VMware\VMware View\Client\Local Mode\vsocklib.dll [346736] (VMware, Inc.) Winsock: Catalog9 12 C:\Program Files\VMware\VMware View\Client\Local Mode\vsocklib.dll [346736] (VMware, Inc.) Winsock: Catalog9-x64 11 C:\Program Files\VMware\VMware View\Client\Local Mode\x64\vsocklib.dll [446576] (VMware, Inc.) Winsock: Catalog9-x64 12 C:\Program Files\VMware\VMware View\Client\Local Mode\x64\vsocklib.dll [446576] (VMware, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.90.1 Tcpip\..\Interfaces\{361A5F24-DD38-4F2A-812C-45FDC0BCA813}: [NameServer]212.23.115.148 212.23.115.132 FireFox: ======== FF ProfilePath: C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: https://www.google.de/ FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20(shExpMatch(host%2C%20'(*.turntable.fm%7Cturntable.fm)')%20%26%26%20url.indexOf('.css')%20%3D%3D%20-1%20%26%26%20url.indexOf('.js')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1)%20%7B%20return%20'PROXY%20ab-us02.personalitycores.com%3A8000%3B%20PROXY%20ab-us03.personalitycores.com%3A8000%3B%20PROXY%20ab-us15.personalitycores.com%3A8000%3B%20PROXY%20ab-us22.personalitycores.com%3A8000%3B%20PROXY%20ab-us12.personalitycores.com%3A8000%3B%20PROXY%20ab-us10.personalitycores.com%3A8000%3B%20PROXY%20ab-us13.personalitycores.com%3A8000%3B%20PROXY%20ab-us08.personalitycores.com%3A8000%3B%20PROXY%20ab-us20.personalitycores.com%3A8000%3B%20PROXY%20ab-us11.personalitycores.com%3A8000%3B%20PROXY%20ab-us17.personalitycores.com%3A8000%3B%20PROXY%20ab-us21.personalitycores.com%3A8000%3B%20PROXY%20ab-us14.personalitycores.com%3A8000%3B%20PROXY%20ab-us18.personalitycores.com%3A8000%3B%20PROXY%20ab-us01.personalitycores.com%3A8000%3B%20PROXY%20ab-us09.personalitycores.com%3A8000%3B%20PROXY%20ab-us16.personalitycores.com%3A8000%3B%20PROXY%20ab-us07.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF NetworkProxy: "type", 2 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nokia.com/EnablerPlugin - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\searchplugins\aol-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: firefox - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\Extensions\firefox@lizardlink.biz.xpi FF Extension: jid1-QpHD8URtZWJC2A - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi FF Extension: speedanalysis03 - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\Extensions\speedanalysis03@SpeedAnalysis.com.xpi FF Extension: Adblock Plus - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ou3igakk.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF HKLM-x32\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com\ FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com\ FF HKLM-x32\...\Firefox\Extensions: [ytfmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\ FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\ Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR DefaultSearchURL: (Search the web) - hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss_Btisdt7&mntrId=B80F00234DE93E13&affID=121565&tt=160913_m3&tsp=5012 CHR DefaultSuggestURL: (Search the web) - "suggest_url": "", CHR Extension: (Freemake Youtube Download Button) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh\1.0.0_0 CHR Extension: (Freemake Video Converter) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0 CHR Extension: (Google Wallet) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.172_0 CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [kdneagjiboclldmglpjofpeipkbollcf] - C:\Users\Thomas\AppData\Local\CRE\kdneagjiboclldmglpjofpeipkbollcf.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx ==================== Services (Whitelisted) ================= R2 ALDITALKVerbindungsassistent_Service; C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [358968 2013-09-18] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-10-24] (AVAST Software) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-08-26] (Freemake) R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-08-26] (Ellora Assets Corp.) S3 HauppaugeTVServer; C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe [582144 2013-08-31] (Hauppauge Computer Works) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2409272 2013-10-11] (TuneUp Software) S3 ufad-ws60; C:\Program Files\VMware\VMware View\Client\Local Mode\vmware-ufad.exe [191024 2010-08-19] (VMware, Inc.) R2 VMAuthdService; C:\Program Files\VMware\VMware View\Client\Local Mode\vmware-authd.exe [113264 2011-03-26] (VMware, Inc.) R2 postgresql-8.4; C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N "postgresql-8.4" -D "C:/Program Files (x86)/PostgreSQL/8.4/data" -w [x] R2 postgresql-9.2; C:/Program Files (x86)/PostgreSQL/9.2/bin/pg_ctl.exe runservice -N "postgresql-9.2" -D "C:/Program Files (x86)/PostgreSQL/9.2/data" -w [x] S2 Util Lizardlink; "C:\Program Files (x86)\Lizardlink\bin\utilLizardlink.exe" [x] ==================== Drivers (Whitelisted) ==================== R3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31968 2012-10-08] (Wondershare) R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-10-24] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-10-24] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-24] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-24] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-10-24] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-11-08] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-10-24] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-10-24] () R3 AVMCOWAN; C:\Windows\System32\DRIVERS\AVMCOWAN.sys [79872 2009-06-10] (AVM GmbH) S3 azvusb; C:\Windows\System32\DRIVERS\azvusb.sys [54784 2009-08-24] (AzureWave Technologies, Inc.) R3 btaudio; C:\Windows\System32\drivers\btaudio.sys [135208 2008-05-21] (Broadcom Corporation.) R3 BTDriver; C:\Windows\System32\DRIVERS\btport.sys [44200 2008-02-05] (Broadcom Corporation.) R3 BTKRNL; C:\Windows\System32\DRIVERS\btkrnl.sys [1282472 2008-08-08] (Broadcom Corporation.) R3 BTWDNDIS; C:\Windows\System32\DRIVERS\btwdndis.sys [156456 2007-09-20] (Broadcom Corporation.) R3 btwhid; C:\Windows\System32\DRIVERS\btwhid.sys [71592 2008-03-11] (Broadcom Corporation.) R3 btwmodem; C:\Windows\System32\DRIVERS\btwmodem.sys [43944 2008-02-05] (Broadcom Corporation.) R3 BTWUSB; C:\Windows\System32\Drivers\btwusb.sys [56104 2008-08-04] (Broadcom Corporation.) R3 FUS2BASE; C:\Windows\System32\DRIVERS\fus2base.sys [696832 2009-06-10] (AVM Berlin) S3 GigasetGenericUSB_x64; C:\Windows\System32\DRIVERS\GigasetGenericUSB_x64.sys [54272 2009-02-20] (Siemens Home and Office Communication Devices GmbH & Co. KG) R3 hcwD9bda; C:\Windows\System32\drivers\hcwD9bda.sys [526720 2010-12-22] ( ) S3 hwdatacard; C:\Windows\SysWow64\DRIVERS\ewusbmdm.sys [115328 2008-07-24] (Huawei Technologies Co., Ltd.) R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.) S3 PCTV_NTAMD64; C:\Windows\System32\DRIVERS\pctv4XXe_amd64.sys [571552 2007-08-06] (Pinnacle Systems GmbH) S3 TTHID; C:\Windows\System32\DRIVERS\Cinergy_Hybrid-Stick_HID.sys [27944 2012-09-27] (DTV-DVB) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2012-11-16] (TuneUp Software) S3 UDXTTM6010; C:\Windows\System32\DRIVERS\UDXTTM6010.sys [841384 2012-09-27] () R2 vstor2-ws60; C:\Program Files\VMware\VMware View\Client\Local Mode\vstor2-ws60.sys [32816 2010-08-19] (VMware, Inc.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-21 16:59 - 2013-11-21 17:00 - 01957964 _____ (Farbar) C:\Users\Thomas\Downloads\FRST64 (2).exe 2013-11-20 22:32 - 2013-11-20 22:32 - 00448512 _____ (OldTimer Tools) C:\Users\Thomas\Downloads\TFC.exe 2013-11-20 02:10 - 2013-11-20 02:10 - 00000000 ____D C:\LwD 2013-11-19 17:41 - 2013-11-21 16:46 - 00065536 _____ C:\Windows\system32\Ikeext.etl 2013-11-19 17:39 - 2013-11-19 17:40 - 02347384 _____ (ESET) C:\Users\Thomas\Downloads\esetsmartinstaller_enu.exe 2013-11-19 17:07 - 2013-11-19 17:07 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Malwarebytes 2013-11-19 17:06 - 2013-11-19 17:06 - 00001115 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-19 17:06 - 2013-11-19 17:06 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-19 17:06 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-11-19 17:05 - 2013-11-19 17:05 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Thomas\Downloads\mbam-setup-1.75.0.1300.exe 2013-11-19 16:14 - 2013-11-19 16:14 - 00081249 _____ C:\Users\Thomas\Desktop\FRST.txt 2013-11-19 16:11 - 2013-11-19 16:12 - 01957964 _____ (Farbar) C:\Users\Thomas\Downloads\FRST64 (1).exe 2013-11-19 16:07 - 2013-11-19 16:07 - 00002408 _____ C:\Users\Thomas\Desktop\JRT.txt 2013-11-19 15:58 - 2013-11-19 15:58 - 00000000 ____D C:\Windows\ERUNT 2013-11-19 15:57 - 2013-11-19 15:57 - 01034531 _____ (Thisisu) C:\Users\Thomas\Downloads\JRT.exe 2013-11-19 15:54 - 2013-11-19 15:54 - 00027736 _____ C:\Users\Thomas\Desktop\AdwCleaner[S0].txt 2013-11-19 15:43 - 2013-11-19 15:47 - 00000000 ____D C:\AdwCleaner 2013-11-19 15:36 - 2013-11-19 15:36 - 01085542 _____ C:\Users\Thomas\Desktop\adwcleaner.exe 2013-11-19 08:09 - 2013-11-19 08:09 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-19 08:07 - 2013-11-19 10:08 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-11-19 08:05 - 2013-11-19 11:18 - 00000000 ____D C:\Users\Thomas\Desktop\mbar 