|
Plagegeister aller Art und deren Bekämpfung: optimizer proWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
26.12.2013, 18:05 | #1 |
| optimizer pro Hallo Beim Download von Freemake Video Converter wurde auf meinem PC auch Optimizer Pro installiert. In der Systemsteuerung habe ich es bereits gelöscht, jedoch weiss ich nicht, ob dies reicht. Daher habe ich nun das Farbar Recovery Scan Tool heruntergeladen und ausgeführt. Die Logfiles kopiere ich in diese Nachricht. Kann mir bitte jemand helfen? Jetzt schon vielen Dank!! Liebe Grüsse Sarah FRST Logfile: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-12-2013 Ran by Sarah (administrator) on SARAH-PC on 26-12-2013 17:55:59 Running from C:\Users\Sarah\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Realtek Semiconductor) C:\Windows\RTKAUDIOSERVICE.EXE (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Teruten) C:\Windows\System32\FsUsbExService.Exe (InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Sony Corporation) C:\Program Files\sony\Network Utility\NSUService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (ArcSoft, Inc.) C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files\sony\VAIO Power Management\SPMService.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Sony Corporation) C:\Program Files\sony\VAIO Power Management\SPMgr.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Sony Corporation) C:\Program Files\sony\VAIO Update 4\VAIOUpdt.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Sony Corporation) C:\Program Files\sony\ISB Utility\ISBMgr.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Brother Industries, Ltd.) C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe (Sony Corporation) C:\Program Files\sony\Network Utility\LANUtil.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Samsung) C:\Program Files\Samsung\Kies\Kies.exe (Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Brother Industries, Ltd.) C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\System32\sdclt.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Freemake) C:\Program Files\Freemake\Freemake Video Converter\FreemakeVC.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6295552 2008-10-17] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [835584 2007-03-10] (Synaptics, Inc.) HKLM\...\Run: [ISBMgr.exe] - C:\Program Files\sony\ISB Utility\ISBMgr.exe [317280 2008-04-03] (Sony Corporation) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.) HKLM\...\Run: [OrderReminder] - C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [98304 2006-01-30] (Hewlett-Packard) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [FreePDFAssistent] - C:\Program Files\FreePDF\FreePDFA.exe [150528 2003-12-24] (shbox) HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.) HKLM\...\Run: [BrMfcWnd] - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [745472 2009-02-10] (Brother Industries, Ltd.) HKLM\...\Run: [ControlCenter3] - C:\Program Files\Brother\ControlCenter3\BrCtrCen.exe [77824 2007-10-30] (Brother Industries, Ltd.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-21] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [310280 2012-12-20] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [FreePDF Assistant] - C:\Program Files\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) Winlogon\Notify\VESWinlogon: C:\Windows\system32\VESWinlogon.dll (Sony Corporation) HKCU\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [270336 2008-11-05] (Sony Corporation) HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2008-12-04] (Google Inc.) HKCU\...\Run: [Sony Ericsson PC Companion] - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [433872 2011-10-21] (Sony Ericsson) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1476104 2012-12-20] (Samsung) HKCU\...\Run: [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup HKCU\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844296 2012-12-20] (Samsung) HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil32_11_9_900_117_Plugin.exe -update plugin [829832 2013-11-04] (Adobe Systems Incorporated) HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [ 2008-12-04] (Google Inc.) HKU\Default\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [ 2008-11-05] (Sony Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [ 2008-12-04] (Google Inc.) HKU\Default User\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [ 2008-11-05] (Sony Corporation) AppInit_DLLs: [ ] () Startup: C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.avira.com/?l=dis&o=APN10396&gct=hp&dc=EU&locale=de_CH HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.sonystyle-europe.com?csint=140016340 hxxp://www.club-vaio.com/vbc/ebay/index.html hxxp://www.club-vaio.com/vbc HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.studivz.net/ hxxp://www.southernfm.co.uk/ hxxp://www.cambridgeesol-luzern.ch/index2.htm hxxp://www.cambridgeesol.org/exams/exams-info/results-information/lost-certificates.html https://mail.stud.unilu.ch/webmail/ hxxp://www.nzz.ch/ hxxp://news.bbc.co.uk/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer) BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} hxxp://www.extrafilm.ch/ImageUploader5.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUpldde-ch.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\zs3abbli.default FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF SelectedSearchEngine: Google FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=6.0.12.69 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprjplug;version=1.0.3.69 - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.69 - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @movenetworks.com/Quantum Media Player - C:\Users\Sarah\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\googledesktop.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Microsoft .NET Framework Assistant - C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\zs3abbli.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Program Files\Real\RealPlayer\browserrecord FF Extension: RealPlayer Browser Record Plugin - C:\Program Files\Real\RealPlayer\browserrecord FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF HKLM\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF Extension: Freemake Video Converter Plugin - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ Chrome: ======= CHR HomePage: CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (DivX Player Netscape Plugin) - C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc) CHR Plugin: (QuickTime Plug-in 7.6.5) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.5) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.5) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.5) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.5) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.5) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll No File CHR Plugin: (QuickTime Plug-in 7.6.5) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll No File CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Move Media Player 7) - C:\Users\Sarah\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.70.10) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (Google Drive) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Google Wallet) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.126_0 CHR Extension: (Gmail) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx ========================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-21] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG) S4 EFUploadSrv; C:\Program Files\ExtraFilm Designer CH DE\EFUploadSrv.exe [1716224 2009-07-09] (Textalk AB) S3 GoogleDesktopManager-110309-193829; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-02-11] (Google) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 NSUService; C:\Program Files\sony\Network Utility\NSUService.exe [303104 2008-11-05] (Sony Corporation) S3 ServiceLayer; C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe [651776 2009-09-17] (Nokia) S3 SOHCImp; C:\Program Files\Sony\VAIO Media plus\SOHCImp.exe [103712 2008-10-21] (Sony Corporation) S3 SOHDms; C:\Program Files\Sony\VAIO Media plus\SOHDms.exe [353568 2008-10-21] (Sony Corporation) S3 SOHDs; C:\Program Files\Sony\VAIO Media plus\SOHDs.exe [62752 2008-10-21] (Sony Corporation) S3 Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [155344 2011-06-29] (Avanquest Software) S3 SPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe [77824 2008-05-20] (Sony Corporation) R2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S4 VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [73728 2008-09-08] (Sony Corporation) S4 VAIO Event Service; C:\Program Files\sony\VAIO Event Service\VESMgr.exe [203624 2008-11-05] (Sony Corporation) R2 VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [411488 2008-09-05] (Sony Corporation) S4 VcmIAlzMgr; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [337184 2008-06-11] (Sony Corporation) S4 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [279848 2008-09-08] (Sony Corporation) S4 VzCdbSvc; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2008-09-08] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== S3 61883; C:\Windows\System32\DRIVERS\61883.sys [45696 2008-01-21] (Microsoft Corporation) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17920 2008-04-24] (ArcSoft, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-21] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-21] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-25] (Avira Operations GmbH & Co. KG) R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [36608 2009-03-31] () R0 Lbd; C:\Windows\System32\DRIVERS\Lbd.sys [64288 2010-12-03] (Lavasoft AB) S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [86824 2008-10-21] (MCCI Corporation) S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [15016 2008-10-21] (MCCI Corporation) S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [114600 2008-10-21] (MCCI Corporation) S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [108328 2008-10-21] (MCCI Corporation) S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [26024 2008-10-21] (MCCI Corporation) S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [104616 2008-10-21] (MCCI Corporation) S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [109736 2008-10-21] (MCCI Corporation) S3 s117bus; C:\Windows\System32\DRIVERS\s117bus.sys [82984 2007-06-25] (MCCI Corporation) S3 s117mdfl; C:\Windows\System32\DRIVERS\s117mdfl.sys [14888 2007-06-25] (MCCI Corporation) S3 s117mdm; C:\Windows\System32\DRIVERS\s117mdm.sys [108456 2007-06-25] (MCCI Corporation) S3 s117mgmt; C:\Windows\System32\DRIVERS\s117mgmt.sys [100264 2007-06-25] (MCCI Corporation) S3 s117nd5; C:\Windows\System32\DRIVERS\s117nd5.sys [22952 2007-06-25] (MCCI