|
Plagegeister aller Art und deren Bekämpfung: Ungwollte Startseite/Suchmaschine: " http://www.searchnu.com/413" - wie entferne ich das?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
08.12.2013, 13:32 | #1 |
| Ungwollte Startseite/Suchmaschine: " http://www.searchnu.com/413" - wie entferne ich das? Hallo zusammen, bei Mozilla erscheint seit einiger Zeit die neue Startseite hxxp://www.searchnu.com/413 die anscheinend auch als Suchmaschine arbeitet. Ich habe gesehen, dass es bereits viele andere Themen zu dem Problem gibt und möchte auch nicht nerven - da ihr aber sagt,dass jedes Problem etwas anders ist, erlaube ich mir mal dieses Thema zu eröffnen. Da ich auf meinem anderen Laptop ein ähnliches Problem mit wise search hatte, habe ich mal die erste Anleitung die ich da bekam gemacht und poste hier eine FRST log und die addition schon mal. Vielen Dank schon mal Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-12-2013 02 Ran by Admin (administrator) on AYELEN-VAIO on 08-12-2013 13:28:29 Running from C:\Users\Admin\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Bandoo Media, inc) C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe (Apple Inc.) C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7938080 2009-07-24] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-07-24] (Realtek Semiconductor Corp.) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [208384 2009-08-03] (Alps Electric Co., Ltd.) HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe [186904 2009-06-04] (Intel Corporation) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Java\jre6\bin\jusched.exe [171520 2009-08-17] (Sun Microsystems, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM-x32\...\Run: [ISBMgr.exe] - C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [317288 2009-05-26] (Sony Corporation) HKLM-x32\...\Run: [MarketingTools] - C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [26624 2009-09-05] (Sony Corporation) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-09-08] (Apple Inc.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3460784 2011-04-18] (AVAST Software) HKLM-x32\...\Run: [DATAMNGR] - C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe [1694608 2011-11-10] (Bandoo Media, inc) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [38872 2012-07-31] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [919008 2012-07-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [49208 2011-05-10] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-05-30] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [421776 2012-06-07] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKU\Ayelen\...\Run: [msnmsgr] - "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background HKU\Ayelen\...\Run: [HP Deskjet 3070 B611 series (NET)] - C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\ScanToPCActivationApp.exe [2676584 2011-06-08] (Hewlett-Packard Co.) AppInit_DLLs: C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\x64\IEBHO.dll [1791384 2011-11-10] (Bandoo Media, inc) AppInit_DLLs-x32: C:\PROGRA~2\WIA6EB~1\Datamngr\datamngr.dll C:\PROGRA~2\WIA6EB~1\Datamngr\IEBHO.dll [1233816 2011-11-10] (Bandoo Media, inc) Startup: C:\Users\Ayelen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File) Startup: C:\Users\Ayelen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\Ayelen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_01.09.2010_10-16.lnk ShortcutTarget: setup_9.0.0.722_01.09.2010_10-16.lnk -> C:\Users\Admin\Desktop\Virus Removal Tool\setup_9.0.0.722_01.09.2010_10-16\startup.exe (No File) Startup: C:\Users\Ayelen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3070 B611 series (Netzwerk).lnk ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 3070 B611 series (Netzwerk).lnk -> C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=SVEA&bmod=EU01 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SVEA&bmod=EU01 URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} URLSearchHook: HKLM-x32 - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=413&sr=0&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=413&sr=0&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=413&sr=0&q={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=413&sr=0&q={searchTerms} SearchScopes: HKCU - DefaultScope {A6A8E986-A77C-4D4C-A6D9-5A6420E7770C} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta SearchScopes: HKCU - {3E774340-48D5-4C1A-B79D-BD6D6E4C10D2} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-0/4?satitle={searchTerms} SearchScopes: HKCU - {A6A8E986-A77C-4D4C-A6D9-5A6420E7770C} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta SearchScopes: HKCU - {FBF7DC4A-FC99-482F-A6D3-B73399875CB0} URL = hxxp://services.zinio.com/search?s={selection}&rf=sonyslices BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\x64\BrowserConnection.dll (Bandoo Media, inc) BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll () BHO-x32: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM-x32 - Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll () DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: HKLM-x32 {888078C6-70B2-4F88-8EE7-1F50DDEA6120} https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4530x7tp.default FF Homepage: hxxp://www.searchqu.com/413 FF Keyword.URL: hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=413&sr=0&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4530x7tp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433} FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! WebRep - C:\Program Files\AVAST Software\Avast\WebRep\FF ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [42184 2011-04-18] (AVAST Software) S3 Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [313840 2009-06-26] (Sonic Solutions) S2 Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [362992 2009-06-26] (Sonic Solutions) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [189984 2009-07-24] (Realtek Semiconductor) S3 SOHDBSvr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-07-27] (Sony Corporation) S3 SOHPlMgr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-07-27] (Sony Corporation) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-07-23] (Sony Corporation) R2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [642920 2009-07-22] (Sony Corporation) R3 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-07-23] (Sony Corporation) R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1368624 2013-08-01] (Sony Corporation) R2 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [206336 2009-07-23] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R1 15749921; C:\Windows\System32\DRIVERS\15749921.sys [157712 2009-09-25] (Kaspersky Lab) R0 15749922; C:\Windows\System32\DRIVERS\15749922.sys [40464 2009-10-22] (Kaspersky Lab) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [22360 2011-04-18] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [64344 2011-04-18] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [31064 2011-04-18] (AVAST Software) R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [600920 2011-04-18] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [287064 2011-04-18] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [53592 2011-04-18] (AVAST Software) R2 risdptsk; C:\Windows\system32\DRIVERS\risdsn64.sys [76288 2009-07-31] (REDC) R1 setup_9.0.0.722_01.09.2010_10-16drv; C:\Windows\System32\DRIVERS\1574992.sys [352784 2009-10-09] (Kaspersky Lab) S3 USBET; C:\Windows\System32\DRIVERS\ETdrv.sys [6409344 2010-11-10] (Etron) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-08 13:28 - 2013-12-08 13:28 - 00019596 _____ C:\Users\Admin\Downloads\FRST.txt 2013-12-08 13:28 - 2013-12-08 13:28 - 00000000 ____D C:\FRST 2013-12-08 13:27 - 2013-12-08 13:27 - 01927772 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe 2013-12-06 22:54 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-12-06 22:49 - 2013-12-06 22:49 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-06 22:49 - 2013-12-06 22:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-06 22:49 - 2013-12-06 22:49 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-06 22:49 - 2013-12-06 22:49 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-06 22:49 - 2013-12-06 22:49 