2013-11-19 07:58 - 2013-11-19 07:59 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Thomas\Downloads\mbar-1.07.0.1007.exe 2013-11-18 20:19 - 2013-11-18 20:22 - 146279768 _____ C:\Users\Thomas\Downloads\wintv7_cd_3.1a.exe 2013-11-16 23:15 - 2013-11-16 23:16 - 00034957 _____ C:\Users\Thomas\Downloads\logfiles.zip 2013-11-16 21:55 - 2013-11-16 21:55 - 00199379 _____ C:\Users\Thomas\Downloads\Gmer.txt 2013-11-16 21:39 - 2013-11-16 21:39 - 00377856 _____ C:\Users\Thomas\Downloads\gmer_2.1.19163.exe 2013-11-16 21:39 - 2013-11-16 21:39 - 00377856 _____ C:\Users\Thomas\Downloads\1rg9ry1l.exe 2013-11-16 20:20 - 2013-11-16 20:21 - 00044726 _____ C:\Users\Thomas\Downloads\Addition.txt 2013-11-16 20:18 - 2013-11-21 17:01 - 00028561 _____ C:\Users\Thomas\Downloads\FRST.txt 2013-11-16 20:17 - 2013-11-16 20:17 - 01957794 _____ (Farbar) C:\Users\Thomas\Downloads\FRST64.exe 2013-11-16 20:17 - 2013-11-16 20:17 - 00000000 ____D C:\FRST 2013-11-16 20:15 - 2013-11-16 20:15 - 00000474 _____ C:\Users\Thomas\Downloads\defogger_disable.log 2013-11-16 20:15 - 2013-11-16 20:15 - 00000000 _____ C:\Users\Thomas\defogger_reenable 2013-11-16 20:14 - 2013-11-16 20:15 - 00050477 _____ C:\Users\Thomas\Downloads\Defogger.exe 2013-11-16 19:48 - 2013-11-16 19:48 - 25393512 _____ (PortableApps.com) C:\Users\Thomas\Downloads\firefoxportable_25.0_german.paf.exe 2013-11-16 19:17 - 2013-11-16 19:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\WhiteListing 2013-11-16 19:17 - 2013-11-16 19:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\TBHostSupport 2013-11-16 19:17 - 2013-11-16 19:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\NativeMessaging 2013-11-16 19:05 - 2013-11-16 19:05 - 23115760 _____ (Mozilla) C:\Users\Thomas\Downloads\firefox_setup_25.0.1.exe 2013-11-16 18:09 - 2013-11-16 18:09 - 00283184 _____ (Mozilla) C:\Users\Thomas\Downloads\Firefox Setup Stub 25_0_1_exe 2013-11-16 17:47 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2013-11-16 17:47 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2013-11-16 17:47 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2013-11-16 17:47 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2013-11-16 17:47 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2013-11-16 17:47 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-11-16 17:47 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2013-11-16 17:47 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2013-11-16 17:47 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2013-11-16 17:47 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2013-11-16 17:47 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2013-11-16 17:47 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2013-11-16 17:47 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-11-16 17:47 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2013-11-16 17:47 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2013-11-16 17:47 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2013-11-16 17:47 - 2013-10-01 21:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-11-16 17:47 - 2013-10-01 21:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-11-16 17:43 - 2013-09-25 03:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2013-11-16 17:43 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2013-11-14 01:21 - 2013-11-14 01:21 - 00010240 _____ C:\Users\Thomas\Downloads\Doodle(9).xls 2013-11-13 00:57 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-11-13 00:51 - 2013-11-13 00:51 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-13 00:51 - 2013-11-13 00:51 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-13 00:50 - 2013-11-13 00:50 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-13 00:50 - 2013-11-13 00:50 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-13 00:50 - 2013-11-13 00:50 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-13 00:50 - 2013-11-13 00:50 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-13 00:50 - 2013-11-13 00:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-13 00:50 - 2013-11-13 00:50 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-13 00:50 - 2013-11-13 00:50 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-13 00:50 - 2013-11-13 00:50 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-13 00:50 - 2013-11-13 00:50 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-13 00:50 - 2013-11-13 00:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-13 00:47 - 2013-11-13 00:57 - 00010277 _____ C:\Windows\IE11_main.log 2013-11-13 00:33 - 2013-11-19 17:36 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-13 