Corporation) S3 s117obex; C:\Windows\System32\DRIVERS\s117obex.sys [98344 2007-06-25] (MCCI Corporation) S3 s117unic; C:\Windows\System32\DRIVERS\s117unic.sys [98856 2007-06-25] (MCCI Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) S3 ss_bbus; C:\Windows\System32\DRIVERS\ss_bbus.sys [90112 2009-03-20] (MCCI) S3 ss_bmdfl; C:\Windows\System32\DRIVERS\ss_bmdfl.sys [14976 2009-03-20] (MCCI Corporation) S3 ss_bmdm; C:\Windows\System32\DRIVERS\ss_bmdm.sys [121856 2009-03-20] (MCCI Corporation) S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-26 17:55 - 2013-12-26 17:56 - 00026400 _____ C:\Users\Sarah\Downloads\FRST.txt 2013-12-26 17:55 - 2013-12-26 17:55 - 01061649 _____ (Farbar) C:\Users\Sarah\Downloads\FRST.exe 2013-12-26 17:55 - 2013-12-26 17:55 - 00000000 ____D C:\FRST 2013-12-26 16:50 - 2013-12-26 16:52 - 00000000 ____D C:\Users\Sarah\Documents\Freemake 2013-12-26 16:50 - 2013-12-26 16:51 - 00000000 ____D C:\ProgramData\Freemake 2013-12-26 16:50 - 2013-12-26 16:50 - 00001113 _____ C:\Users\Public\Desktop\Freemake Video Converter.lnk 2013-12-26 16:50 - 2013-12-26 16:50 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake 2013-12-26 16:49 - 2013-12-26 16:50 - 00000000 ____D C:\Program Files\Freemake 2013-12-26 16:49 - 2013-12-26 16:49 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\OpenCandy 2013-12-26 16:48 - 2013-12-26 16:48 - 01271928 _____ (Ellora Assets Corporation ) C:\Users\Sarah\Downloads\FreemakeVideo4121ConverterSetup.exe 2013-12-26 16:39 - 2013-12-26 16:39 - 00001664 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-12-26 16:37 - 2013-12-26 16:39 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-12-26 16:37 - 2013-12-26 16:39 - 00000000 ____D C:\Program Files\iTunes 2013-12-26 16:37 - 2013-12-26 16:37 - 00000000 ____D C:\Program Files\iPod 2013-12-26 16:33 - 2013-12-26 16:33 - 00000000 ____D C:\Windows\LastGood 2013-12-26 16:29 - 2013-12-26 16:29 - 00000000 ____D C:\Program Files\QuickTime 2013-12-22 12:03 - 2013-12-22 12:03 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-12 18:53 - 2013-10-30 03:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2013-12-12 18:53 - 2013-10-30 02:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-12 18:53 - 2013-10-30 01:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-12 18:53 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-12 18:52 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-12 18:52 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-12 18:52 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2013-12-12 18:52 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-12 18:52 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-12 18:51 - 2013-10-25 09:25 - 00916992 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-12 18:51 - 2013-10-25 09:24 - 01213440 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 18:51 - 2013-10-25 09:24 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-12 18:51 - 2013-10-25 09:22 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-12 18:51 - 2013-10-25 09:20 - 00611840 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2013-12-12 18:51 - 2013-10-25 09:19 - 06018560 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-12 18:51 - 2013-10-25 09:19 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-12 18:51 - 2013-10-25 09:19 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-12 18:51 - 2013-10-25 09:19 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 11111936 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 02005504 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 01469440 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-12 18:51 - 2013-10-25 09:18 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-12 18:51 - 2013-10-25 09:16 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll 2013-12-12 18:51 - 2013-10-25 07:39 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-12 18:51 - 2013-10-25 05:55 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-12 18:51 - 2013-10-25 05:55 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-12 18:51 - 2013-10-25 05:53 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-12 18:51 - 2013-10-25 05:53 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-12 18:51 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-07 21:52 - 2013-12-17 22:35 - 00000000 ____D C:\Users\Sarah\Documents\§TRIP 2014 2013-12-07 21:52 - 2013-12-07 21:52 - 00000000 ____D C:\Users\Sarah\Documents\Neuer Ordner 2013-12-02 20:19 - 2013-12-02 20:19 - 01545496 _____ (Graboid Inc) C:\Users\Sarah\Downloads\GraboidVideoInstaller-4.631.exe ==================== One Month Modified Files and Folders ======= 2013-12-26 17:56 - 2013-12-26 17:55 - 00026400 _____ C:\Users\Sarah\Downloads\FRST.txt 2013-12-26 17:55 - 2013-12-26 17:55 - 01061649 _____ (Farbar) C:\Users\Sarah\Downloads\FRST.exe 2013-12-26 17:55 - 2013-12-26 17:55 - 00000000 ____D C:\FRST 2013-12-26 17:06 - 2012-12-30 13:17 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-26 17:06 - 2010-02-07 23:06 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-26 17:05 - 2009-01-24 09:50 - 01735869 _____ C:\Windows\WindowsUpdate.log 2013-12-26 16:52 - 2013-12-26 16:50 - 00000000 ____D C:\Users\Sarah\Documents\Freemake 2013-12-26 16:51 - 2013-12-26 16:50 - 00000000 ____D C:\ProgramData\Freemake 2013-12-26 16:50 - 2013-12-26 16:50 - 00001113 _____ C:\Users\Public\Desktop\Freemake Video Converter.lnk 2013-12-26 16:50 - 2013-12-26 16:50 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake 2013-12-26 16:50 - 2013-12-26 16:49 - 00000000 ____D C:\Program Files\Freemake 2013-12-26 16:49 - 2013-12-26 16:49 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\OpenCandy 2013-12-26 16:48 - 2013-12-26 16:48 - 01271928 _____ (Ellora Assets Corporation ) C:\Users\Sarah\Downloads\FreemakeVideo4121ConverterSetup.exe 2013-12-26 16:39 - 2013-12-26 16:39 - 00001664 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-12-26 16:39 - 2013-12-26 16:37 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-12-26 16:39 - 2013-12-26 16:37 - 00000000 ____D C:\Program Files\iTunes 2013-12-26 16:37 - 2013-12-26 16:37 - 00000000 ____D C:\Program Files\iPod 2013-12-26 16:37 - 2009-01-24 20:58 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-12-26 16:33 - 2013-12-26 16:33 - 00000000 ____D C:\Windows\LastGood 2013-12-26 16:33 - 2009-01-24 09:53 - 00000000 ____D C:\Users\Sarah 2013-12-26 16:29 - 2013-12-26 16:29 - 00000000 ____D C:\Program Files\QuickTime 2013-12-26 16:18 - 2006-11-02 13:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-26 16:18 - 2006-11-02 13:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-26 14:24 - 2008-01-21 08:16 - 01601866 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-26 14:21 - 2013-10-14 21:32 - 00000000 ____D C:\Users\Sarah\AppData\Local\FreePDF_XP 2013-12-26 14:20 - 2009-01-24 20:18 - 00000434 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2013-12-26 14:18 - 2006-11-02 14:01 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-26 14:18 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-25 21:59 - 2012-04-27 17:14 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-12-22 12:03 - 2013-12-22 12:03 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-21 09:52 - 2012-10-18 22:28 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-12-21 09:52 - 2012-10-18 22:28 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-12-17 22:35 - 2013-12-07 21:52 - 00000000 ____D C:\Users\Sarah\Documents\§TRIP 2014 2013-12-13 18:43 - 2006-11-02 13:47 - 00395888 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-13 18:39 - 2008-10-23 12:25 - 00000000 ____D C:\Windows\system32\RTCOM 2013-12-12 20:06 - 2008-12-04 05:45 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-12 20:04 - 2013-08-14 23:22 - 00000000 ____D C:\Windows\system32\MRT 2013-12-12 20:01 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-12-10 23:01 - 2009-01-25 19:51 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\Skype 2013-12-10 20:01 - 2008-12-04 06:01 - 00000000 ____D C:\ProgramData\Skype 2013-12-10 20:00 - 2012-11-29 07:46 - 00000000 ___RD C:\Program Files\Skype 2013-12-07 21:52 - 2013-12-07 21:52 - 00000000 ____D C:\Users\Sarah\Documents\Neuer Ordner 2013-12-02 20:19 - 2013-12-02 20:19 - 01545496 _____ (Graboid Inc) C:\Users\Sarah\Downloads\GraboidVideoInstaller-4.631.exe Files to move or delete: ==================== C:\Users\Sarah\AppData\Roaming\desktop.ini Some content of TEMP: ==================== C:\Users\Sarah\AppData\Local\Temp\avgnt.exe C:\Users\Sarah\AppData\Local\Temp\FreemakeVideoConverter_4.1.2.1.exe C:\Users\Sarah\AppData\Local\Temp\SHSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-26 14:25 ==================== End Of Log ============================ Addition Logfile: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 25-12-2013 Ran by Sarah at 2013-12-26 17:57:41 Running from C:\Users\Sarah\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) 1400 (Version: 82.0.242.000) 1400_Help (Version: 82.0.242.000) 1400Trb (Version: 82.0.242.000) 2007 Microsoft Office system (Version: 12.0.6612.1000) 32 Bit HP CIO Components Installer (Version: 7.1.8) Adobe Flash Player 10 ActiveX (Version: 10.2.159.1) Adobe Flash Player 11 Plugin (Version: 11.9.900.117) Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8) AIO_CDB_ProductContext (Version: 82.0.242.000) AIO_CDB_Software (Version: 82.0.242.000) AIO_Scan (Version: 82.0.173.000) Aldi Suisse Foto Service 4.9 (Version: 4.9) Apple Application Support (Version: 2.3.6) Apple Mobile Device Support (Version: 7.0.0.117) Apple Software Update (Version: 2.1.3.127) ArcSoft Magic-i Visual Effects 2 (Version: 2.0.1.39) ArcSoft WebCam Companion 2 ATI Catalyst Install Manager (Version: 3.0.682.0) Avira Free Antivirus (Version: 14.0.2.286) Bonjour (Version: 3.0.0.10) Brother MFL-Pro Suite (Version: 1.00) BufferChm (Version: 82.0.173.000) Business Contact Manager für Outlook 2007 SP2 (Version: 3.0.8619.1) Catalyst Control Center - Branding (Version: 1.00.0000) Catalyst Control Center Core Implementation (Version: 2008.0717.2343.40629) Catalyst Control Center Graphics Full Existing (Version: 2008.0717.2343.40629) Catalyst Control Center Graphics Full New (Version: 2008.0717.2343.40629) Catalyst Control Center Graphics Light (Version: 2008.0717.2343.40629) Catalyst Control Center Graphics Previews Common (Version: 2008.0717.2343.40629) Catalyst Control Center Graphics Previews Vista (Version: 2008.0717.2343.40629) Catalyst Control Center InstallProxy (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Chinese Standard (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Chinese Traditional (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Czech (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Danish (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Dutch (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Finnish (Version: 2008.0717.2343.40629) Catalyst Control Center Localization French (Version: 2008.0717.2343.40629) Catalyst Control Center Localization German (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Greek (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Hungarian (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Italian (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Japanese (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Korean (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Norwegian (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Polish (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Portuguese (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Russian (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Spanish (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Swedish (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Thai (Version: 2008.0717.2343.40629) Catalyst Control Center Localization Turkish (Version: 2008.0717.2343.40629) CCC Help Chinese Standard (Version: 2008.0717.2342.40629) CCC Help Chinese Traditional (Version: 2008.0717.2342.40629) CCC Help Czech (Version: 2008.0717.2342.40629) CCC Help Danish (Version: 2008.0717.2342.40629) CCC Help Dutch (Version: 2008.0717.2342.40629) CCC Help English (Version: 2008.0717.2342.40629) CCC Help Finnish (Version: 2008.0717.2342.40629) CCC Help French (Version: 2008.0717.2342.40629) CCC Help German (Version: 2008.0717.2342.40629) CCC Help Greek (Version: 2008.0717.2342.40629) CCC Help Hungarian (Version: 2008.0717.2342.40629) CCC Help Italian (Version: 2008.0717.2342.40629) CCC Help Japanese (Version: 2008.0717.2342.40629) CCC Help Korean (Version: 2008.0717.2342.40629) CCC Help Norwegian (Version: 2008.0717.2342.40629) CCC Help Polish (Version: 2008.0717.2342.40629) CCC Help Portuguese (Version: 2008.0717.2342.40629) CCC Help Russian (Version: 2008.0717.2342.40629) CCC Help Spanish (Version: 2008.0717.2342.40629) CCC Help Swedish (Version: 2008.0717.2342.40629) CCC Help Thai (Version: 2008.0717.2342.40629) CCC Help Turkish (Version: 2008.0717.2342.40629) ccc-core-static (Version: 2008.0717.2343.40629) ccc-utility (Version: 2008.0717.2343.40629) CCleaner (Version: 4.06) Click to Disc (Version: 1.2.52.09250) Click to Disc Editor (Version: 1.2.51) Copy (Version: 82.0.188.000) CustomerResearchQFolder (Version: 1.00.0000) D3DX10 (Version: 15.4.2368.0902) Destinations (Version: 82.0.173.000) DeviceManagementQFolder (Version: 1.00.0000) Die Sims 2: Open For Business Die Sims 2: Wilde Campus-Jahre Die Sims™ 2 Apartment-Leben Die Sims™ 2 Freizeit-Spaß DivX Converter (Version: 7.1.0) DivX Plus DirectShow Filters DivX Setup (Version: 2.5.0.15) DivX Version Checker (Version: 7.1.0.2) DocProc (Version: 8.1.0.0) DocProcQFolder (Version: 1.00.0000) Dr_Brain_GJ_Vol2 Dropbox (HKCU Version: 1.6.16) eSupportQFolder (Version: 1.00.0000) ExtraFilm Designer CH DE Fax (Version: 82.0.188.000) Freemake Video Converter Version 4.1.2 (Version: 4.1.2) FreePDF (Remove only) Google Chrome (Version: 31.0.1650.63) Google Desktop (Version: 5.9.0911.03589) Google Earth (Version: 4.2.205.5730) Google Talk (remove only) Google Toolbar for Internet Explorer (Version: 1.0.0) Google Toolbar for Internet Explorer (Version: 7.5.4805.320) Google Update Helper (Version: 1.3.22.3) GPL Ghostscript 8.56 GPL Ghostscript Fonts HDAUDIO SoftV92 Data Fax Modem with SmartCP HP Customer Participation Program 8.0 (Version: 8.0) HP Imaging Device Functions 8.0 (Version: 8.0) HP OCR Software 8.0 (Version: 8.0) HP OrderReminder (Version: 2.1) HP Photosmart Essential (Version: 1.12.0.46) HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B (Version: 8.0) HP Product Assistant (Version: 100.000.001.000) HP Solution Center 8.0 (Version: 8.0) HP Update (Version: 5.003.001.001) HPDiagnosticAlert (Version: 1.00.0000) HPProductAssistant (Version: 82.0.173.000) HPSSupply (Version: 2.1.3.0000) ICQ6.5 (Version: 6.5) ifolor Bestellsoftware 3.6 (Version: 3.6.185.0) Intel PROSet Wireless Intel(R) PROSet/Wireless WiFi-Software (Version: 12.01.1000) iTunes (Version: 11.1.3.8) LaserJet 1018 MarketResearch (Version: 82.0.174.000) Me&My VAIO (Version: 1.0.0.11140) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Office 2003 Web Components (Version: 11.0.8003.0) Microsoft Office 2007 Primary Interop Assemblies (Version: 12.0.4518.1014) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Professional Hybrid 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Small Business Connectivity Components (Version: 2.0.7024.0) Microsoft Office Suite Activation Assistant (Version: 2.9) Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) (Version: 9.4.5000.00) Microsoft SQL Server Native Client (Version: 9.00.5000.00) Microsoft SQL Server VSS Writer (Version: 9.00.5000.00) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Move Media Player Mozilla Firefox 26.0 (x86 de) (Version: 26.0) Mozilla Maintenance Service (Version: 26.0) MSVCRT (Version: 15.4.2862.0708) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) Music Transfer (Version: 1.2.00.17290) MyFreeCodec Nestea Everest Screen Saver Nokia Connectivity Cable Driver (Version: 7.1.20.0) NTI CD & DVD-Maker (Version: 6.5) NTI CD & DVD-Maker 6.5 Gold (Version: 6.5) OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0) OpenMG Secure Module 5.1.00 (Version: 5.1.00.05200) PC Connectivity Solution (Version: 9.39.0.0) Picasa 2 (Version: 2.0) Primo (Version: 1.00.0000) QuickTime (Version: 7.74.80.86) RealPlayer Realtek High Definition Audio Driver (Version: 6.0.1.5653) RedMon - Redirection Port Monitor Roxio Central Audio (Version: 3.7.0) Roxio Central Copy (Version: 3.7.0) Roxio Central Core (Version: 3.7.0) Roxio Central Data (Version: 3.7.0) Roxio Central Tools (Version: 3.7.0) Roxio Easy Media Creator 10 LJ (Version: 10.1) Roxio Easy Media Creator Home (Version: 10.1.296) Samsung Kies (Version: 2.5.1.12123_2) SAMSUNG Mobile Composite Device Software Samsung Mobile Modem Device Software SAMSUNG Mobile Modem Driver Set Samsung Mobile phone USB driver Software SAMSUNG Mobile USB Modem 1.0 Software SAMSUNG Mobile USB Modem Software Samsung New PC Studio (Version: 1.00.0000) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.16.0) SAMSUNG USB Mobile Device Software SamsungConnectivityCableDriver (Version: 6.83.6.2.1) Scan (Version: 8.1.0.0) Segoe UI (Version: 15.4.2271.0615) Setting Utility Series (Version: 4.2.0.10150) Skins (Version: 2008.0717.2343.40629) Skype™ 6.11 (Version: 6.11.102) Software Info for Me&My VAIO (Version: 1.0.0.09110) SolutionCenter (Version: 82.0.188.000) Sony Ericsson PC Companion 2.02.002 (Version: 2.02.002) Sony Ericsson Update Engine (Version: 2.11.10.7) Sony Picture Utility (Version: 3.3.01.09300) Sony Video Shared Library (Version: 3.5.00) Status (Version: 82.0.173.000) steuern.lu.2008 nP 4.0 steuern.lu.2009 nP 5.0 steuern.lu.2010 nP 6.0 (Version: 6.0) steuern.lu.2011 nP 7.0.1 (Version: 7.0.1) steuern.lu.2012 nP 8.0 (Version: 8.0) Synaptics Pointing Device Driver (Version: 9.1.13.0) Toolbox (Version: 82.0.173.000) TrayApp (Version: 82.0.188.000) UltraStar 0.6.2 UnloadSupport (Version: 1.00.0000) Unterstützung für VAIO-Präsentation (Version: 1.1.0.08250) Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (Version: 9.00.5000.00) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition Update für Microsoft Office Excel 2007 Help (KB963678) Update für Microsoft Office Outlook 2007 Help (KB963677) Update für Microsoft Office Powerpoint 2007 Help (KB963669) Update für Microsoft Office Word 2007 Help (KB963665) VAIO Content Folder Setting (Version: 2.1.0.08260) VAIO Content Folder Watcher (Version: 1.0.01.09030) VAIO Content Metadata Intelligent Analyzing Manager (Version: 3.2.00.06115) VAIO Content Metadata Manager Setting (Version: 3.2.00.06062) VAIO Content Metadata XML Interface Library (Version: 3.2.00.06112) VAIO Control Center (Version: 3.2.0.09120) VAIO Data Restore Tool (Version: 1.0.04.01170) VAIO DVD Menu Data Basic (Version: 1.0.00.08130) VAIO Energie Verwaltung (Version: 3.2.0.10060) VAIO Entertainment Platform (Version: 3.2.3.10070) VAIO Event Service (Version: 4.2.0.11060) VAIO Launcher (Version: 2.2.0.09090) VAIO Marketing Tools VAIO Media plus (Version: 1.2.0.10230) VAIO Media plus Opening Movie (Version: 1.2.0.09100) VAIO Movie Story (Version: 1.3.01.08060) VAIO Movie Story Template Data (Version: 1.3.00.06120) VAIO MusicBox (Version: 2.1.1.09160) VAIO MusicBox Sample Music (Version: 1.1.00.14140) VAIO Original Function Setting (Version: 1.5.00.08150) VAIO Smart Network (Version: 2.2.0.11050) VAIO Update 4 (Version: 4.0.0.08280) VAIO Wallpaper Contents (Version: 1.3.0.10310) VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0) Visual C++ 2008 x86 Runtime - (v9.0.30729) (Version: 9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 (Version: 9.0.30729.01) WebReg (Version: 82.0.173.000) Windows Live Communications Platform (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3508.1109) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0) Windows Live Installer (Version: 15.4.3502.0922) Windows Live Messenger (Version: 15.4.3502.0922) Windows Live Photo Common (Version: 15.4.3502.0922) Windows Live PIMT Platform (Version: 15.4.3508.1109) Windows Live SOXE (Version: 15.4.3502.0922) Windows Live SOXE Definitions (Version: 15.4.3502.0922) Windows Live UX Platform (Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109) Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0) (Version: 08/22/2008 7.0.0.0) WinDVD for VAIO (Version: 8.0-B9.602) xp-AntiSpy 3.97-9 ==================== Restore Points ========================= 15-11-2013 17:41:47 Geplanter Prüfpunkt 21-11-2013 19:52:05 Geplanter Prüfpunkt 22-11-2013 17:04:07 Geplanter Prüfpunkt 23-11-2013 08:08:05 Geplanter Prüfpunkt 24-11-2013 16:13:45 Geplanter Prüfpunkt 25-11-2013 16:22:42 Geplanter Prüfpunkt 27-11-2013 19:33:54 Geplanter Prüfpunkt 02-12-2013 20:00:51 Geplanter Prüfpunkt 05-12-2013 20:28:47 Geplanter Prüfpunkt 08-12-2013 20:45:21 Geplanter Prüfpunkt 09-12-2013 17:23:20 Geplanter Prüfpunkt 10-12-2013 20:31:11 Geplanter Prüfpunkt 12-12-2013 18:56:50 Geplanter Prüfpunkt 12-12-2013 18:58:33 Windows Update 16-12-2013 19:08:52 Geplanter Prüfpunkt 17-12-2013 18:21:15 Geplanter Prüfpunkt 22-12-2013 11:34:17 Geplanter Prüfpunkt 23-12-2013 19:47:57 Geplanter Prüfpunkt 24-12-2013 08:19:35 Geplanter Prüfpunkt 25-12-2013 22:19:10 Geplanter Prüfpunkt 26-12-2013 15:33:08 Gerätetreiber-Paketinstallation: Apple Netzwerkadapter ==================== Hosts content: ========================== 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {1698B380-3CBA-4749-AE6C-311910393130} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files\Ask.com\UpdateTask.exe Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {292472D7-5C57-4A7B-8756-C3182F944308} - System32\Tasks\SONY\VAIO