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-06 22:49 - 2013-12-06 22:49 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-06 22:49 - 2013-12-06 22:49 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-06 22:49 - 2013-12-06 22:49 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-06 22:49 - 2013-12-06 22:49 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-06 22:49 - 2013-12-06 22:49 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-06 22:49 - 2013-12-06 22:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-06 22:48 - 2013-12-06 22:54 - 00010277 _____ C:\Windows\IE11_main.log 2013-11-23 19:18 - 2013-11-23 19:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-15 02:18 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-15 02:18 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-15 02:17 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-15 02:17 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-15 02:17 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-15 02:17 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-15 02:17 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-15 02:17 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-15 02:17 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-15 02:17 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-15 02:17 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-15 02:17 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-15 02:17 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-15 02:17 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-15 02:17 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-15 02:17 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-15 02:17 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-15 02:17 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-15 02:17 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-15 02:17 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-15 02:17 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-15 02:17 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-15 02:17 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-15 02:17 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-15 02:17 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-15 02:17 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-15 02:17 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-15 02:17 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-15 02:17 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-15 02:17 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys ==================== One Month Modified Files and Folders ======= 2013-12-08 13:28 - 2013-12-08 13:28 - 00019596 _____ C:\Users\Admin\Downloads\FRST.txt 2013-12-08 13:28 - 2013-12-08 13:28 - 00000000 ____D C:\FRST 2013-12-08 13:27 - 2013-12-08 13:27 - 01927772 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe 2013-12-08 13:14 - 2010-01-05 13:58 - 01356215 _____ C:\Windows\WindowsUpdate.log 2013-12-08 13:00 - 2009-09-05 13:09 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-08 12:48 - 2012-06-10 11:52 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-08 12:22 - 2013-04-12 22:46 - 00003942 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{08D4C479-6A0F-404A-9EB8-BDDBFE7B3B66} 2013-12-08 12:21 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-08 12:21 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-08 12:17 - 2013-04-12 22:45 - 00001421 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-08 12:17 - 2009-09-05 13:09 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-08 12:15 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-08 12:15 - 2009-07-14 05:51 - 00180805 _____ C:\Windows\setupact.log 2013-12-08 12:14 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-06 22:54 - 2013-12-06 22:48 - 00010277 _____ C:\Windows\IE11_main.log 2013-12-06 22:49 - 2013-12-06 22:49 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-06 22:49 - 2013-12-06 22:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-06 22:49 - 2013-12-06 22:49 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-06 22:49 - 2013-12-06 22:49 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-06 22:49 - 2013-12-06 22:49 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-06 22:49 - 2013-12-06 22:49 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-06 22:49 - 2013-12-06 22:49 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-06 22:49 - 2013-12-06 22:49 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-06 22:49 - 2013-12-06 22:49 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-06 22:49 - 2013-12-06 22:49 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-06 22:49 - 2013-12-06 22:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-06 13:54 - 2012-04-23 14:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-06 13:54 - 2009-09-05 13:42 - 00594432 _____ C:\Windows\PFRO.log 2013-11-27 20:23 - 2013-11-07 10:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox.bak 2013-11-27 20:17 - 2013-04-12 22:42 - 00000000 ____D C:\Users\Admin 2013-11-23 19:49 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-23 19:18 - 2013-11-23 19:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-23 19:06 - 2009-07-14 18:58 - 00654400 _____ C:\Windows\system32\perfh007.dat 2013-11-23 19:06 - 2009-07-14 18:58 - 00130240 _____ C:\Windows\system32\perfc007.dat 2013-11-23 19:06 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-15 02:50 - 2009-09-05 13:23 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-15 02:47 - 2013-08-31 09:05 - 00000000 ____D C:\Windows\system32\MRT 2013-11-15 02:45 - 2010-02-23 13:31 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\AskSLib.dll C:\Users\Admin\AppData\Local\Temp\fszgpjb-.dll C:\Users\Admin\AppData\Local\Temp\SkypeSetup.exe C:\Users\Ayelen\AppData\Local\Temp\ose00000.exe C:\Users\Ayelen\AppData\Local\Temp\SkypeSetup.exe C:\Users\Ayelen\AppData\Local\Temp\_is1FFE.exe C:\Users\Ayelen\AppData\Local\Temp\_is9E32.exe C:\Users\Ayelen\AppData\Local\Temp\_isAE58.exe C:\Users\Ayelen\AppData\Local\Temp\_isEC52.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-06 14:35 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-12-2013 02 Ran by Admin at 2013-12-08 13:30:11 Running from C:\Users\Admin\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C} AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe AIR (x32 Version: 2.7.0.19480) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Reader 9.5.2 - Deutsch (x32 Version: 9.5.2) Advertising Center (x32 Version: 0.0.0.2) Alps Pointing-device for VAIO Apple Application Support (x32 Version: 2.1.9) Apple Mobile Device Support (Version: 5.2.0.6) Apple Software Update (x32 Version: 2.1.3.127) ArcSoft Magic-i Visual Effects 2 (x32 Version: 2.0.1.85) ArcSoft WebCam Companion 3 (x32 Version: 3.0.21.390) avast! Free Antivirus (x32 Version: 6.0.1091.0) Bonjour (Version: 3.0.0.10) Click to Disc (x32 Version: 1.2.70.06160) Click to Disc Editor (x32 Version: 2.0.02) Compatibility Pack für 2007 Office System (x32 Version: 12.0.6612.1000) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32) Einstellungen für VAIO-Inhaltsüberwachung (x32 Version: 2.4.0.06120) FLV Player 2.0 (build 25) (x32 Version: 2.0 (build 25)) Fragen-Lern-CD 4.0 (x32 Version: 4.0.1) Free DVD Video Converter version 1.5 (x32) Free FLV Converter V 7.2.0 (x32 Version: 7.1.0.0) Free Video to MP3 Converter version 4.0 (x32) FTP Commander (x32) GeoHTML (x32) GIMP 2.6.8 (x32) Google Update Helper (x32 Version: 1.3.21.165) HP Deskjet 3070 B611 series - Grundlegende Software für das Gerät (Version: 25.0.571.0) HP Deskjet 3070 B611 series Hilfe (x32 Version: 140.0.2.2) HP Update (x32 Version: 5.003.001.001) Intel(R) Graphics Media Accelerator Driver Intel® Matrix Storage Manager iTunes (Version: 10.6.3.25) Java 7 Update 25 (64-bit) (Version: 7.0.250) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) Java(TM) 6 Update 14 (64-bit) (Version: 6.0.140) Java(TM) 6 Update 33 (x32 Version: 6.0.330) Malwarebytes Anti-Malware Version 1.65.0.1400 (x32 Version: 1.65.0.1400) Media Go (x32 Version: 2.1.392) Media Go Video Playback Engine 1.88.116.12060 (x32 Version: 1.88.116.12060) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft Office 2010 Service Pack 1 (SP1) (x32) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office Home and Student 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office PowerPoint Viewer 2007 (German) (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Single Image 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Suite Activation Assistant (x32 Version: 2.9) Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SQL Server Compact 3.5 SP1 English (x32 Version: 3.5.5692.0) Microsoft SQL Server Compact 3.5 SP1 x64 English (Version: 3.5.5692.