00:05 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-13 00:05 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-13 00:04 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-13 00:04 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-13 00:04 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-13 00:04 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-13 00:04 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-13 00:04 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-13 00:04 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-13 00:04 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-13 00:04 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-13 00:04 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-13 00:04 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-13 00:04 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-13 00:04 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-13 00:04 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-13 00:04 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-13 00:03 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-13 00:03 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-13 00:03 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-13 00:03 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-13 00:03 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-13 00:03 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-13 00:03 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-13 00:03 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-13 00:02 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-13 00:02 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-13 00:02 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-13 00:02 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-13 00:02 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-12 17:56 - 2013-11-12 18:14 - 00028672 _____ C:\Users\Thomas\Downloads\Doodle(8).xls 2013-11-11 11:45 - 2013-11-11 11:45 - 00007168 _____ C:\Users\Thomas\serienbrief_2.xls 2013-11-11 11:38 - 2013-11-11 11:38 - 00034816 _____ C:\Users\Thomas\rp_abgleich_bewerber.xls 2013-11-11 11:37 - 2013-11-11 11:40 - 00038912 _____ C:\Users\Thomas\rp_ka_abgleich_bewerber.xls 2013-11-11 00:09 - 2013-11-11 00:34 - 00000000 ____D C:\Users\Thomas\.freemind 2013-11-11 00:09 - 2013-11-11 00:09 - 00001097 _____ C:\Users\Thomas\Desktop\FreeMind.lnk 2013-11-11 00:09 - 2013-11-11 00:09 - 00000000 ____D C:\Program Files (x86)\FreeMind 2013-11-11 00:02 - 2013-11-11 00:03 - 37618815 _____ ( ) C:\Users\Thomas\Downloads\FreeMind-Windows-Installer-1.0.0-max.exe 2013-11-10 18:59 - 2013-11-10 19:11 - 00011264 ___SH C:\Users\Thomas\AppData\Roaming\Thumbs.db 2013-11-09 20:55 - 2013-11-09 20:55 - 00000000 ____D C:\Program Files (x86)\Sibelius Software 2013-11-09 20:46 - 2013-11-09 20:46 - 22889984 _____ C:\Users\Thomas\Downloads\ScorchAllBrowsersInstaller.msi 2013-11-09 02:46 - 2013-11-09 02:48 - 00292576 _____ C:\Windows\Minidump\110913-33602-01.dmp 2013-11-07 19:42 - 2013-11-07 19:42 - 00003146 _____ C:\Windows\System32\Tasks\{5D59FAC7-C7D9-4C92-A816-88158946F109} 2013-11-07 18:59 - 2013-11-09 02:46 - 948084901 _____ C:\Windows\MEMORY.DMP 2013-11-07 18:59 - 2013-11-07 18:59 - 00262144 _____ C:\Windows\Minidump\110713-33711-01.dmp 2013-11-07 16:47 - 2013-11-07 16:46 - 00009728 _____ C:\Users\Thomas\Downloads\Doodle(7).xls 2013-11-06 13:40 - 2013-11-06 13:40 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\TeamViewer 2013-11-06 13:18 - 2013-11-06 13:18 - 00000000 ____D C:\Users\Thomas\Downloads\PendiqSiliconLabs(1) 2013-11-06 13:09 - 2013-11-06 13:09 - 03484663 _____ C:\Users\Thomas\Downloads\PendiqSiliconLabs(1).zip 2013-11-06 12:25 - 2013-11-06 12:28 - 17664344 _____ C:\Users\Thomas\Downloads\SiDiary_Update_V6(1).exe 2013-11-06 12:23 - 2013-11-06 12:23 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_silabser_01009.Wdf 2013-11-05 18:32 - 2013-11-10 00:07 - 00181208 _____ C:\Users\Thomas\AppData\Local\GDIPFONTCACHEV1.DAT 2013-11-05 18:30 - 2013-11-21 16:46 - 00004376 _____ C:\Windows\setupact.log 2013-11-05 18:30 - 2013-11-11 07:40 - 00589984 _____ C:\Windows\system32\FNTCACHE.DAT 2013-11-05 18:30 - 2013-11-05 18:30 - 00000000 _____ C:\Windows\setuperr.log 2013-11-05 18:29 - 2013-11-21 16:46 - 00009254 _____ C:\Windows\PFRO.log 2013-11-01 22:44 - 2013-11-01 22:44 - 00009216 _____ C:\Users\Thomas\Downloads\Doodle(6).xls 2013-10-30 22:13 - 2013-10-30 22:12 - 03073266 _____ C:\Users\Thomas\Downloads\mobackup_0421205-790[680].zip 2013-10-28 08:03 - 2013-10-28 08:03 - 00000000 ____D C:\Users\dell\AppData\Roaming\TuneUp Software 