Wallpaper Setting Tool\VAIO Wallpaper Setting Tool => C:\Program Files\sony\VAIO Wallpaper Setting Tool\VWSet.exe [2008-06-27] (Sony Corporation) Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {3E8A15CB-B8FE-453D-BCDE-6199DC002ABA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-07] (Google Inc.) Task: {415A322E-9312-4A23-8D5F-C3515A6C8B31} - System32\Tasks\SONY\VAIO Update\VAIO Update => C:\Program Files\sony\VAIO Update 4\VAIOUpdt.exe [2008-08-28] (Sony Corporation) Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {8879B9B2-AC2E-4364-A3F5-3003B5E5F859} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {8BDB90A4-BE1A-4580-B4A4-7D77E657454B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-07] (Google Inc.) Task: {9638A763-2266-4C8D-8813-30E1105D3618} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {A4DCE0E8-5B84-4B5B-BB72-37DE28A0A218} - System32\Tasks\SONY\Me&My VAIO\Me&My VAIO => C:\Program Files\Sony\Me&My VAIO\QLGuide.exe Task: {DB9473B2-B3B4-4F2E-AA68-15BD9A4B1C7D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-09-19] (Piriform Ltd) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] () Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2008-10-23 19:48 - 2008-10-07 02:47 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll 2013-10-10 22:31 - 2013-10-10 22:31 - 01920512 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.UI\30692e977b98ee8676445954a1fd4275\Kies.UI.ni.dll 2013-08-14 23:22 - 2013-08-14 23:22 - 00078848 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.MVVM\73e3aae136f67d671daf3a36793777fc\Kies.MVVM.ni.dll 2013-08-14 23:22 - 2013-08-14 23:22 - 00184832 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\ae1c9ecb8ec8e593f51cbbe7979c7767\Kies.Common.DeviceServiceLib.Interface.ni.dll 2013-10-10 22:37 - 2013-10-10 22:37 - 00347648 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePhoto\0649849ea953692629ff06fb35daff11\DevicePhoto.ni.dll 2013-10-10 22:37 - 2013-10-10 22:37 - 00293888 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceVideo\0ade19d3962a554148e84631b24910ba\DeviceVideo.ni.dll 2013-10-10 22:37 - 2013-10-10 22:37 - 00615424 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePodcast\a6e186c248600b767efb4b728ed480f2\DevicePodcast.ni.dll 2013-08-14 23:23 - 2013-08-14 23:23 - 00307200 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DummyStorePlugin\5c4dbc3c1e024e1d417763383ccde01e\DummyStorePlugin.ni.dll 2013-08-14 23:23 - 2013-08-14 23:23 - 13033984 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Theme\1b83ce8db8f120b5e463846c0bf4ab0f\Kies.Theme.ni.dll 2013-10-10 22:31 - 2013-10-10 22:31 - 00571392 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\7263a97f5423c5667fa809c67da42edb\Kies.Common.DeviceServiceLib.FileService.ni.dll 2013-07-12 21:25 - 2013-07-12 21:25 - 00038912 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\84472d2ceeb937633639e4252adb85bb\Kies.Common.DeviceServiceLib.FirmwareUpdate.Firmw areUpdateAgentHelper.ni.dll 2013-08-14 23:22 - 2013-08-14 23:22 - 00232960 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ASF_cSharpAPI\6a4bcf254a32a7a34c46cad07a50bd0a\ASF_cSharpAPI.ni.dll 2013-12-22 12:03 - 2013-12-22 12:03 - 03559024 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2013-12-05 21:02 - 2013-12-04 03:48 - 04055504 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-05 21:02 - 2013-12-04 03:48 - 00399312 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-05 21:01 - 2013-12-04 03:47 - 01619408 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll 2006-12-10 20:51 - 2006-12-10 20:51 - 00065536 ____R () C:\Program Files\HP\Digital Imaging\bin\crm\xmlparse.dll 2006-12-10 20:51 - 2006-12-10 20:51 - 00077824 ____R () C:\Program Files\HP\Digital Imaging\bin\crm\xmltok.dll 2013-12-05 21:02 - 2013-12-04 03:48 - 13586896 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll 2008-12-04 05:32 - 2008-12-04 05:32 - 00014848 _____ () C:\Windows\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll 2008-08-26 11:41 - 2008-08-26 11:41 - 00016384 ____R () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll 2013-12-05 21:01 - 2013-12-04 03:47 - 00702416 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libglesv2.dll 2013-12-05 21:01 - 2013-12-04 03:47 - 00099792 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libegl.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 01242952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-11-04 19:57 - 2013-11-04 19:57 - 16233864 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll 2013-12-26 16:49 - 2013-11-08 09:51 - 14447630 _____ () C:\Program Files\Freemake\COM\1.1\avcodec-54.dll 2013-12-26 16:49 - 2013-11-08 09:51 - 01078557 _____ () C:\Program Files\Freemake\COM\1.1\xvidcore.dll 2013-12-26 16:49 - 2013-11-08 09:51 - 00190990 _____ () C:\Program Files\Freemake\COM\1.1\avutil-52.dll 2013-12-26 16:49 - 2013-11-08 09:51 - 03028494 _____ () C:\Program Files\Freemake\COM\1.1\avformat-54.dll 2013-12-26 16:49 - 2013-11-08 09:51 - 00333838 _____ () C:\Program Files\Freemake\COM\1.1\swscale-2.dll 2013-12-26 16:49 - 2013-11-08 09:51 - 00138766 _____ () C:\Program Files\Freemake\COM\1.1\avresample-1.dll 2013-12-26 16:50 - 2013-11-08 09:51 - 00234717 _____ () C:\Program Files\Freemake\COM\1.1\libdvdnav.dll 2013-12-26 16:50 - 2013-11-08 09:51 - 00054182 _____ () C:\Program Files\Freemake\COM\1.1\libdvdcss-2.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/26/2013 02:18:49 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/26/2013 09:30:57 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/26/2013 00:06:02 AM) (Source: EventSystem) (User: ) Description: 80070005EventSystem.EventSubscription{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000} Error: (12/25/2013 10:00:00 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/24/2013 11:04:13 AM) (Source: EventSystem) (User: ) Description: 80070005EventSystem.EventSubscription{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000} Error: (12/24/2013 08:21:08 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/23/2013 09:05:35 PM) (Source: MsiInstaller) (User: Sarah-PC) Description: Produkt: iCloud -- Systemsteuerung „iCloud“ 3.1 erfordert Windows 7 oder Windows 8. Error: (12/23/2013 08:03:13 PM) (Source: Windows Backup) (User: ) Description: Die Dateisicherung ist aufgrund eines Fehlers beim Schreiben in das Sicherungsziel G:\ fehlgeschlagen. Fehler: Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (12/23/2013 07:53:15 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/22/2013 11:08:38 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (12/26/2013 04:34:09 PM) (Source: Service Control Manager) (User: ) Description: Apple Mobile Device1600001Neustart des Diensts Error: (12/26/2013 02:20:57 PM) (Source: Service Control Manager) (User: ) Description: Windows Media Player-NetzwerkfreigabedienstUPnP-Gerätehost%%1058 Error: (12/26/2013 02:19:44 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (12/26/2013 02:18:49 PM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (12/26/2013 09:57:13 AM) (Source: Service Control Manager) (User: ) Description: Windows Media Player-NetzwerkfreigabedienstUPnP-Gerätehost%%1058 Error: (12/26/2013 09:31:53 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (12/26/2013 09:30:57 AM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (12/25/2013 10:03:58 PM) (Source: Service Control Manager) (User: ) Description: 30000Google Software Updater Error: (12/25/2013 10:03:58 PM) (Source: DCOM) (User: ) Description: 1053gusvc{89DAE4CD-9F17-4980-902A-99BA84A8F5C8} Error: (12/25/2013 10:03:09 PM) (Source: Service Control Manager) (User: ) Description: Windows Media Player-NetzwerkfreigabedienstUPnP-Gerätehost%%1058 Microsoft Office Sessions: ========================= Error: (05/30/2013 08:30:41 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error: (07/03/2009 01:34:52 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error: (06/26/2009 05:42:56 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 7 seconds with 0 seconds of active time. This session ended with a crash. Error: (06/26/2009 05:42:18 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 4 seconds with 0 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2012-08-28 00:50:34.205 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-08-28 00:50:34.050 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-08-28 00:50:33.795 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-08-28 00:50:33.632 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-08-28 00:50:33.458 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-08-28 00:50:33.281 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-08-28 00:50:33.018 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18000_none_b31e1252666640f6\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-08-28 00:50:32.838 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18000_none_b31e1252666640f6\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-08-28 00:50:32.619 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18000_none_b31e1252666640f6\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-08-28 00:50:32.442 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18000_none_b31e1252666640f6\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 69% Total physical RAM: 3038.13 MB Available physical RAM: 925.57 MB Total Pagefile: 6285.24 MB Available Pagefile: 3365.4 MB Total Virtual: 2047.88 MB Available Virtual: 1905.47 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:288.23 GB) (Free:10.83 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive f: (VIDEO_TS) (CDROM) (Total:5.5 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298 GB) (Disk ID: 6C9DCDDD) Partition 1: (Not Active) - (Size=10 GB) - (Type=27) Partition 2: (Active) - (Size=288 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
26.12.2013, 23:07 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | optimizer pro Hallo und
__________________Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
30.12.2013, 00:15 | #3 |
| optimizer pro Vielen Dank für die Hilfe!! Hier das Logfile:
__________________Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.07.0.1008 www.malwarebytes.org Database version: v2013.12.29.06 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 8.0.6001.19489 Sarah :: SARAH-PC [administrator] 29.12.2013 23:55:32 mbar-log-2013-12-29 (23-55-32).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 229637 Time elapsed: 17 minute(s), 38 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) |
30.12.2013, 00:19 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | optimizer pro Adware/Junkware/Toolbars entfernen 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: SC - Schortcut Cleaner Downloade dir bitte Shortcut Cleaner (by Grinler) auf deinen Desktop.
4. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten |
30.12.2013, 10:08 | #5 |
| optimizer pro Danke! Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 30/12/2013 um 09:01:59 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : Sarah - SARAH-PC # Gestartet von : C:\Users\Sarah\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec Ordner Gelöscht : C:\Program Files\myfree codec Ordner Gelöscht : C:\Users\Sarah\AppData\LocalLow\boost_interprocess Ordner Gelöscht : C:\Users\Sarah\AppData\Roaming\OpenCandy Datei Gelöscht : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1698B380-3CBA-4749-AE6C-311910393130} [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1698B380-3CBA-4749-AE6C-311910393130} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_104D0200 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C4C4F1F4-3074-4CB6-9FB8-0A64273166F0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F994E0D9-8335-48F1-99C2-A712C21F8D5F} Schlüssel Gelöscht : HKCU\Software\Myfree Codec Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Schlüssel Gelöscht : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C} Schlüssel Gelöscht : HKLM\Software\Myfree Codec Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyFreeCodec Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9 ***** [ Browser ] ***** -\\ Internet Explorer v8.0.6001.19489 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\zs3abbli.default\prefs.js ] -\\ Google Chrome v31.0.1650.63 [ Datei : C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [7794 octets] - [30/12/2013 09:01:05] AdwCleaner[S0].txt - [7676 octets] - [30/12/2013 09:01:59] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7736 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows Vista (TM) Home Premium x86 Ran by Sarah on 30.12.2013 at 9:13:54.30 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9 ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Sarah\AppData\Roaming\mozilla\firefox\profiles\zs3abbli.default\minidumps [271 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 30.12.2013 at 9:16:36.01 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Shortcut Cleaner 1.2.6 by Lawrence Abrams (Grinler) hxxp://www.bleepingcomputer.com/ Copyright 2008-2013 BleepingComputer.com More Information about Shortcut Cleaner can be found at this link: hxxp://www.bleepingcomputer.com/download/shortcut-cleaner/ Windows Version: Windows Vista (TM) Home Premium Service Pack 2 Program started at: 12/30/2013 09:47:45 AM. Scanning for registry hijacks: * No issues found in the Registry. Searching for Hijacked Shortcuts: Searching C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\ Searching C:\ProgramData\Microsoft\Windows\Start Menu\ Searching C:\Users\Sarah\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ Searching C:\Users\Public\Desktop\ Searching C:\Users\Sarah\Desktop 0 bad shortcuts found. Program finished at: 12/30/2013 09:47:48 AM Execution time: 0 hours(s), 0 minute(s), and 2 seconds(s) FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-12-2013 01 Ran by Sarah (administrator) on SARAH-PC on 30-12-2013 10:02:20 Running from C:\Users\Sarah\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Realtek Semiconductor) C:\Windows\RTKAUDIOSERVICE.EXE (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Teruten) C:\Windows\System32\FsUsbExService.Exe (InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Sony Corporation) C:\Program Files\sony\Network Utility\NSUService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (ArcSoft, Inc.) C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files\sony\VAIO Power Management\SPMService.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Sony Corporation) C:\Program Files\sony\ISB Utility\ISBMgr.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Brother Industries, Ltd.) C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe (Sony Corporation) C:\Program Files\sony\VAIO Update 4\VAIOUpdt.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Sony Corporation) C:\Program Files\sony\Network Utility\LANUtil.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Samsung) C:\Program Files\Samsung\Kies\Kies.exe (Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Brother Industries, Ltd.) C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe (Sony Corporation) C:\Program Files\sony\VAIO Power Management\SPMgr.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Windows\System32\sdclt.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Farbar) C:\Users\Sarah\Downloads\FRST (1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6295552 2008-10-17] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [835584 2007-03-10] (Synaptics, Inc.) HKLM\...\Run: [ISBMgr.exe] - C:\Program Files\sony\ISB Utility\ISBMgr.exe [317280 2008-04-03] (Sony Corporation) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.) HKLM\...\Run: [OrderReminder] - C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [98304 2006-01-30] (Hewlett-Packard) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [FreePDFAssistent] - C:\Program Files\FreePDF\FreePDFA.exe [150528 2003-12-24] (shbox) HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.) HKLM\...\Run: [BrMfcWnd] - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [745472 2009-02-10] (Brother Industries, Ltd.) HKLM\...\Run: [ControlCenter3] - C:\Program Files\Brother\ControlCenter3\BrCtrCen.exe [77824 2007-10-30] (Brother Industries, Ltd.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-21] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [310280 2012-12-20] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [FreePDF Assistant] - C:\Program Files\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) Winlogon\Notify\VESWinlogon: C:\Windows\system32\VESWinlogon.dll (Sony Corporation) HKCU\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [270336 2008-11-05] (Sony Corporation) HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2008-12-04] (Google Inc.) HKCU\...\Run: [Sony Ericsson PC Companion] - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [433872 2011-10-21] (Sony Ericsson) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1476104 2012-12-20] (Samsung) HKCU\...\Run: [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup HKCU\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844296 2012-12-20] (Samsung) MountPoints2: {5284d153-e9f2-11dd-8231-806e6f6e6963} - F:\Autorun.exe HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [ 2008-12-04] (Google Inc.) HKU\Default\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [ 2008-11-05] (Sony Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [ 2008-12-04] (Google Inc.) HKU\Default User\...\Run: [NSUFloatingUI] - C:\Program Files\sony\Network Utility\LANUtil.exe [ 2008-11-05] (Sony Corporation) AppInit_DLLs: [ ] () Startup: C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.sonystyle-europe.com?csint=140016340 hxxp://www.club-vaio.com/vbc/ebay/index.html hxxp://www.club-vaio.com/vbc HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.studivz.net/ hxxp://www.southernfm.co.uk/ hxxp://www.cambridgeesol-luzern.ch/index2.htm hxxp://www.cambridgeesol.org/exams/exams-info/results-information/lost-certificates.html https://mail.stud.unilu.ch/webmail/ hxxp://www.nzz.ch/ hxxp://news.bbc.co.uk/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM - DefaultScope value is missing. BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer) BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} hxxp://www.extrafilm.ch/ImageUploader5.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUpldde-ch.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\zs3abbli.default FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF SelectedSearchEngine: Google FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=6.0.12.69 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprjplug;version=1.0.3.69 - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.69 - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @movenetworks.com/Quantum Media Player - C:\Users\Sarah\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\googledesktop.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Microsoft .NET Framework Assistant - C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\zs3abbli.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Program Files\Real\RealPlayer\browserrecord FF Extension: RealPlayer Browser Record Plugin - C:\Program Files\Real\RealPlayer\browserrecord FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF HKLM\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF Extension: Freemake Video Converter Plugin - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ Chrome: ======= CHR HomePage: CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (DivX Player Netscape Plugin) - C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc) CHR Plugin: (QuickTime Plug-in 7.6.5) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.5) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.5) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.5) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.5) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.5) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll No File CHR Plugin: (QuickTime Plug-in 7.6.5) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll No File CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Move Media Player 7) - C:\Users\Sarah\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.70.10) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (Google Drive) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Freemake Video Converter) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0 CHR Extension: (Google Wallet) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.126_0 CHR Extension: (Gmail) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx ========================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-21] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG) S4 EFUploadSrv; C:\Program Files\ExtraFilm