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable - KB2467175 (x32 Version: 8.0.51011) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Word 97 (x32) Microsoft Works (x32 Version: 9.7.0621) Mozilla Firefox 25.0.1 (x86 de) (x32 Version: 25.0.1) Mozilla Maintenance Service (x32 Version: 25.0.1) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) Music Transfer (x32 Version: 1.3.01.13160) MusicStation (x32 Version: 1.2.2.180) Nero 9 Lite (x32) Nero ControlCenter (x32 Version: 9.0.0.1) Nero Installer (x32 Version: 4.4.9.0) Nero Online Upgrade (x32 Version: 1.3.0.0) Nero StartSmart (x32 Version: 9.4.31.100) neroxml (x32 Version: 1.0.0) Nvu 1.0 (x32 Version: 1.0) NWZ-E460 WALKMAN Guide (x32 Version: 2.0.2.04130) OpenOffice.org 3.1 (x32 Version: 3.1.9420) Photo to Cartoon (x32 Version: 1.0.0) PhotoScape (x32) PlayStation(R)Network Downloader (x32 Version: 2.07.00849) PlayStation(R)Store (x32 Version: 4.8.1.14440) Primo (x32 Version: 1.00.0000) QuickTime (x32 Version: 7.68.75.0) Realtek High Definition Audio Driver (x32 Version: 6.0.1.5886) Roxio Central Audio (x32 Version: 3.8.0) Roxio Central Copy (x32 Version: 3.8.0) Roxio Central Core (x32 Version: 3.8.0) Roxio Central Data (x32 Version: 3.8.0) Roxio Central Tools (x32 Version: 3.8.0) Roxio Easy Media Creator 10 LJ (x32 Version: 10.3) Roxio Easy Media Creator Home (x32 Version: 10.3.121) Runtime (x32 Version: 1.00.0000) SAMSUNG USB Driver for Mobile Phones (Version: 1.4.4.0) Setting Utility Series (x32 Version: 5.0.0.07300) Skype Click to Call (x32 Version: 6.3.11079) Skype™ 6.0 (x32 Version: 6.0.126) Sony Home Network Library (x32 Version: 2.0.0.07280) Sony Picture Utility (x32 Version: 4.2.12.16210) Spelling Dictionaries Support For Adobe Reader 9 (x32 Version: 9.0.0) Spybot - Search & Destroy (x32 Version: 1.6.2) Uninstall 1.0.0.1 (x32) Unterstützung für VAIO-Präsentation (x32 Version: 2.0.0.05270) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32) Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2494150) (x32) Update for Microsoft Office 2010 (KB2553065) (x32) Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2566458) (x32) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32) Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32) Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32) Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32) Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition (x32) VAIO Content Metadata Intelligent Analyzing Manager (x32 Version: 3.5.0.06261) VAIO Content Metadata Intelligent Network Service Manager (x32 Version: 3.5.0.06260) VAIO Content Metadata Manager Settings (x32 Version: 3.5.0.06260) VAIO Content Metadata XML Interface Library (x32 Version: 3.5.0.06180) VAIO Content Monitoring Settings (x32 Version: 2.4.0.06120) VAIO Control Center (x32 Version: 4.0.0.06120) VAIO Data Restore Tool (x32 Version: 1.1.01.06290) VAIO DVD Menu Data Basic (x32 Version: 1.0.00.08130) VAIO Energie Verwaltung (x32 Version: 4.0.0.07160) VAIO Entertainment Platform (x32 Version: 3.5.0.07230) VAIO Event Service (x32 Version: 5.0.0.07010) VAIO Gate (x32 Version: 1.0.0.08050) VAIO Marketing Tools (x32) VAIO Media plus (x32 Version: 2.0.0.07280) VAIO Media plus Opening Movie (x32 Version: 1.2.0.09100) VAIO Movie Story (x32 Version: 1.5.00.06191) VAIO Movie Story Template Data (x32 Version: 1.5.00.06010) VAIO NW screensaver (x32 Version: 1.0.0.0) VAIO Original Function Settings (x32 Version: 2.0.0.07010) VAIO Original Funktion Einstellungen (x32 Version: 2.0.0.07010) VAIO Premium Partners 1.00 (x32) VAIO Quick Web Access (x32 Version: 1.1.2.4) VAIO Smart Network (x32 Version: 3.0.0.08120) VAIO Update (x32 Version: 6.3.0.08010) VAIO Wallpaper Contents (x32 Version: 2.0.0.06010) VAIO-Support für Übertragungen (x32 Version: 1.1.2.06030) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0) VLC media player 1.1.5 (x32 Version: 1.1.5) VU5x64 (Version: 1.1.0) VU5x86 (x32 Version: 1.0.0) VU5x86 (x32 Version: 1.1.0) WIDCOMM Bluetooth Software (Version: 6.2.0.9600) Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2) Windows Searchqu Toolbar (x32 Version: 3.0.0.117623) <==== ATTENTION XMedia Recode 2.3.3.3 (x32 Version: 2.3.3.3) Yahoo! Detect (x32) ==================== Restore Points ========================= 05-10-2013 14:01:08 Installiert VAIO Update 14-10-2013 01:00:57 Windows Update 28-10-2013 17:37:02 Geplanter Prüfpunkt 07-11-2013 11:04:54 Geplanter Prüfpunkt 15-11-2013 01:44:04 Windows Update 23-11-2013 18:47:55 Geplanter Prüfpunkt 06-12-2013 13:42:09 Geplanter Prüfpunkt 06-12-2013 21:47:39 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {4FF786D9-CD87-4E2B-A627-1B368586F8B3} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2013-08-01] (Sony Corporation) Task: {599D69EB-851C-42C4-930C-C7341F53B95E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {6AED8AFC-B1F6-4271-BED3-8DE0A1D1ED13} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-14] (Adobe Systems Incorporated) Task: {75C97007-3CD2-4B59-A07D-696D18A5CDEA} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2009-08-05] (Sony Corporation) Task: {A15955B1-8DD9-40BF-A2E9-23B825B97B24} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2009-09-05] (Google Inc.) Task: {C2DA41F7-F277-425E-8332-ADB4FB788475} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2013-08-01] (Sony Corporation) Task: {CAC29CFF-F80E-4E0B-96C4-08A4BBA3BAAE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2009-09-05] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-12-08 12:16 - 2013-12-06 20:24 - 02244096 _____ () C:\Program Files\AVAST Software\Avast\defs\13120601\algo.dll 2012-05-30 19:06 - 2012-05-30 19:06 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2012-05-30 19:06 - 2012-05-30 19:06 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2009-09-05 13:33 - 2009-07-01 10:49 - 00010752 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESBasePS.dll 2009-09-05 13:33 - 2009-07-01 10:49 - 00009728 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSubPS.dll 2013-11-23 19:18 - 2013-11-23 19:18 - 03363952 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Ayelen\Downloads\Lettera Rettori e Promemoria Esami Celi.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/08/2013 00:16:31 PM) (Source: VzCdbSvc) (User: ) Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019) Error: (12/06/2013 01:57:03 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL) Error: (12/06/2013 01:55:17 PM) (Source: VzCdbSvc) (User: ) Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019) Error: (11/27/2013 08:19:26 PM) (Source: VzCdbSvc) (User: ) Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019) Error: (11/23/2013 07:01:36 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL) Error: (11/23/2013 07:00:54 PM) (Source: VzCdbSvc) (User: ) Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019) Error: (11/15/2013 02:05:29 AM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL) Error: (11/15/2013 02:05:06 AM) (Source: VzCdbSvc) (User: ) Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019) Error: (11/07/2013 01:13:03 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 145144 Error: (11/07/2013 01:13:03 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 145144 System errors: ============= Error: (12/08/2013 00:15:45 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Roxio Upnp Server 10 erreicht. Error: (12/06/2013 01:56:06 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Installer" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/06/2013 01:56:06 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Installer erreicht. Error: (12/06/2013 01:56:06 PM) (Source: DCOM) (User: ) Description: 1053MSIServer{000C101C-0000-0000-C000-000000000046} Error: (12/06/2013 01:55:06 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Roxio