2013-10-27 21:41 - 2013-10-27 21:41 - 00000000 ____D C:\Program Files (x86)\Silabs 2013-10-27 21:40 - 2013-10-27 21:41 - 00000000 ____D C:\Users\Thomas\Downloads\PendiqSiliconLabs 2013-10-27 21:40 - 2013-10-27 21:40 - 03484663 _____ C:\Users\Thomas\Downloads\PendiqSiliconLabs.zip 2013-10-27 21:31 - 2013-10-27 21:31 - 00001013 _____ C:\Users\Public\Desktop\Audacity.lnk 2013-10-25 16:09 - 2013-10-25 16:09 - 00000000 ____D C:\Users\dell\AppData\Roaming\AVAST Software 2013-10-25 16:08 - 2013-10-25 16:08 - 00000000 ____D C:\Users\dell\AppData\Roaming\Adobe 2013-10-25 16:06 - 2013-10-25 16:06 - 00000000 ____D C:\Users\dell\AppData\Local\Google 2013-10-24 19:12 - 2013-10-24 19:14 - 106320416 _____ C:\Users\Thomas\Downloads\Nokia_Suite_webinstaller_ALL(1).exe 2013-10-24 16:19 - 2013-10-24 16:19 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\AVAST Software 2013-10-22 11:26 - 2013-10-22 11:26 - 22180353 _____ (Audacity Team ) C:\Users\Thomas\Downloads\audacity-win-2.0.5.exe ==================== One Month Modified Files and Folders ======= 2013-11-21 17:01 - 2013-11-16 20:18 - 00028561 _____ C:\Users\Thomas\Downloads\FRST.txt 2013-11-21 17:00 - 2013-11-21 16:59 - 01957964 _____ (Farbar) C:\Users\Thomas\Downloads\FRST64 (2).exe 2013-11-21 16:58 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\tracing 2013-11-21 16:57 - 2009-07-14 05:45 - 00021504 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-21 16:57 - 2009-07-14 05:45 - 00021504 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-21 16:52 - 2013-02-06 18:10 - 01853952 _____ C:\Windows\WindowsUpdate.log 2013-11-21 16:48 - 2013-03-17 18:24 - 00000000 ____D C:\ProgramData\VMware 2013-11-21 16:48 - 2013-03-08 20:37 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Dropbox 2013-11-21 16:48 - 2013-02-08 13:27 - 00000000 ___RD C:\Users\Thomas\Dropbox 2013-11-21 16:47 - 2013-03-01 10:49 - 00000000 ____D C:\Users\postgres 2013-11-21 16:46 - 2013-11-19 17:41 - 00065536 _____ C:\Windows\system32\Ikeext.etl 2013-11-21 16:46 - 2013-11-05 18:30 - 00004376 _____ C:\Windows\setupact.log 2013-11-21 16:46 - 2013-11-05 18:29 - 00009254 _____ C:\Windows\PFRO.log 2013-11-21 16:46 - 2013-03-08 23:38 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-21 16:46 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-21 16:43 - 2013-02-07 03:56 - 00000000 ____D C:\Users\Thomas\Documents\Outlook-Dateien 2013-11-21 14:11 - 2013-02-08 12:44 - 00000188 _____ C:\Users\Thomas\AppData\Roaming\default.rss 2013-11-21 11:34 - 2013-02-07 03:54 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\vlc 2013-11-21 10:59 - 2013-02-22 00:20 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\dvdcss 2013-11-21 04:54 - 2013-03-08 23:09 - 00000502 _____ C:\Windows\Tasks\Personal Backup VideoAudioNachNAS.job 2013-11-21 02:22 - 2013-02-12 01:53 - 00000506 _____ C:\Windows\Tasks\Personal Backup DateienThomasNachZ3.job 2013-11-20 22:32 - 2013-11-20 22:32 - 00448512 _____ (OldTimer Tools) C:\Users\Thomas\Downloads\TFC.exe 2013-11-20 22:25 - 2013-02-07 03:54 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\FileZilla 2013-11-20 03:23 - 2013-02-07 07:24 - 00000000 ___RD C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-11-20 02:10 - 2013-11-20 02:10 - 00000000 ____D C:\LwD 2013-11-20 02:08 - 2013-02-07 03:56 - 00000000 ____D C:\Users\Thomas\Documents\PersBackup 2013-11-20 00:29 - 2013-02-07 07:23 - 00000000 ____D C:\Users\Thomas 2013-11-20 00:28 - 2013-02-12 01:12 - 00000000 ____D C:\Program Files\Recuva 2013-11-19 17:46 - 2013-02-07 03:04 - 00703102 _____ C:\Windows\system32\perfh007.dat 2013-11-19 17:46 - 2013-02-07 03:04 - 00150392 _____ C:\Windows\system32\perfc007.dat 2013-11-19 17:46 - 2009-07-14 06:13 - 01629362 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-19 17:40 - 2013-11-19 17:39 - 02347384 _____ (ESET) C:\Users\Thomas\Downloads\esetsmartinstaller_enu.exe 2013-11-19 17:36 - 2013-11-13 00:33 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-19 17:33 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-11-19 17:07 - 2013-11-19 17:07 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Malwarebytes 2013-11-19 17:06 - 2013-11-19 17:06 - 00001115 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-19 17:06 - 2013-11-19 17:06 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-19 17:05 - 2013-11-19 17:05 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Thomas\Downloads\mbam-setup-1.75.0.1300.exe 2013-11-19 16:14 - 2013-11-19 16:14 - 00081249 _____ C:\Users\Thomas\Desktop\FRST.txt 2013-11-19 16:12 - 2013-11-19 16:11 - 01957964 _____ (Farbar) C:\Users\Thomas\Downloads\FRST64 (1).exe 2013-11-19 