Designer CH DE\EFUploadSrv.exe [1716224 2009-07-09] (Textalk AB) S3 GoogleDesktopManager-110309-193829; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-02-11] (Google) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 NSUService; C:\Program Files\sony\Network Utility\NSUService.exe [303104 2008-11-05] (Sony Corporation) S3 ServiceLayer; C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe [651776 2009-09-17] (Nokia) S3 SOHCImp; C:\Program Files\Sony\VAIO Media plus\SOHCImp.exe [103712 2008-10-21] (Sony Corporation) S3 SOHDms; C:\Program Files\Sony\VAIO Media plus\SOHDms.exe [353568 2008-10-21] (Sony Corporation) S3 SOHDs; C:\Program Files\Sony\VAIO Media plus\SOHDs.exe [62752 2008-10-21] (Sony Corporation) S3 Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [155344 2011-06-29] (Avanquest Software) S3 SPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe [77824 2008-05-20] (Sony Corporation) R2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S4 VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [73728 2008-09-08] (Sony Corporation) S4 VAIO Event Service; C:\Program Files\sony\VAIO Event Service\VESMgr.exe [203624 2008-11-05] (Sony Corporation) R2 VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [411488 2008-09-05] (Sony Corporation) S4 VcmIAlzMgr; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [337184 2008-06-11] (Sony Corporation) S4 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [279848 2008-09-08] (Sony Corporation) S4 VzCdbSvc; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2008-09-08] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== S3 61883; C:\Windows\System32\DRIVERS\61883.sys [45696 2008-01-21] (Microsoft Corporation) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17920 2008-04-24] (ArcSoft, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-21] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-21] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-25] (Avira Operations GmbH & Co. KG) R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [36608 2009-03-31] () R0 Lbd; C:\Windows\System32\DRIVERS\Lbd.sys [64288 2010-12-03] (Lavasoft AB) S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [86824 2008-10-21] (MCCI Corporation) S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [15016 2008-10-21] (MCCI Corporation) S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [114600 2008-10-21] (MCCI Corporation) S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [108328 2008-10-21] (MCCI Corporation) S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [26024 2008-10-21] (MCCI Corporation) S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [104616 2008-10-21] (MCCI Corporation) S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [109736 2008-10-21] (MCCI Corporation) S3 s117bus; C:\Windows\System32\DRIVERS\s117bus.sys [82984 2007-06-25] (MCCI Corporation) S3 s117mdfl; C:\Windows\System32\DRIVERS\s117mdfl.sys [14888 2007-06-25] (MCCI Corporation) S3 s117mdm; C:\Windows\System32\DRIVERS\s117mdm.sys [108456 2007-06-25] (MCCI Corporation) S3 s117mgmt; C:\Windows\System32\DRIVERS\s117mgmt.sys [100264 2007-06-25] (MCCI Corporation) S3 s117nd5; C:\Windows\System32\DRIVERS\s117nd5.sys [22952 2007-06-25] (MCCI Corporation) S3 s117obex; C:\Windows\System32\DRIVERS\s117obex.sys [98344 2007-06-25] (MCCI Corporation) S3 s117unic; C:\Windows\System32\DRIVERS\s117unic.sys [98856 2007-06-25] (MCCI Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) S3 ss_bbus; C:\Windows\System32\DRIVERS\ss_bbus.sys [90112 2009-03-20] (MCCI) S3 ss_bmdfl; C:\Windows\System32\DRIVERS\ss_bmdfl.sys [14976 2009-03-20] (MCCI Corporation) S3 ss_bmdm; C:\Windows\System32\DRIVERS\ss_bmdm.sys [121856 2009-03-20] (MCCI Corporation) S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-30 10:02 - 2013-12-30 10:02 - 00000000 ____D C:\FRST 2013-12-30 09:52 - 2013-12-30 09:52 - 00000000 _____ C:\Users\Sarah\Downloads\Nicht bestätigt 156436.crdownload 2013-12-30 09:25 - 2013-12-30 09:25 - 01064199 _____ (Farbar) C:\Users\Sarah\Downloads\FRST (1).exe 2013-12-30 09:21 - 2013-12-30 09:47 - 00001814 _____ C:\sc-cleaner.txt 2013-12-30 09:20 - 2013-12-30 09:20 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Sarah\Downloads\sc-cleaner.exe 2013-12-30 09:16 - 2013-12-30 09:16 - 00000899 _____ C:\Users\Sarah\Desktop\JRT.txt 2013-12-30 09:13 - 2013-12-30 09:13 - 00000000 ____D C:\Windows\ERUNT 2013-12-30 09:12 - 2013-12-30 09:13 - 01034531 _____ (Thisisu) C:\Users\Sarah\Downloads\JRT (2).exe 2013-12-30 09:11 - 2013-12-30 09:11 - 01034531 _____ (Thisisu) C:\Users\Sarah\Downloads\JRT.exe 2013-12-30 09:11 - 2013-12-30 09:11 - 01034531 _____ (Thisisu) C:\Users\Sarah\Downloads\JRT (1).exe 2013-12-30 09:00 - 2013-12-30 09:02 - 00000000 ____D C:\AdwCleaner 2013-12-30 09:00 - 2013-12-30 09:00 - 01233962 _____ C:\Users\Sarah\Downloads\adwcleaner.exe 2013-12-29 23:04 - 2013-12-30 00:13 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-12-29 23:04 - 2013-12-29 23:55 - 00104664 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2013-12-29 23:00 - 2013-12-30 00:13 - 00000000 ____D C:\Users\Sarah\Desktop\mbar 2013-12-29 23:00 - 2013-12-29 23:55 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-12-29 22:59 - 2013-12-29 22:59 - 12582688 _____ (Malwarebytes Corp.) C:\Users\Sarah\Downloads\mbar-1.07.0.1008.exe 2013-12-26 17:57 - 2013-12-26 18:01 - 00034055 _____ C:\Users\Sarah\Downloads\Addition.txt 2013-12-26 17:55 - 2013-12-30 10:02 - 00025270 _____ C:\Users\Sarah\Downloads\FRST.txt 2013-12-26 17:55 - 2013-12-26 17:55 - 01061649 _____ (Farbar) C:\Users\Sarah\Downloads\FRST.exe 2013-12-26 16:50 - 2013-12-26 16:52 - 00000000 ____D C:\Users\Sarah\Documents\Freemake 2013-12-26 16:50 - 2013-12-26 16:51 - 00000000 ____D C:\ProgramData\Freemake 2013-12-26 16:50 - 2013-12-26 16:50 - 00001113 _____ C:\Users\Public\Desktop\Freemake Video Converter.lnk 2013-12-26 16:50 - 2013-12-26 16:50 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake 2013-12-26 16:49 - 2013-12-26 16:50 - 00000000 ____D C:\Program Files\Freemake 2013-12-26 16:48 - 2013-12-26 16:48 - 01271928 _____ (Ellora Assets Corporation ) C:\Users\Sarah\Downloads\FreemakeVideo4121ConverterSetup.exe 2013-12-26 16:39 - 2013-12-26 16:39 - 00001664 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-12-26 16:37 - 2013-12-26 16:39 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-12-26 16:37 - 2013-12-26 16:39 - 00000000 ____D C:\Program Files\iTunes 2013-12-26 16:37 - 2013-12-26 16:37 - 00000000 ____D C:\Program Files\iPod 2013-12-26 16:29 - 2013-12-26 16:29 - 00000000 ____D C:\Program Files\QuickTime 2013-12-22 12:03 - 2013-12-22 12:03 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-12 18:53 - 2013-10-30 03:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2013-12-12 18:53 - 2013-10-30 02:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-12 18:53 - 2013-10-30 01:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-12 18:53 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-12 18:52 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-12 18:52 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-12 18:52 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2013-12-12 18:52 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-12 18:52 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-12 18:51 - 2013-10-25 09:25 - 00916992 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-12 18:51 - 2013-10-25 09:24 - 01213440 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 18:51 - 2013-10-25 09:24 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-12 18:51 - 2013-10-25 09:22 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-12 18:51 - 2013-10-25 09:20 - 00611840 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2013-12-12 18:51 - 2013-10-25 09:19 - 06018560 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-12 18:51 - 2013-10-25 09:19 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-12 18:51 - 2013-10-25 09:19 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-12 18:51 - 2013-10-25 09:19 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 11111936 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 02005504 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 01469440 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-12 18:51 - 2013-10-25 09:18 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-12 18:51 - 2013-10-25 09:18 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-12 18:51 - 2013-10-25 09:16 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll 2013-12-12 18:51 - 2013-10-25 07:39 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-12 18:51 - 2013-10-25 05:55 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-12 18:51 - 2013-10-25 05:55 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-12 18:51 - 2013-10-25 05:53 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-12 18:51 - 2013-10-25 05:53 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-12 18:51 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-07 21:52 - 2013-12-17 22:35 - 00000000 ____D C:\Users\Sarah\Documents\§TRIP 2014 2013-12-07 21:52 - 2013-12-07 21:52 - 00000000 ____D C:\Users\Sarah\Documents\Neuer Ordner 2013-12-02 20:19 - 2013-12-02 20:19 - 01545496 _____ (Graboid Inc) C:\Users\Sarah\Downloads\GraboidVideoInstaller-4.631.exe ==================== One Month Modified Files and Folders ======= 2013-12-30 10:02 - 2013-12-30 10:02 - 00000000 ____D C:\FRST 2013-12-30 10:02 - 2013-12-26 17:55 - 00025270 _____ C:\Users\Sarah\Downloads\FRST.txt 2013-12-30 09:52 - 2013-12-30 09:52 - 00000000 _____ C:\Users\Sarah\Downloads\Nicht bestätigt 156436.crdownload 2013-12-30 09:47 - 2013-12-30 09:21 - 00001814 _____ C:\sc-cleaner.txt 2013-12-30 09:25 - 2013-12-30 09:25 - 01064199 _____ (Farbar) C:\Users\Sarah\Downloads\FRST (1).exe 2013-12-30 09:20 - 2013-12-30 09:20 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Sarah\Downloads\sc-cleaner.exe 2013-12-30 09:16 - 2013-12-30 09:16 - 00000899 _____ C:\Users\Sarah\Desktop\JRT.txt 2013-12-30 09:13 - 2013-12-30 09:13 - 00000000 ____D