Upnp Server 10 erreicht. Error: (12/06/2013 01:54:42 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 27.11.2013 um 23:56:52 unerwartet heruntergefahren. Error: (11/27/2013 08:18:45 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Roxio Upnp Server 10 erreicht. Error: (11/27/2013 08:17:04 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 26.11.2013 um 23:36:38 unerwartet heruntergefahren. Error: (11/23/2013 07:00:38 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Roxio Upnp Server 10 erreicht. Error: (11/15/2013 02:04:54 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Roxio Upnp Server 10 erreicht. Microsoft Office Sessions: ========================= Error: (12/08/2013 00:16:31 PM) (Source: VzCdbSvc)(User: ) Description: {56F9312C-C989-4E04-8C23-299DEE3A36F5}0x80042019 Error: (12/06/2013 01:57:03 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL) Error: (12/06/2013 01:55:17 PM) (Source: VzCdbSvc)(User: ) Description: {56F9312C-C989-4E04-8C23-299DEE3A36F5}0x80042019 Error: (11/27/2013 08:19:26 PM) (Source: VzCdbSvc)(User: ) Description: {56F9312C-C989-4E04-8C23-299DEE3A36F5}0x80042019 Error: (11/23/2013 07:01:36 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL) Error: (11/23/2013 07:00:54 PM) (Source: VzCdbSvc)(User: ) Description: {56F9312C-C989-4E04-8C23-299DEE3A36F5}0x80042019 Error: (11/15/2013 02:05:29 AM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL) Error: (11/15/2013 02:05:06 AM) (Source: VzCdbSvc)(User: ) Description: {56F9312C-C989-4E04-8C23-299DEE3A36F5}0x80042019 Error: (11/07/2013 01:13:03 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 145144 Error: (11/07/2013 01:13:03 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 145144 ==================== Memory info =========================== Percentage of memory in use: 38% Total physical RAM: 3935.02 MB Available physical RAM: 2407.15 MB Total Pagefile: 7868.22 MB Available Pagefile: 6146.63 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:288.75 GB) (Free:227.44 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 85CF8683) Partition 1: (Not Active) - (Size=9 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=289 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
08.12.2013, 13:52 | #2 |
/// Malwareteam | Ungwollte Startseite/Suchmaschine: " http://www.searchnu.com/413" - wie entferne ich das?Mein Name ist Heiko, ich werde dir bei deinem Problem helfen. Die Bereinigung deines Systems ist individuell auf dich zugeschnitten und mitunter mit viel Arbeit für uns beide verbunden. Bitte Lesen: Regeln für die Bereinigung Eine Bereinigung beinhaltet nebst dem Entfernen von Malware auch das Schließn von Sicherheitslücken und sollte gründlich durchgeführt werden. Sie erfolgt deshalb in mehreren Schritten und bedeutet einigen Aufwand für dich. Beachte: Das Verschwinden der offensichtlichen Symptome bedeutet nicht, dass das System schon sauber ist. Lese Dir die Anleitung zuerst vollständig durch. Sollte etwas unklar sein, frage bevor Du mit der abarbeitung der Schritte beginnst.
Hinweis: Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist meist der schnellere und immer der sicherste Weg. Dann fangen wir mal mit Schritt 1 an: Deinstalliere bitte Sypbot Search and Destroy Schritt 2: Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 3: erstelle ein neues FRST Logfile und poste es hier, besteht das Problem mit search.nu nach dem ausführen von ADWcleaner immernoch?
__________________ |
08.12.2013, 14:30 | #3 |
| Ungwollte Startseite/Suchmaschine: " http://www.searchnu.com/413" - wie entferne ich das? Hallo Heiko, danke für die schnelle Antwort. Nach dem ADW Cleaner ist die Seite schon verschwunden Muss ich jetzt noch was beachten, oder sind wir schon fertig? LG
__________________adw log: Code:
ATTFilter # AdwCleaner v3.014 - Bericht erstellt am 08/12/2013 um 14:22:28 # Updated 01/12/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Admin - AYELEN-VAIO # Gestartet von : C:\Users\Admin\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\boost_interprocess Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar Ordner Gelöscht : C:\ProgramData\Partner Ordner Gelöscht : C:\Program Files (x86)\ICQ6Toolbar Ordner Gelöscht : C:\Program Files (x86)\Windows Searchqu Toolbar Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB Ordner Gelöscht : C:\Users\Ayelen\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\Ayelen\AppData\LocalLow\searchquband Ordner Gelöscht : C:\Users\Ayelen\AppData\LocalLow\Searchqutoolbar Ordner Gelöscht : C:\Users\Ayelen\AppData\Roaming\FissaSearch Ordner Gelöscht : C:\Users\Ayelen\AppData\Roaming\freeTVRadio Ordner Gelöscht : C:\Users\Ayelen\AppData\Roaming\Mozilla\Firefox\Profiles\cedywuar.default\Conduit Ordner Gelöscht : C:\Users\Ayelen\AppData\Roaming\Mozilla\Firefox\Profiles\cedywuar.default\ICQToolbarData Ordner Gelöscht : C:\Users\Ayelen\AppData\Roaming\Mozilla\Firefox\Profiles\cedywuar.default\Searchqutoolbar Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433} Datei Gelöscht : C:\Users\Ayelen\AppData\Roaming\Mozilla\Firefox\Profiles\cedywuar.default\searchplugins\Fissa.xml Datei Gelöscht : C:\Users\Ayelen\AppData\Roaming\Mozilla\Firefox\Profiles\cedywuar.default\searchplugins\icqplugin.xml Datei Gelöscht : C:\Users\Ayelen\AppData\Roaming\Mozilla\Firefox\Profiles\cedywuar.default\searchplugins\icqplugin-1.xml Datei Gelöscht : C:\Users\Ayelen\AppData\Roaming\Mozilla\Firefox\Profiles\cedywuar.default\searchplugins\Search_Results.xml Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Search_Results.xml ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\DNSBHO.dll Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\BrowserConnection.Loader Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\BrowserConnection.Loader.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DnsBHO.BHO Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DnsBHO.BHO.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [DataMngr] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2319825 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_windows-live-messenger_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_windows-live-messenger_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_windows-live-messenger_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_windows-live-messenger_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{99079A25-328F-4BD4-BE04-00955ACAA0A7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9D717F81-9148-4F12-8568-69135F087DB0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{5B4144E1-B61D-495A-9A50-CD1A95D86D15} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{841D5A49-E48D-413C-9C28-EB3D9081D705} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079A25-328F-4BD4-BE04-00955ACAA0A7} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4F12-8568-69135F087DB0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079A25-328F-4BD4-BE04-00955ACAA0A7} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{99079A25-328F-4BD4-BE04-00955ACAA0A7}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{9D717F81-9148-4F12-8568-69135F087DB0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8E9CF769-3D3B-40EB-9E2D-76E7A205E4D2} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4F12-8568-69135F087DB0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} Schlüssel Gelöscht : HKCU\Software\DataMngr Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\Software\DeviceVM Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar Schlüssel Gelöscht : HKLM\Software\SearchquMediabarTb Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Searchqu Toolbar Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DataMngr Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DeviceVM Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\WIA6EB~1\Datamngr\datamngr.dll Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\WIA6EB~1\Datamngr\IEBHO.dll Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\WIA6EB~1\Datamngr\x64\datamngr.dll Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\WIA6EB~1\Datamngr\x64\IEBHO.dll ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v25.0.1 (de) [ Datei : C:\Users\Ayelen\AppData\Roaming\Mozilla\Firefox\Profiles\cedywuar.default\prefs.js ] Zeile gelöscht : user_pref("browser.search.defaulturl", "hxxp://www.fissa.com/es/results/?s=b&c=1005165359&suid=EhrnxMUDS&d=2&q="); Zeile gelöscht : user_pref("browser.search.order.1", "Search Results"); Zeile gelöscht : user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !important; background: url(\"I[...] Zeile gelöscht : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*"); Zeile gelöscht : user_pref("extensions.wrc.SearchRules.rambler.ru.style", ".WRCN {display:none} .search-results .title + .