16:07 - 2013-11-19 16:07 - 00002408 _____ C:\Users\Thomas\Desktop\JRT.txt 2013-11-19 15:58 - 2013-11-19 15:58 - 00000000 ____D C:\Windows\ERUNT 2013-11-19 15:57 - 2013-11-19 15:57 - 01034531 _____ (Thisisu) C:\Users\Thomas\Downloads\JRT.exe 2013-11-19 15:54 - 2013-11-19 15:54 - 00027736 _____ C:\Users\Thomas\Desktop\AdwCleaner[S0].txt 2013-11-19 15:47 - 2013-11-19 15:43 - 00000000 ____D C:\AdwCleaner 2013-11-19 15:47 - 2013-09-21 23:27 - 00000601 _____ C:\Users\Thomas\Desktop\Search.lnk 2013-11-19 15:47 - 2013-02-07 03:54 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Uniblue 2013-11-19 15:36 - 2013-11-19 15:36 - 01085542 _____ C:\Users\Thomas\Desktop\adwcleaner.exe 2013-11-19 11:18 - 2013-11-19 08:05 - 00000000 ____D C:\Users\Thomas\Desktop\mbar 2013-11-19 10:08 - 2013-11-19 08:07 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-11-19 09:31 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\addins 2013-11-19 08:09 - 2013-11-19 08:09 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-19 07:59 - 2013-11-19 07:58 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Thomas\Downloads\mbar-1.07.0.1007.exe 2013-11-18 22:24 - 2013-08-12 22:27 - 00001093 _____ C:\Users\Public\Desktop\WinTV 7.lnk 2013-11-18 22:24 - 2013-02-14 15:52 - 00000401 _____ C:\Windows\ODBCINST.INI 2013-11-18 22:24 - 2013-02-14 15:52 - 00000135 _____ C:\Windows\ODBC.INI 2013-11-18 22:23 - 2013-03-08 21:50 - 00000000 ____D C:\ProgramData\Package Cache 2013-11-18 22:19 - 2013-08-12 22:24 - 00000000 ____D C:\Users\Public\WinTV 2013-11-18 22:19 - 2013-02-14 17:09 - 00000000 ____D C:\Program Files (x86)\WinTV 2013-11-18 22:19 - 2010-01-18 13:42 - 00037639 _____ C:\Windows\Irremote.ini 2013-11-18 22:18 - 2013-08-12 22:24 - 00003124 _____ C:\Windows\HCWPNP.INI 2013-11-18 22:18 - 2013-02-14 15:46 - 00426047 _____ C:\hcwDriverInstall.txt 2013-11-18 22:18 - 2013-02-06 18:20 - 00000000 ____D C:\Program Files (x86)\InstallShield Installation Information 2013-11-18 22:17 - 2009-07-14 03:34 - 00000246 _____ C:\Windows\system.ini 2013-11-18 22:16 - 2013-02-14 16:28 - 00000000 ____D C:\Hauppauge 2013-11-18 20:22 - 2013-11-18 20:19 - 146279768 _____ C:\Users\Thomas\Downloads\wintv7_cd_3.1a.exe 2013-11-18 06:23 - 2013-02-06 20:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-17 04:30 - 2013-02-07 03:54 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\PersBackup5 2013-11-16 23:16 - 2013-11-16 23:15 - 00034957 _____ C:\Users\Thomas\Downloads\logfiles.zip 2013-11-16 21:55 - 2013-11-16 21:55 - 00199379 _____ C:\Users\Thomas\Downloads\Gmer.txt 2013-11-16 21:39 - 2013-11-16 21:39 - 00377856 _____ C:\Users\Thomas\Downloads\gmer_2.1.19163.exe 2013-11-16 21:39 - 2013-11-16 21:39 - 00377856 _____ C:\Users\Thomas\Downloads\1rg9ry1l.exe 2013-11-16 21:14 - 2013-02-12 01:12 - 00002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-11-16 21:11 - 2013-02-23 18:03 - 00000000 ____D C:\Users\Thomas\AppData\Local\FreePDF_XP 2013-11-16 20:21 - 2013-11-16 20:20 - 00044726 _____ C:\Users\Thomas\Downloads\Addition.txt 2013-11-16 20:17 - 2013-11-16 20:17 - 01957794 _____ (Farbar) C:\Users\Thomas\Downloads\FRST64.exe 2013-11-16 20:17 - 2013-11-16 20:17 - 00000000 ____D C:\FRST 2013-11-16 20:15 - 2013-11-16 20:15 - 00000474 _____ C:\Users\Thomas\Downloads\defogger_disable.log 2013-11-16 20:15 - 2013-11-16 20:15 - 00000000 _____ C:\Users\Thomas\defogger_reenable 2013-11-16 20:15 - 2013-11-16 20:14 - 00050477 _____ C:\Users\Thomas\Downloads\Defogger.exe 2013-11-16 19:48 - 2013-11-16 19:48 - 25393512 _____ (PortableApps.com) C:\Users\Thomas\Downloads\firefoxportable_25.0_german.paf.exe 2013-11-16 19:46 - 2013-06-27 09:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-16 19:46 - 2013-02-06 20:15 - 00001153 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-11-16 19:17 - 2013-11-16 19:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\WhiteListing 2013-11-16 19:17 - 2013-11-16 19:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\TBHostSupport 2013-11-16 19:17 - 2013-11-16 19:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\NativeMessaging 2013-11-16 19:05 - 2013-11-16 19:05 - 23115760 _____ (Mozilla) C:\Users\Thomas\Downloads\firefox_setup_25.0.1.exe 2013-11-16 18:52 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-16 18:09 - 2013-11-16 18:09 - 00283184 _____ (Mozilla) C:\Users\Thomas\Downloads\Firefox Setup Stub 25_0_1_exe 2013-11-14 01:21 - 2013-11-14 01:21 - 00010240 _____ C:\Users\Thomas\Downloads\Doodle(9).xls 2013-11-13 06:32 - 2013-02-07 07:24 - 00001427 _____ C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-13 06:23 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-13 00:57 - 2013-11-13 00:47 - 00010277 _____ C:\Windows\IE11_main.log 2013-11-13 00:51 - 2013-11-13 00:51 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-13 00:51 - 2013-11-13 00:51 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-13 00:50 - 2013-11-13 00:50 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-13 00:50 - 2013-11-13 00:50 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-13 00:50 - 2013-11-13 00:50 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-13 00:50 - 2013-11-13 00:50 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-13 00:50 - 2013-11-13 00:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-13 00:50 - 2013-11-13 00:50 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-13 00:50 - 2013-11-13 00:50 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-13 00:50 - 2013-11-13 00:50 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-13 00:50 - 2013-11-13 00:50 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-13 00:50 - 2013-11-13 00:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-13 00:50 - 2013-11-13 00:50 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-13 00:50 - 2013-11-13 00:50 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-13 00:32 - 2013-02-07 03:06 - 00000000 ____D C:\Windows\Panther 2013-11-13 00:23 - 2013-02-06 23:25 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-13 00:18 - 2013-07-12 21:19 - 00000000 ____D C:\Windows\system32\MRT 2013-11-13 00:11 - 2013-02-06 19:48 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-12 19:41 - 2013-02-07 03:54 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Audacity 2013-11-12 18:14 - 2013-11-12 17:56 - 00028672 _____ C:\Users\Thomas\Downloads\Doodle(8).xls 2013-11-11 11:52 - 2013-02-07 03:54 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\postgresql 2013-11-11 11:45 - 2013-11-11 11:45 - 00007168 _____ C:\Users\Thomas\serienbrief_2.xls 2013-11-11 11:40 - 2013-11-11 11:37 - 00038912 _____ C:\Users\Thomas\rp_ka_abgleich_bewerber.xls 2013-11-11 11:40 - 2013-07-24 16:37 - 00014848 _____ C:\Users\Thomas\bewerber.xls 2013-11-11 11:38 - 2013-11-11 11:38 - 00034816 _____ C:\Users\Thomas\rp_abgleich_bewerber.xls 2013-11-11 07:40 - 2013-11-05 18:30 - 00589984 _____ C:\Windows\system32\FNTCACHE.DAT 2013-11-11 00:34 - 2013-11-11 00:09 - 00000000 ____D C:\Users\Thomas\.freemind 2013-11-11 00:09 - 2013-11-11 00:09 - 00001097 _____ C:\Users\Thomas\Desktop\FreeMind.lnk 2013-11-11 00:09 - 2013-11-11 00:09 - 00000000 ____D C:\Program Files (x86)\FreeMind 2013-11-11 00:09 - 2013-02-08 12:50 - 00001121 _____ C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\FreeMind.lnk 2013-11-11 00:03 - 2013-11-11 00:02 - 37618815 _____ ( ) C:\Users\Thomas\Downloads\FreeMind-Windows-Installer-1.0.0-max.exe 2013-11-10 20:12 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2013-11-10 20:11 - 2013-02-07 03:54 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\VMware 2013-11-10 19:11 - 2013-11-10 18:59 - 00011264 ___SH C:\Users\Thomas\AppData\Roaming\Thumbs.db 2013-11-10 19:00 - 2013-02-08 01:44 - 00002850 _____ C:\Users\Thomas\Documents\pgadmin.log 2013-11-10 18:53 - 2013-03-17 18:29 - 00000000 ____D C:\Program Files (x86)\svpbw10 2013-11-10 18:29 - 2013-02-07 03:54 - 00000000 ____D C:\Users\Thomas\AppData\Local\Microsoft Help 2013-11-10 00:07 - 2013-11-05 18:32 - 00181208 _____ C:\Users\Thomas\AppData\Local\GDIPFONTCACHEV1.DAT 2013-11-09 20:55 - 2013-11-09 20:55 - 00000000 ____D C:\Program Files (x86)\Sibelius Software 2013-11-09 20:46 - 2013-11-09 20:46 - 22889984 _____ C:\Users\Thomas\Downloads\ScorchAllBrowsersInstaller.msi 2013-11-09 02:48 - 2013-11-09 02:46 - 00292576 _____ C:\Windows\Minidump\110913-33602-01.dmp 2013-11-09 02:46 - 2013-11-07 18:59 - 948084901 _____ C:\Windows\MEMORY.DMP 2013-11-09 02:46 - 2013-02-14 15:56 - 00000000 ____D C:\Windows\Minidump 2013-11-08 19:05 - 2013-02-07 00:42 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2013-11-08 14:03 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-11-08 13:33 - 2013-10-17 21:39 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\LavasoftStatistics 2013-11-07 19:42 - 2013-11-07 19:42 - 00003146 _____ C:\Windows\System32\Tasks\{5D59FAC7-C7D9-4C92-A816-88158946F109} 2013-11-07 18:59 - 2013-11-07 18:59 - 00262144 _____ C:\Windows\Minidump\110713-33711-01.dmp 2013-11-07 16:46 - 2013-11-07 16:47 - 00009728 _____ C:\Users\Thomas\Downloads\Doodle(7).xls 2013-11-06 13:40 - 2013-11-06 13:40 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\TeamViewer 2013-11-06 13:18 - 2013-11-06 13:18 - 00000000 ____D C:\Users\Thomas\Downloads\PendiqSiliconLabs(1) 2013-11-06 