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}"); Zeile gelöscht : user_pref("icqtoolbar.allowSendURL", false); Zeile gelöscht : user_pref("icqtoolbar.engineVerified", false); Zeile gelöscht : user_pref("icqtoolbar.hiddenElements", "itb_options"); Zeile gelöscht : user_pref("icqtoolbar.history", "flv%20mp3%20converter%20gratis||flv%20converter%20gratis||flv%20converter||itunes%20kosten||kommentare%20f%C3%BCr%20home||kommentaremailer%20f%C3%BCr%20home||kommentar[...] Zeile gelöscht : user_pref("icqtoolbar.installTime", "1296996352"); Zeile gelöscht : user_pref("icqtoolbar.itbsitescount", 0); Zeile gelöscht : user_pref("icqtoolbar.newtab_state", "1"); Zeile gelöscht : user_pref("icqtoolbar.numberOfSearches", 1); Zeile gelöscht : user_pref("icqtoolbar.previousFFVersion", "3.6.13"); Zeile gelöscht : user_pref("icqtoolbar.removedsitescount", 2); Zeile gelöscht : user_pref("icqtoolbar.skip_default_search", "no"); Zeile gelöscht : user_pref("icqtoolbar.suggestions", false); Zeile gelöscht : user_pref("icqtoolbar.uninstStatSent", true); Zeile gelöscht : user_pref("icqtoolbar.uniqueID", "126685390412668539041266956992178"); Zeile gelöscht : user_pref("icqtoolbar.usageStatstTimestamp", 1296996354); Zeile gelöscht : user_pref("icqtoolbar.voucherHideClicks", 0); Zeile gelöscht : user_pref("icqtoolbar.voucherMoreLinkClicks", 0); Zeile gelöscht : user_pref("icqtoolbar.voucherRedeemClicks", 0); Zeile gelöscht : user_pref("icqtoolbar.voucherWasShown", 0); Zeile gelöscht : user_pref("icqtoolbar.xmlEnableSuggestions", false); Zeile gelöscht : user_pref("icqtoolbar.xmlLanguage", "de"); Zeile gelöscht : user_pref("keyword.URL", "hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=413&sr=0&q="); [ Datei : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4530x7tp.default\prefs.js ] Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://www.searchqu.com/413"); Zeile gelöscht : user_pref("keyword.URL", "hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=413&sr=0&q="); ************************* AdwCleaner[R0].txt - [11514 octets] - [08/12/2013 14:21:42] AdwCleaner[S0].txt - [11288 octets] - [08/12/2013 14:22:28] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11349 octets] ########## FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-12-2013 02 Ran by Admin (administrator) on AYELEN-VAIO on 08-12-2013 14:27:39 Running from C:\Users\Admin\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7938080 2009-07-24] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-07-24] (Realtek Semiconductor Corp.) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [208384 2009-08-03] (Alps Electric Co., Ltd.) HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe [186904 2009-06-04] (Intel Corporation) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Java\jre6\bin\jusched.exe [171520 2009-08-17] (Sun Microsystems, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM-x32\...\Run: [ISBMgr.exe] - C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [317288 2009-05-26] (Sony Corporation) HKLM-x32\...\Run: [MarketingTools] - C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [26624 2009-09-05] (Sony Corporation) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-09-08] (Apple Inc.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3460784 2011-04-18] (AVAST Software) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [38872 2012-07-31] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [919008 2012-07-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [49208 2011-05-10] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-05-30] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [421776 2012-06-07] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKU\Ayelen\...\Run: [msnmsgr] - "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background HKU\Ayelen\...\Run: [HP Deskjet 3070 B611 series (NET)] - C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\ScanToPCActivationApp.exe [2676584 2011-06-08] (Hewlett-Packard Co.) AppInit_DLLs: [ ] () AppInit_DLLs-x32: [ ] () Startup: C:\Users\Ayelen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File) Startup: C:\Users\Ayelen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\Ayelen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_01.09.2010_10-16.lnk ShortcutTarget: setup_9.0.0.722_01.09.2010_10-16.lnk -> C:\Users\Admin\Desktop\Virus Removal Tool\setup_9.0.0.722_01.09.2010_10-16\startup.exe (No File) Startup: C:\Users\Ayelen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3070 B611 series (Netzwerk).lnk ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 3070 B611 series (Netzwerk).lnk -> C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=SVEA&bmod=EU01 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SVEA&bmod=EU01 URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = SearchScopes: HKCU - {3E774340-48D5-4C1A-B79D-BD6D6E4C10D2} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-0/4?satitle={searchTerms} SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKCU - {A6A8E986-A77C-4D4C-A6D9-5A6420E7770C} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta SearchScopes: HKCU - {FBF7DC4A-FC99-482F-A6D3-B73399875CB0} URL = hxxp://services.zinio.com/search?s={selection}&rf=sonyslices BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: HKLM-x32 {888078C6-70B2-4F88-8EE7-1F50DDEA6120} https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4530x7tp.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4530x7tp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! WebRep - C:\Program Files\AVAST Software\Avast\WebRep\FF ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [42184 2011-04-18] (AVAST Software) S3 Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [313840 2009-06-26] (Sonic Solutions) S2 Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [362992 2009-06-26] (Sonic Solutions) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [189984 2009-07-24] (Realtek Semiconductor) S3 SOHDBSvr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-07-27] (Sony Corporation) S3 SOHPlMgr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-07-27] (Sony Corporation) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-07-23] (Sony Corporation) R2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [642920 2009-07-22] (Sony Corporation) R3 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-07-23] (Sony Corporation) R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1368624 2013-08-01] (Sony Corporation) R2 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [206336 2009-07-23] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R1 15749921; C:\Windows\System32\DRIVERS\15749921.sys [157712 2009-09-25] (Kaspersky Lab) R0 15749922; C:\Windows\System32\DRIVERS\15749922.sys [40464 2009-10-22] (Kaspersky Lab) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [22360 2011-04-18] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [64344 2011-04-18] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [31064 2011-04-18] (AVAST Software) R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [600920 2011-04-18] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [287064 2011-04-18] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [53592 2011-04-18] (AVAST Software) R2 risdptsk; C:\Windows\system32\DRIVERS\risdsn64.sys [76288 2009-07-31] (REDC) R1 setup_9.0.0.722_01.09.2010_10-16drv; C:\Windows\System32\DRIVERS\1574992.sys [352784 2009-10-09] (Kaspersky Lab) S3 USBET; C:\Windows\System32\DRIVERS\ETdrv.sys [6409344 2010-11-10] (Etron) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-08 14:21 - 2013-12-08 14:22 - 00000000 ____D C:\AdwCleaner 2013-12-08 14:20 - 2013-12-08 14:20 - 01110034 _____ C:\Users\Admin\Downloads\adwcleaner.exe 2013-12-08 13:30 - 2013-12-08 13:30 - 00022693 _____ C:\Users\Admin\Downloads\Addition.txt 2013-12-08 13:28 - 2013-12-08 14:27 - 00017103 _____ C:\Users\Admin\Downloads\FRST.txt 2013-12-08 13:28 - 2013-12-08 13:28 - 00000000 ____D C:\FRST 2013-12-08 13:27 - 2013-12-08 13:27 - 01927772 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe 2013-12-06 22:54 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-12-06 22:49 - 2013-12-06 22:49 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-06 22:49 - 2013-12-06 22:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-06 22:49 - 2013-12-06 22:49 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-06 22:49 - 2013-12-06 22:49 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-06 22:49 - 2013-12-06 22:49 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-06 22:49 - 2013-12-06 22:49 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-06 22:49 - 2013-12-06 22:49 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-06 22:49 - 2013-12-06 22:49 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-06 22:49 - 2013-12-06 22:49 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-06 22:49 - 2013-12-06 22:49 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-06 22:49 - 2013-12-06 22:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-06 22:48 - 2013-12-06 22:54 - 00010277 _____ C:\Windows\IE11_main.log 2013-11-23 19:18 - 2013-11-23 19:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-15 02:18 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-15 02:18 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-15 02:17 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-15 02:17 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-15 02:17 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-15 02:17 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-15 02:17 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-15 02:17 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-15 02:17 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-15 02:17 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-15 02:17 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-15 02:17 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-15 02:17 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-15 02:17 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-15 02:17 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-15 02:17 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-15 02:17 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-15 02:17 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-15 02:17 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-15 02:17 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-15 02:17 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-15 02:17 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-15 02:17 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-15 02:17 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-15 02:17 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-15 02:17 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-15 02:17 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-15 02:17 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-15 02:17 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-15 02:17 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys ==================== One Month Modified Files and Folders ======= 2013-12-08 14:28 - 2013-12-08 13:28 - 00017103 _____ C:\Users\Admin\Downloads\FRST.txt 2013-12-08 14:26 - 2013-04-12 22:46 - 00003942 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{08D4C479-6A0F-404A-9EB8-BDDBFE7B3B66} 2013-12-08 14:24 - 2009-09-05 13:09 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-08 14:24 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-08 14:24 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-08 14:23 - 2009-07-14 05:51 - 00180861 _____ C:\Windows\setupact.log 2013-12-08 14:22 - 2013-12-08 14:21 - 00000000 ____D C:\AdwCleaner 2013-12-08 14:22 - 2010-01-05 13:58 - 01382072 _____ C:\Windows\WindowsUpdate.log 2013-12-08 14:20 - 2013-12-08 14:20 - 01110034 _____ C:\Users\Admin\Downloads\adwcleaner.exe 2013-12-08 14:00 - 2009-09-05 13:09 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-08 13:48 - 2012-06-10 11:52 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-08 13:30 - 2013-12-08 13:30 - 00022693 _____ C:\Users\Admin\Downloads\Addition.txt 2013-12-08 13:28 - 2013-12-08 13:28 - 00000000 ____D C:\FRST 2013-12-08 13:27 - 2013-12-08 13:27 - 01927772 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe 2013-12-08 12:21 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-08 12:21 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-08 12:17 - 2013-04-12 22:45 - 00001421 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-08 12:14 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-06 22:54 - 2013-12-06 22:48 - 00010277 _____ C:\Windows\IE11_main.log 2013-12-06 22:49 - 2013-12-06 22:49 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-06 22:49 - 2013-12-06 22:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-06 22:49 - 2013-12-06 22:49 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-06 22:49 - 2013-12-06 22:49 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-06 22:49 - 2013-12-06 22:49 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-06 22:49 - 2013-12-06 22:49 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-06 22:49 - 2013-12-06 22:49 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-06 22:49 - 2013-12-06 22:49 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-06 22:49 - 2013-12-06 22:49 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-06 22:49 - 2013-12-06 22:49 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-06 22:49 - 2013-12-06 22:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-06 13:54 - 2012-04-23 14:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-06 13:54 - 2009-09-05 13:42 - 00594432 _____ C:\Windows\PFRO.log 2013-11-27 20:23 - 2013-11-07 10:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox.bak 2013-11-27 20:17 - 2013-04-12 22:42 - 00000000 ____D C:\Users\Admin 2013-11-23 19:49 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-23 19:18 - 2013-11-23 19:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-23 19:06 - 2009-07-14 18:58 - 00654400 _____ C:\Windows\system32\perfh007.dat 2013-11-23 19:06 - 2009-07-14 18:58 - 00130240 _____ C:\Windows\system32\perfc007.dat 2013-11-23 19:06 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-15 02:50 - 2009-09-05 13:23 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-15 02:47 - 2013-08-31 09:05 - 00000000 ____D C:\Windows\system32\MRT 2013-11-15 02:45 - 2010-02-23 13:31 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\AskSLib.dll C:\Users\Admin\AppData\Local\Temp\fszgpjb-.dll C:\Users\Admin\AppData\Local\Temp\Quarantine.exe C:\Users\Admin\AppData\Local\Temp\SkypeSetup.exe C:\Users\Ayelen\AppData\Local\Temp\ose00000.exe C:\Users\Ayelen\AppData\Local\Temp\SkypeSetup.exe C:\Users\Ayelen\AppData\Local\Temp\_is1FFE.exe C:\Users\Ayelen\AppData\Local\Temp\_is9E32.exe C:\Users\Ayelen\AppData\Local\Temp\_isAE58.exe C:\Users\Ayelen\AppData\Local\Temp\_isEC52.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-06 14:35 ==================== End Of Log ============================ |
08.12.2013, 18:12 | #4 | |
/// Malwareteam | Ungwollte Startseite/Suchmaschine: " http://www.searchnu.com/413" - wie entferne ich das?Zitat:
so geht es weiter: Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
Schritt 2: Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 3: ESET Online Scanner
Schritt 4: Downloade Dir bitte SecurityCheck und:
Schritt 5: erstelle ein neues FRST Logfile und poste es hier |
10.12.2013, 11:28 | #5 |
| Ungwollte Startseite/Suchmaschine: " http://www.searchnu.com/413" - wie entferne ich das? Hallo Heiko, ich habe jetzt mal den Schritt mit dem TFC gemacht und irgendwie geht jetzt überhaupt nichts mehr. Laptop reagiert nicht mehr, hab auf Neustarten geklickt und jetzt ist der Bildschirm schwarz und es tut sich nichts? |
10.12.2013, 11:33 | #6 |
/// Malwareteam | Ungwollte Startseite/Suchmaschine: " http://www.searchnu.com/413" - wie entferne ich das? Was bedeutet bleibt schwarz? Wie weit bootet das System bei dir? TFC löscht nur Temp Files in bestimmten Ordner...