13:09 - 2013-11-06 13:09 - 03484663 _____ C:\Users\Thomas\Downloads\PendiqSiliconLabs(1).zip 2013-11-06 12:28 - 2013-11-06 12:25 - 17664344 _____ C:\Users\Thomas\Downloads\SiDiary_Update_V6(1).exe 2013-11-06 12:24 - 2013-02-10 16:58 - 00000000 ____D C:\Windows\Downloaded Installations 2013-11-06 12:23 - 2013-11-06 12:23 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_silabser_01009.Wdf 2013-11-05 18:30 - 2013-11-05 18:30 - 00000000 _____ C:\Windows\setuperr.log 2013-11-05 18:29 - 2013-03-11 17:48 - 00000000 ____D C:\Users\Thomas\.thumbnails 2013-11-05 15:21 - 2013-06-28 08:34 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Nero 2013-11-01 22:44 - 2013-11-01 22:44 - 00009216 _____ C:\Users\Thomas\Downloads\Doodle(6).xls 2013-10-30 22:12 - 2013-10-30 22:13 - 03073266 _____ C:\Users\Thomas\Downloads\mobackup_0421205-790[680].zip 2013-10-28 08:11 - 2013-02-06 23:25 - 00000000 ____D C:\Users\dell\AppData\Local\Microsoft Help 2013-10-28 08:03 - 2013-10-28 08:03 - 00000000 ____D C:\Users\dell\AppData\Roaming\TuneUp Software 2013-10-27 21:41 - 2013-10-27 21:41 - 00000000 ____D C:\Program Files (x86)\Silabs 2013-10-27 21:41 - 2013-10-27 21:40 - 00000000 ____D C:\Users\Thomas\Downloads\PendiqSiliconLabs 2013-10-27 21:40 - 2013-10-27 21:40 - 03484663 _____ C:\Users\Thomas\Downloads\PendiqSiliconLabs.zip 2013-10-27 21:31 - 2013-10-27 21:31 - 00001013 _____ C:\Users\Public\Desktop\Audacity.lnk 2013-10-27 21:31 - 2013-02-15 06:26 - 00000000 ____D C:\Program Files (x86)\Audacity 2013-10-25 16:09 - 2013-10-25 16:09 - 00000000 ____D C:\Users\dell\AppData\Roaming\AVAST Software 2013-10-25 16:09 - 2013-02-19 06:18 - 00167488 _____ C:\Users\dell\AppData\Local\GDIPFONTCACHEV1.DAT 2013-10-25 16:08 - 2013-10-25 16:08 - 00000000 ____D C:\Users\dell\AppData\Roaming\Adobe 2013-10-25 16:08 - 2013-02-06 18:18 - 00001427 _____ C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-10-25 16:08 - 2013-02-06 18:18 - 00000000 ___RD C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-25 16:08 - 2013-02-06 18:18 - 00000000 ___RD C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-10-25 16:06 - 2013-10-25 16:06 - 00000000 ____D C:\Users\dell\AppData\Local\Google 2013-10-24 21:48 - 2013-10-11 14:31 - 00002095 _____ C:\Users\Public\Desktop\Nokia Suite.lnk 2013-10-24 19:14 - 2013-10-24 19:12 - 106320416 _____ C:\Users\Thomas\Downloads\Nokia_Suite_webinstaller_ALL(1).exe 2013-10-24 16:34 - 2013-06-30 08:35 - 00016384 ___SH C:\Users\Thomas\Thumbs.db 2013-10-24 16:19 - 2013-10-24 16:19 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\AVAST Software 2013-10-24 01:39 - 2013-03-16 10:32 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-10-24 01:39 - 2013-03-16 10:32 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-10-24 01:39 - 2013-02-07 00:42 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-10-24 01:39 - 2013-02-07 00:42 - 00001972 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-10-24 01:39 - 2013-02-07 00:41 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-10-24 01:39 - 2013-02-07 00:41 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-10-24 01:39 - 2013-02-07 00:41 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-10-24 01:39 - 2013-02-07 00:41 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-10-24 01:39 - 2013-02-07 00:41 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-10-24 01:39 - 2013-02-07 00:40 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-10-24 01:37 - 2013-02-07 00:40 - 00000000 ____D C:\ProgramData\AVAST Software 2013-10-24 01:36 - 2013-02-07 00:41 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-10-23 09:47 - 2013-02-14 23:34 - 00000000 ____D C:\ProgramData\PC Suite 2013-10-22 23:34 - 2013-10-17 21:53 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-22 11:26 - 2013-10-22 11:26 - 22180353 _____ (Audacity Team ) C:\Users\Thomas\Downloads\audacity-win-2.0.5.exe Some content of TEMP: ==================== C:\Users\Thomas\AppData\Local\Temp\NOSEventMessages.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-11 08:44 ==================== End Of Log ============================ --- --- --- |
Themen zu Firefox lässt sich nicht mehr starten, auch nicht nach Neuinstallation (Win 7 prof. 64-Bit) |
adware.installbrain, anwendung, browser, browserfenster, firefox, funktionieren, html/scrinject.b.gen, internet explorer, logdatei, neuinstallation, nicht mehr, programm, pup.optional.conduit.a, pup.optional.delta.a, pup.optional.opencandy, pup.optional.somoto, rogue.internetsecurityessentials, schließen, taskmanager, trojan:js/medfos.b, tv-karte, welchem, werbung, win32/adware.bundlore, windows 7 64 bit |