__________________ --> Ungwollte Startseite/Suchmaschine: " http://www.searchnu.com/413" - wie entferne ich das? |
10.12.2013, 11:43 | #7 |
| Ungwollte Startseite/Suchmaschine: " http://www.searchnu.com/413" - wie entferne ich das? Ich habe absolut keine Ahnung Bin ein totaler newbie was das alles betrifft. Scheint nach Neustart jetzt aber alles wieder zu laufen Ich lasse jetzt mbam arbeiten und melde mich dann mit den restlichen Schritten |
10.12.2013, 11:46 | #8 |
/// Malwareteam | Ungwollte Startseite/Suchmaschine: " http://www.searchnu.com/413" - wie entferne ich das? uff dafür bin ich jetzt "endgültig" wach |
10.12.2013, 23:20 | #9 |
| Ungwollte Startseite/Suchmaschine: " http://www.searchnu.com/413" - wie entferne ich das? Ich wollte dich nicht erschrecken, sorry So hier mal die ganzen logs, mbam hat zwei Sachen gefunden. mbam: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.12.10.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16428 Admin :: AYELEN-VAIO [Administrator] 10.12.2013 11:41:59 mbam-log-2013-12-10 (11-41-59).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 420802 Laufzeit: 1 Stunde(n), 15 Minute(n), 12 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\Users\Ayelen\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Ayelen\AppData\Roaming\Mozilla\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433} (PUP.Optional.Searchqu.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Checkup: Code:
ATTFilter Results of screen317's Security Check version 0.99.77 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Spybot - Search & Destroy Malwarebytes Anti-Malware Version 1.75.0.1300 Java(TM) 6 Update 33 Java 7 Update 25 Java version out of Date! Adobe Flash Player 11.9.900.117 Adobe Reader 9 Adobe Reader out of Date! Mozilla Firefox (25.0.1) ````````Process Check: objlist.exe by Laurent```````` ESET ESET Online Scanner OnlineScannerApp.exe AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-12-2013 Ran by Admin (administrator) on AYELEN-VAIO on 10-12-2013 23:08:50 Running from C:\Users\Admin\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7938080 2009-07-24] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-07-24] (Realtek Semiconductor Corp.) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [208384 2009-08-03] (Alps Electric Co., Ltd.) HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe [186904 2009-06-04] (Intel Corporation) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Java\jre6\bin\jusched.exe [171520 2009-08-17] (Sun Microsystems, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM-x32\...\Run: [ISBMgr.exe] - C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [317288 2009-05-26] (Sony Corporation) HKLM-x32\...\Run: [MarketingTools] - C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [26624 2009-09-05] (Sony Corporation) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-09-08] (Apple Inc.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3460784 2011-04-18] (AVAST Software) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [38872 2012-07-31] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [919008 2012-07-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [49208 2011-05-10] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-05-30] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [421776 2012-06-07] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKU\Ayelen\...\Run: [msnmsgr] - "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background HKU\Ayelen\...\Run: [HP Deskjet 3070 B611 series (NET)] - C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\ScanToPCActivationApp.exe [2676584 2011-06-08] (Hewlett-Packard Co.) AppInit_DLLs: [ ] () Startup: C:\Users\Ayelen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File) Startup: C:\Users\Ayelen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\Ayelen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_01.09.2010_10-16.lnk ShortcutTarget: setup_9.0.0.722_01.09.2010_10-16.lnk -> C:\Users\Admin\Desktop\Virus Removal Tool\setup_9.0.0.722_01.09.2010_10-16\startup.exe (No File) Startup: C:\Users\Ayelen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3070 B611 series (Netzwerk).lnk ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 3070 B611 series (Netzwerk).lnk -> C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=SVEA&bmod=EU01 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SVEA&bmod=EU01 URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = SearchScopes: HKCU - {3E774340-48D5-4C1A-B79D-BD6D6E4C10D2} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-0/4?satitle={searchTerms} SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKCU - {A6A8E986-A77C-4D4C-A6D9-5A6420E7770C} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta SearchScopes: HKCU - {FBF7DC4A-FC99-482F-A6D3-B73399875CB0} URL = hxxp://services.zinio.com/search?s={selection}&rf=sonyslices BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: HKLM-x32 {888078C6-70B2-4F88-8EE7-1F50DDEA6120} https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4530x7tp.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4530x7tp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! WebRep - C:\Program Files\AVAST Software\Avast\WebRep\FF ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [42184 2011-04-18] (AVAST Software) S3 Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [313840 2009-06-26] (Sonic Solutions) S2 Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [362992 2009-06-26] (Sonic Solutions) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [189984 2009-07-24] (Realtek Semiconductor) S3 SOHDBSvr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-07-27] (Sony Corporation) S3 SOHPlMgr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-07-27] (Sony Corporation) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-07-23] (Sony Corporation) R2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [642920 2009-07-22] (Sony Corporation) R3 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-07-23] (Sony Corporation) R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1368624 2013-08-01] (Sony Corporation) R2 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [206336 2009-07-23] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R1 15749921; C:\Windows\System32\DRIVERS\15749921.sys [157712 2009-09-25] (Kaspersky Lab) R0 15749922; C:\Windows\System32\DRIVERS\15749922.sys [40464 2009-10-22] (Kaspersky Lab) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [22360 2011-04-18] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [64344 2011-04-18] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [31064 2011-04-18] (AVAST Software) R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [600920 2011-04-18] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [287064 2011-04-18] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [53592 2011-04-18] (AVAST Software) R2 risdptsk; C:\Windows\system32\DRIVERS\risdsn64.sys [76288 2009-07-31] (REDC) S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R1 setup_9.0.0.722_01.09.2010_10-16drv; C:\Windows\System32\DRIVERS\1574992.sys [352784 2009-10-09] (Kaspersky Lab) S3 USBET; C:\Windows\System32\DRIVERS\ETdrv.sys [6409344 2010-11-10] (Etron) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-10 23:08 - 2013-12-10 23:08 - 00000000 ____D C:\Users\Admin\Downloads\FRST-OlderVersion 2013-12-10 23:04 - 2013-12-10 23:04 - 00891200 _____ C:\Users\Admin\Downloads\SecurityCheck.exe 2013-12-10 13:06 - 2013-12-10 13:06 - 00000000 ____D C:\Program Files (x86)\ESET 2013-12-10 13:00 - 2013-12-10 13:00 - 02347384 _____ (ESET) C:\Users\Admin\Downloads\esetsmartinstaller_enu.exe 2013-12-10 11:41 - 2013-12-10 11:41 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-12-10 11:41 - 2013-12-10 11:41 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Malwarebytes 2013-12-10 11:40 - 2013-12-10 11:40 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Admin\Downloads\mbam-setup-1.75.0.1300.exe 2013-12-10 11:06 - 2013-12-10 11:06 - 00448512 _____ (OldTimer Tools) C:\Users\Admin\Downloads\TFC.exe 2013-12-08 14:21 - 2013-12-08 14:22 - 00000000 ____D C:\AdwCleaner 2013-12-08 14:20 - 2013-12-08 14:20 - 01110034 _____ C:\Users\Admin\Downloads\adwcleaner.exe 2013-12-08 13:30 - 2013-12-08 13:30 - 00022693 _____ C:\Users\Admin\Downloads\Addition.txt 2013-12-08 13:28 - 2013-12-10 23:08 - 00017114 _____ C:\Users\Admin\Downloads\FRST.txt 2013-12-08 13:28 - 2013-12-10 23:08 - 00000000 ____D C:\FRST 2013-12-08 13:27 - 2013-12-10 23:08 - 01928110 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe 2013-12-06 22:54 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-12-06 22:49 - 2013-12-06 22:49 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-06 22:49 - 2013-12-06 22:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-06 22:49 - 2013-12-06 22:49 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-06 22:49 - 2013-12-06 22:49 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-06 22:49 - 2013-12-06 22:49 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-06 22:49 - 2013-12-06 22:49 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-06 22:49 - 2013-12-06 22:49 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-06 22:49 - 2013-12-06 22:49 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-06 22:49 - 2013-12-06 22:49 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-06 22:49 - 2013-12-06 22:49 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-06 22:49 - 2013-12-06 22:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-06 22:48 - 2013-12-06 22:54 - 00010277 _____ C:\Windows\IE11_main.log 2013-11-23 19:18 - 2013-11-23 19:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-15 02:18 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-15 02:18 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-15 02:17 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-15 02:17 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-15 02:17 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-15 02:17 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-15 02:17 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-15 02:17 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-15 02:17 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-15 02:17 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-15 02:17 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-15 02:17 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-15 02:17 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-15 02:17 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-15 02:17 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-15 02:17 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-15 02:17 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-15 02:17 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-15 02:17 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-15 02:17 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-15 02:17 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-15 02:17 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-15 02:17 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-15 02:17 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-15 02:17 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-15 02:17 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-15 02:17 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-15 02:17 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-15 02:17 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-15 02:17 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys ==================== One Month Modified Files and Folders ======= 2013-12-10 23:09 - 2013-12-08 13:28 - 00017114 _____ C:\Users\Admin\Downloads\FRST.txt 2013-12-10 23:08 - 2013-12-10 23:08 - 00000000 ____D C:\Users\Admin\Downloads\FRST-OlderVersion 2013-12-10 23:08 - 2013-12-08 13:28 - 00000000 ____D C:\FRST 2013-12-10 23:08 - 2013-12-08 13:27 - 01928110 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe 2013-12-10 23:08 - 2009-09-05 13:09 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-10 23:08 - 2009-09-05 13:09 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-10 23:04 - 2013-12-10 23:04 - 00891200 _____ C:\Users\Admin\Downloads\SecurityCheck.exe 2013-12-10 23:03 - 2009-09-05 13:09 - 00004120 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-10 23:03 - 2009-09-05 13:09 - 00003868 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-12-10 23:01 - 2012-06-10 11:52 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-10 23:01 - 2010-01-05 13:58 - 01530806 _____ C:\Windows\WindowsUpdate.log 2013-12-10 16:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-10 13:10 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-10 13:10 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-10 13:06 - 2013-12-10 13:06 - 00000000 ____D C:\Program Files (x86)\ESET 2013-12-10 13:03 - 2013-04-12 22:46 - 00003942 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{08D4C479-6A0F-404A-9EB8-BDDBFE7B3B66} 2013-12-10 13:02 - 2009-09-05 13:42 - 00595126 _____ C:\Windows\PFRO.log 2013-12-10 13:02 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-10 13:02 - 2009-07-14 05:51 - 00180973 _____ C:\Windows\setupact.log 2013-12-10 13:00 - 2013-12-10 13:00 - 02347384 _____ (ESET) C:\Users\Admin\Downloads\esetsmartinstaller_enu.exe 2013-12-10 11:41 - 2013-12-10 11:41 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-12-10 11:41 - 2013-12-10 11:41 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Malwarebytes 2013-12-10 11:41 - 2010-10-03 11:50 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-12-10 11:40 - 2013-12-10 11:40 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Admin\Downloads\mbam-setup-1.75.0.1300.exe 2013-12-10 11:06 - 2013-12-10 11:06 - 00448512 _____ (OldTimer Tools) C:\Users\Admin\Downloads\TFC.exe 2013-12-08 14:24 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-08 14:22 - 2013-12-08 14:21 - 00000000 ____D C:\AdwCleaner 2013-12-08 14:22 - 2010-01-05 16:30 - 00000000 ____D C:\ProgramData\ICQ 2013-12-08 14:20 - 2013-12-08 14:20 - 01110034 _____ C:\Users\Admin\Downloads\adwcleaner.exe 2013-12-08 13:30 - 2013-12-08 13:30 - 00022693 _____ C:\Users\Admin\Downloads\Addition.txt 2013-12-08 12:17 - 2013-04-12 22:45 - 00001421 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-08 12:14 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-06 22:54 - 2013-12-06 22:48 - 00010277 _____ C:\Windows\IE11_main.log 2013-12-06 22:49 - 2013-12-06 22:49 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-06 22:49 - 2013-12-06 22:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-06 22:49 - 2013-12-06 22:49 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-06 22:49 - 2013-12-06 22:49 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-06 22:49 - 2013-12-06 22:49 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-06 22:49 - 2013-12-06 22:49 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-06 22:49 - 2013-12-06 22:49 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-06 22:49 - 2013-12-06 22:49 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-06 22:49 - 2013-12-06 22:49 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-06 22:49 - 2013-12-06 22:49 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-06 22:49 - 2013-12-06 22:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-06 22:49 - 2013-12-06 22:49 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-06 22:49 - 2013-12-06 22:49 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-06 13:54 - 2012-04-23 14:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-27 20:23 - 2013-11-07 10:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox.bak 2013-11-27 20:17 - 2013-04-12 22:42 - 00000000 ____D C:\Users\Admin 2013-11-23 19:18 - 2013-11-23 19:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-23 19:06 - 2009-07-14 18:58 - 00654400 _____ C:\Windows\system32\perfh007.dat 2013-11-23 19:06 - 2009-07-14 18:58 - 00130240 _____ C:\Windows\system32\perfc007.dat 2013-11-23 19:06 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-15 02:50 - 2009-09-05 13:23 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-15 02:47 - 2013-08-31 09:05 - 00000000 ____D C:\Windows\system32\MRT 2013-11-15 02:45 - 2010-02-23 13:31 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-10 16:10 ==================== End Of Log ============================ |
11.12.2013, 07:55 | #10 |
/// Malwareteam | Ungwollte Startseite/Suchmaschine: " http://www.searchnu.com/413" - wie entferne ich das? nein du musst ESET nicht nochmal laufen lassen, wenn du sagst er hat nix gefunden glaub ich dir das Update bitte deine Java Version und deinen Adobe Reader noch. wunderbar dann räumen wir noch auf ... und du bekommst einige Tips von mir (optional) Schritt 1: Die Reihenfolge ist hier entscheidend.
Schritt 2: Wunderbar dein System ist soweit ich das sehen kann sauber. Hier noch ein paar Tipps zur Absicherung deines Systems. Benutzerkonto Einstellungen: Wir sehen immer wieder User mit Administratorrechten. Hier kann jeder Nutzer eines Windowsrechners schon die erste Türe schließen. Arbeite mit einem eingeschränkten Benutzerkonto anstelle eines Kontos mit Administratorrechten. Diese sind für das tägliche Arbeiten nicht nötig, und solltest du einmal Software installieren wollen wirst du im normalfall nach deinem Passwort gefragt. Solltest du Hilfe bei der Erstellung eines "eingeschränkten Kontos" benötigen helfe ich dir gern weiter. Systemupdates: Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Besonders Java erfährt zur Zeit regelmäßig sicherheitsrelevante Updates Ältere Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Antivirensoftware Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen alternatives Browsen Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen. Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. Wenn du möchtest, kannst du das Trojaner Board Forum mit einer kleinen Spende unterstützen. |
12.12.2013, 23:05 | #11 |
| Ungwollte Startseite/Suchmaschine: " http://www.searchnu.com/413" - wie entferne ich das? Also bezüglich der Seite hat sich alles erledigt - Danke für deine Hilfe!!! Zu deinem letzten Post habe ich ein paar Fragen : 1) das was im Schritt 1 steht ist für mich nicht relevant, oder? Diese Programme haben wir ja nicht benutzt oder verstehe ich da irgendwas falsch? 2) Mit der Benützung eines eingeschränkten Kontos meinst du einfach den Standardbenutzer, oder? Oder muss ich da manuell irgendwelche Einstellungen einrichten? 3) Welche kostenlose Antiviren Software würdest du empfehlen? Habe Avira drauf, aber das Gefühl, dass mir das bisher noch absolut nichts gebracht hat |
13.12.2013, 10:12 | #12 | ||||
/// Malwareteam | Ungwollte Startseite/Suchmaschine: " http://www.searchnu.com/413" - wie entferne ich das?Zitat:
Zitat:
Zitat:
Zitat:
|
Themen zu Ungwollte Startseite/Suchmaschine: " http://www.searchnu.com/413" - wie entferne ich das? |
adblock, antivirus, bandoo, bonjour, computer, converter, desktop, downloader, excel, firefox, flash player, home, homepage, kaspersky, malware / spyware, mp3, msiinstaller, plug-in, problem, realtek, registry, scan, secur, security, software, startseite, suchmaschine, svchost.exe, system, system error, trojaner, viren befall, virus, virus auf dem pc |