C:\Windows\ERUNT 2013-12-30 09:13 - 2013-12-30 09:12 - 01034531 _____ (Thisisu) C:\Users\Sarah\Downloads\JRT (2).exe 2013-12-30 09:11 - 2013-12-30 09:11 - 01034531 _____ (Thisisu) C:\Users\Sarah\Downloads\JRT.exe 2013-12-30 09:11 - 2013-12-30 09:11 - 01034531 _____ (Thisisu) C:\Users\Sarah\Downloads\JRT (1).exe 2013-12-30 09:09 - 2009-01-24 09:50 - 01779275 _____ C:\Windows\WindowsUpdate.log 2013-12-30 09:07 - 2012-12-30 13:17 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-30 09:06 - 2009-01-24 20:18 - 00000434 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2013-12-30 09:04 - 2013-10-14 21:32 - 00000000 ____D C:\Users\Sarah\AppData\Local\FreePDF_XP 2013-12-30 09:04 - 2010-02-07 23:06 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-30 09:03 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-30 09:03 - 2006-11-02 13:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-30 09:03 - 2006-11-02 13:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-30 09:02 - 2013-12-30 09:00 - 00000000 ____D C:\AdwCleaner 2013-12-30 09:02 - 2006-11-02 14:01 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-30 09:00 - 2013-12-30 09:00 - 01233962 _____ C:\Users\Sarah\Downloads\adwcleaner.exe 2013-12-30 00:13 - 2013-12-29 23:04 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-12-30 00:13 - 2013-12-29 23:00 - 00000000 ____D C:\Users\Sarah\Desktop\mbar 2013-12-29 23:55 - 2013-12-29 23:04 - 00104664 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2013-12-29 23:55 - 2013-12-29 23:00 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-12-29 23:51 - 2013-09-08 21:46 - 00000000 ____D C:\Users\Sarah\Desktop\Neuer Ordner 2013-12-29 23:01 - 2008-01-21 08:16 - 01601866 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-29 22:59 - 2013-12-29 22:59 - 12582688 _____ (Malwarebytes Corp.) C:\Users\Sarah\Downloads\mbar-1.07.0.1008.exe 2013-12-29 22:53 - 2013-10-13 09:09 - 00001238 _____ C:\Windows\PFRO.log 2013-12-26 18:01 - 2013-12-26 17:57 - 00034055 _____ C:\Users\Sarah\Downloads\Addition.txt 2013-12-26 17:55 - 2013-12-26 17:55 - 01061649 _____ (Farbar) C:\Users\Sarah\Downloads\FRST.exe 2013-12-26 16:52 - 2013-12-26 16:50 - 00000000 ____D C:\Users\Sarah\Documents\Freemake 2013-12-26 16:51 - 2013-12-26 16:50 - 00000000 ____D C:\ProgramData\Freemake 2013-12-26 16:50 - 2013-12-26 16:50 - 00001113 _____ C:\Users\Public\Desktop\Freemake Video Converter.lnk 2013-12-26 16:50 - 2013-12-26 16:50 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake 2013-12-26 16:50 - 2013-12-26 16:49 - 00000000 ____D C:\Program Files\Freemake 2013-12-26 16:48 - 2013-12-26 16:48 - 01271928 _____ (Ellora Assets Corporation ) C:\Users\Sarah\Downloads\FreemakeVideo4121ConverterSetup.exe 2013-12-26 16:39 - 2013-12-26 16:39 - 00001664 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-12-26 16:39 - 2013-12-26 16:37 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-12-26 16:39 - 2013-12-26 16:37 - 00000000 ____D C:\Program Files\iTunes 2013-12-26 16:37 - 2013-12-26 16:37 - 00000000 ____D C:\Program Files\iPod 2013-12-26 16:37 - 2009-01-24 20:58 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-12-26 16:33 - 2009-01-24 09:53 - 00000000 ____D C:\Users\Sarah 2013-12-26 16:29 - 2013-12-26 16:29 - 00000000 ____D C:\Program Files\QuickTime 2013-12-25 21:59 - 2012-04-27 17:14 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-12-22 12:03 - 2013-12-22 12:03 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-21 09:52 - 2012-10-18 22:28 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-12-21 09:52 - 2012-10-18 22:28 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-12-17 22:35 - 2013-12-07 21:52 - 00000000 ____D C:\Users\Sarah\Documents\§TRIP 2014 2013-12-13 18:43 - 2006-11-02 13:47 - 00395888 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-13 18:39 - 2008-10-23 12:25 - 00000000 ____D C:\Windows\system32\RTCOM 2013-12-12 20:06 - 2008-12-04 05:45 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-12 20:04 - 2013-08-14 23:22 - 00000000 ____D C:\Windows\system32\MRT 2013-12-12 20:01 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-12-10 23:01 - 2009-01-25 19:51 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\Skype 2013-12-10 20:01 - 2008-12-04 06:01 - 00000000 ____D C:\ProgramData\Skype 2013-12-10 20:00 - 2012-11-29 07:46 - 00000000 ___RD C:\Program Files\Skype 2013-12-07 21:52 - 2013-12-07 21:52 - 00000000 ____D C:\Users\Sarah\Documents\Neuer Ordner 2013-12-02 20:19 - 2013-12-02 20:19 - 01545496 _____ (Graboid Inc) C:\Users\Sarah\Downloads\GraboidVideoInstaller-4.631.exe Files to move or delete: ==================== C:\Users\Sarah\AppData\Roaming\desktop.ini Some content of TEMP: ==================== C:\Users\Sarah\AppData\Local\Temp\avgnt.exe C:\Users\Sarah\AppData\Local\Temp\FreemakeVideoConverter_4.1.2.1.exe C:\Users\Sarah\AppData\Local\Temp\Quarantine.exe C:\Users\Sarah\AppData\Local\Temp\SHSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-30 09:11 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 29-12-2013 01 Ran by Sarah at 2013-12-30 10:02:48 Running from C:\Users\Sarah\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (Version: - Microsoft) 1400 (Version: 82.0.242.000 - Hewlett-Packard) 1400_Help (Version: 82.0.242.000 - Hewlett-Packard) 1400Trb (Version: 82.0.242.000 - Hewlett-Packard) 2007 Microsoft Office system (Version: 12.0.6612.1000 - Microsoft Corporation) 32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Adobe Flash Player 10 ActiveX (Version: 10.2.159.1 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8 - Adobe Systems Incorporated) AIO_CDB_ProductContext (Version: 82.0.242.000 - Hewlett-Packard) AIO_CDB_Software (Version: 82.0.242.000 - Hewlett-Packard) AIO_Scan (Version: 82.0.173.000 - Hewlett-Packard) Aldi Suisse Foto Service 4.9 (Version: 4.9 - ORWO Net) Apple Application Support (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (Version: 2.1.3.127 - Apple Inc.) ArcSoft Magic-i Visual Effects 2 (Version: 2.0.1.39 - ArcSoft) ArcSoft WebCam Companion 2 (Version: - ArcSoft) ATI Catalyst Install Manager (Version: 3.0.682.0 - ATI Technologies, Inc.) Avira Free Antivirus (Version: 14.0.2.286 - Avira) Bonjour (Version: 3.0.0.10 - Apple Inc.) Brother MFL-Pro Suite (Version: 1.00 - Brother Industries, Ltd.) BufferChm (Version: 82.0.173.000 - Hewlett-Packard) Business Contact Manager für Outlook 2007 SP2 (Version: 3.0.8619.1 - Microsoft Corporation) Catalyst Control Center - Branding (Version: 1.00.0000 - ATI) Catalyst Control Center Core Implementation (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Graphics Full Existing (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Graphics Full New (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Graphics Light (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Graphics Previews Common (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Graphics Previews Vista (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center InstallProxy (Version: 2008.0717.2343.40629 - ATI Technologies, Inc.) Catalyst Control Center Localization Chinese Standard (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Chinese Traditional (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Czech (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Danish (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Dutch (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Finnish (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization French (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization German (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Greek (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Hungarian (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Italian (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Japanese (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Korean (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Norwegian (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Polish (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Portuguese (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Russian (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Spanish (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Swedish (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Thai (Version: 2008.0717.2343.40629 - ATI) Catalyst Control Center Localization Turkish (Version: 2008.0717.2343.40629 - ATI) CCC Help Chinese Standard (Version: 2008.0717.2342.40629 - ATI) CCC Help Chinese Traditional (Version: 2008.0717.2342.40629 - ATI) CCC Help Czech (Version: 2008.0717.2342.40629 - ATI) CCC Help Danish (Version: 2008.0717.2342.40629 - ATI) CCC Help Dutch (Version: 2008.0717.2342.40629 - ATI) CCC Help English (Version: 2008.0717.2342.40629 - ATI) CCC Help Finnish (Version: 2008.0717.2342.40629 - ATI) CCC Help French (Version: 2008.0717.2342.40629 - ATI) CCC Help German (Version: 2008.0717.2342.40629 - ATI) CCC Help Greek (Version: 2008.0717.2342.40629 - ATI) CCC Help Hungarian (Version: 2008.0717.2342.40629 - ATI) CCC Help Italian (Version: 2008.0717.2342.40629 - ATI) CCC Help Japanese (Version: 2008.0717.2342.40629 - ATI) CCC Help Korean (Version: 2008.0717.2342.40629 - ATI) CCC Help Norwegian (Version: 2008.0717.2342.40629 - ATI) CCC Help Polish (Version: 2008.0717.2342.40629 - ATI) CCC Help Portuguese (Version: 2008.0717.2342.40629 - ATI) CCC Help Russian (Version: 2008.0717.2342.40629 - ATI) CCC Help Spanish (Version: 2008.0717.2342.40629 - ATI) CCC Help Swedish (Version: 2008.0717.2342.40629 - ATI) CCC Help Thai (Version: 2008.0717.2342.40629 - ATI) CCC Help Turkish (Version: 2008.0717.2342.40629 - ATI) ccc-core-static (Version: 2008.0717.2343.40629 - Ihr Firmenname) ccc-utility (Version: 2008.0717.2343.40629 - ATI) CCleaner (Version: 4.06 - Piriform) Click to Disc (Version: 1.2.52.09250 - Sony Corporation) Click to Disc Editor (Version: 1.2.51 - Sony Corporation) Copy (Version: 82.0.188.000 - Hewlett-Packard) CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) D3DX10 (Version: 15.4.2368.0902 - Microsoft) Destinations (Version: 82.0.173.000 - Hewlett-Packard) DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Die Sims 2 (Version: - ) Die Sims 2: Open For Business (Version: - ) Die Sims 2: Wilde Campus-Jahre (Version: - ) Die Sims™ 2 Apartment-Leben (Version: - Electronic Arts) Die Sims™ 2 Freizeit-Spaß (Version: - Electronic Arts) DivX Converter (Version: 7.1.0 - DivX, Inc.) DivX Plus DirectShow Filters (Version: - DivX, Inc.) DivX Setup (Version: 2.5.0.15 - DivX, LLC) DivX Version Checker (Version: 7.1.0.2 - DivX, Inc.) DocProc (Version: 8.1.0.0 - Hewlett-Packard) DocProcQFolder (Version: 1.00.0000 - Hewlett-Packard) Dr_Brain_GJ_Vol2 (Version: - ) Dropbox (Version: 1.6.16 - Dropbox, Inc.) eSupportQFolder (Version: 1.00.0000 - Hewlett-Packard) ExtraFilm Designer CH DE (Version: - ) Fax (Version: 82.0.188.000 - Hewlett-Packard) Freemake Video Converter Version 4.1.2 (Version: 4.1.2 - Ellora Assets Corporation) FreePDF (Remove only) (Version: - ) Google Chrome (Version: 31.0.1650.63 - Google Inc.) Google Desktop (Version: 5.9.0911.03589 - Google) Google Earth (Version: 4.2.205.5730 - Google) Google Talk (remove only) (Version: - ) Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Google Toolbar for Internet Explorer (Version: 7.5.4805.320 - Google Inc.) Google Update Helper (Version: 1.3.22.3 - Google Inc.) GPL Ghostscript 8.56 (Version: - ) GPL Ghostscript Fonts (Version: - ) HP Customer Participation Program 8.0 (Version: 8.0 - HP) HP Imaging Device Functions 8.0 (Version: 8.0 - HP) HP OCR Software 8.0 (Version: 8.0 - HP) HP OrderReminder (Version: 2.1 - ) HP Photosmart Essential (Version: 1.12.0.46 - HP) HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B (Version: 8.0 - HP) HP Product Assistant (Version: 100.000.001.000 - Hewlett-Packard) HP Solution Center 8.0 (Version: 8.0 - HP) HP Update (Version: 5.003.001.001 - Hewlett-Packard) HPDiagnosticAlert (Version: 1.00.0000 - Microsoft) HPProductAssistant (Version: 82.0.173.000 - Hewlett-Packard) HPSSupply (Version: 2.1.3.0000 - Ihr Firmenname) ICQ6.5 (Version: 6.5 - ICQ) ifolor Bestellsoftware 3.6 (Version: 3.6.185.0 - Ifolor AG) Intel PROSet Wireless (Version: - ) Intel(R) PROSet/Wireless WiFi-Software (Version: 12.01.1000 - Intel(R) Corporation) iTunes (Version: 11.1.3.8 - Apple Inc.) LaserJet 1018 (Version: - ) MarketResearch (Version: 82.0.174.000 - Hewlett-Packard) Me&My VAIO (Version: 1.0.0.11140 - Sony Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation) Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Microsoft Office 2003 Web Components (Version: 11.0.8003.0 - Microsoft Corporation) Microsoft Office 2007 Primary Interop Assemblies (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Professional Hybrid 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Small Business Connectivity Components (Version: 2.0.7024.0 - Microsoft Corporation) Microsoft Office Suite Activation Assistant (Version: 2.9 - Microsoft Corporation) Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 (Version: - Microsoft Corporation) Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) (Version: 9.4.5000.00 - Microsoft Corporation) Microsoft SQL Server Native Client (Version: 9.00.5000.00 - Microsoft Corporation) Microsoft SQL Server VSS Writer (Version: 9.00.5000.00 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Move Media Player (Version: - Move Networks) Mozilla Firefox 26.0 (x86 de) (Version: 26.0 - Mozilla) Mozilla Maintenance Service (Version: 26.0 - Mozilla) MSVCRT (Version: 15.4.2862.0708 - Microsoft) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation) Music Transfer (Version: 1.2.00.17290 - Sony Corporation) Nestea Everest Screen Saver (Version: - ) Nokia Connectivity Cable Driver (Version: 7.1.20.0 - Nokia) NTI CD & DVD-Maker (Version: 6.5 - NewTech Infosystems) NTI CD & DVD-Maker 6.5 Gold (Version: 6.5 - NewTech Infosystems) OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0 - Microsoft Corporation) OpenMG Secure Module 5.1.00 (Version: 5.1.00.05200 - Sony Corporation) PC Connectivity Solution (Version: 9.39.0.0 - Nokia) Picasa 2 (Version: 2.0 - Google, Inc.) Primo (Version: 1.00.0000 - Your Company Name) QuickTime (Version: 7.74.80.86 - Apple Inc.) RealPlayer (Version: - RealNetworks) Realtek High Definition Audio Driver (Version: 6.0.1.5653 - Realtek Semiconductor Corp.) RedMon - Redirection Port Monitor (Version: - ) Roxio Central Audio (Version: 3.7.0 - Roxio) Roxio Central Copy (Version: 3.7.0 - Roxio) Roxio Central Core (Version: 3.7.0 - Roxio) Roxio Central Data (Version: 3.7.0 - Roxio) Roxio Central Tools (Version: 3.7.0 - Roxio) Roxio Easy Media Creator 10 LJ (Version: 10.1 - Roxio) Roxio Easy Media Creator Home (Version: 10.1.296 - Roxio) Samsung Kies (Version: 2.5.1.12123_2 - Samsung Electronics Co., Ltd.) SAMSUNG Mobile Composite Device Software (Version: - ) Samsung Mobile Modem Device Software (Version: - ) SAMSUNG Mobile Modem Driver Set (Version: - ) Samsung Mobile phone USB driver Software (Version: - ) SAMSUNG Mobile USB Modem 1.0 Software (Version: - ) SAMSUNG Mobile USB Modem Software (Version: - ) Samsung New PC Studio (Version: 1.00.0000 - Samsung Electronics Co., Ltd.) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.16.0 - SAMSUNG Electronics Co., Ltd.) SAMSUNG USB Mobile Device Software (Version: - ) SamsungConnectivityCableDriver (Version: 6.83.6.2.1 - Samsung) Scan (Version: 8.1.0.0 - Hewlett-Packard) Segoe UI (Version: 15.4.2271.0615 - Microsoft Corp) Setting Utility Series (Version: 4.2.0.10150 - Sony Corporation) Skins (Version: 2008.0717.2343.40629 - ATI) Skype™ 6.11 (Version: 6.11.102 - Skype Technologies S.A.) Software Info for Me&My VAIO (Version: 1.0.0.09110 - Sony Corporation) SolutionCenter (Version: 82.0.188.000 - Hewlett-Packard) Sony Ericsson PC Companion 2.02.002 (Version: 2.02.002 - Sony Ericsson) Sony Ericsson Update Engine (Version: 2.11.10.7 - Sony Ericsson Mobile Communications AB) Sony Picture Utility (Version: 3.3.01.09300 - Sony Corporation) Sony Video Shared Library (Version: 3.5.00 - Sony Corporation) Status (Version: 82.0.173.000 - Hewlett-Packard) steuern.lu.2008 nP 4.0 (Version: - Information Factory AG) steuern.lu.2009 nP 5.0 (Version: - Information Factory AG) steuern.lu.2010 nP 6.0 (Version: 6.0 - Information Factory AG) steuern.lu.2011 nP 7.0.1 (Version: 7.0.1 - Information Factory AG) steuern.lu.2012 nP 8.0 (Version: 8.0 - Information Factory AG) Synaptics Pointing Device Driver (Version: 9.1.13.0 - Synaptics) Toolbox (Version: 82.0.173.000 - Hewlett-Packard) TrayApp (Version: 82.0.188.000 - Hewlett-Packard) UltraStar 0.6.2 (Version: - ) UnloadSupport (Version: 1.00.0000 - Hewlett-Packard) Unterstützung für VAIO-Präsentation (Version: 1.1.0.08250 - Sony Corporation) Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (Version: 9.00.5000.00 - Microsoft Corporation) Update for 2007 Microsoft Office System (KB967642) (Version: - Microsoft) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3 - Microsoft Corporation) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (Version: - Microsoft) VAIO Content Folder Setting (Version: 2.1.0.08260 - Sony Corporation) VAIO Content Folder Watcher (Version: 1.0.01.09030 - Sony Corporation) VAIO Content Metadata Intelligent Analyzing Manager (Version: 3.2.00.06115 - Sony Corporation) VAIO Content Metadata Manager Setting (Version: 3.2.00.06062 - Sony Corporation) VAIO Content Metadata XML Interface Library (Version: 3.2.00.06112 - Sony Corporation) VAIO Control Center (Version: 3.2.0.09120 - Sony Corporation) VAIO Data Restore Tool (Version: 1.0.04.01170 - Sony Corporation) VAIO DVD Menu Data Basic (Version: 1.0.00.08130 - Sony Corporation) VAIO Energie Verwaltung (Version: 3.2.0.10060 - Sony Corporation) VAIO Entertainment Platform (Version: 3.2.3.10070 - Sony Corporation) VAIO Event Service (Version: 4.2.0.11060 - Sony Corporation) VAIO Launcher (Version: 2.2.0.09090 - Sony Corporation) VAIO Marketing Tools (Version: - Sony Corporation) VAIO Media plus (Version: 1.2.0.10230 - Sony Corporation) VAIO Media plus Opening Movie (Version: 1.2.0.09100 - Sony Corporation) VAIO Movie Story (Version: 1.3.01.08060 - Sony Corporation) VAIO Movie Story Template Data (Version: 1.3.00.06120 - Sony Corporation) VAIO MusicBox (Version: 2.1.1.09160 - Sony Corporation) VAIO MusicBox Sample Music (Version: 1.1.00.14140 - Sony Corporation) VAIO Original Function Setting (Version: 1.5.00.08150 - Sony Corporation) VAIO Smart Network (Version: 2.2.0.11050 - Sony Corporation) VAIO Update 4 (Version: 4.0.0.08280 - Sony Corporation) VAIO Wallpaper Contents (Version: 1.3.0.10310 - Sony Corporation) VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0 - DivX, Inc) Visual C++ 2008 x86 Runtime - (v9.0.30729) (Version: 9.0.30729 - Microsoft Corporation) Visual C++ 2008 x86 Runtime - v9.0.30729.01 (Version: 9.0.30729.01 - Microsoft Corporation) WebReg (Version: 82.0.173.000 - Hewlett-Packard) Windows Live Communications Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Essentials (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Essentials (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Windows Live Installer (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Photo Common (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live PIMT Platform (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live SOXE (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live SOXE Definitions (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live UX Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109 - Microsoft Corporation) Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0) (Version: 08/22/2008 7.0.0.0 - Nokia) WinDVD for VAIO (Version: 8.0-B9.602 - InterVideo Inc.) xp-AntiSpy 3.97-9 (Version: - Christian Taubenheim) ==================== Restore Points ========================= 22-11-2013 17:04:07 Geplanter Prüfpunkt 23-11-2013 08:08:05 Geplanter Prüfpunkt 24-11-2013 16:13:45 Geplanter Prüfpunkt 25-11-2013 16:22:42 Geplanter Prüfpunkt 27-11-2013 19:33:54 Geplanter Prüfpunkt 02-12-2013 20:00:51 Geplanter Prüfpunkt 05-12-2013 20:28:47 Geplanter Prüfpunkt 08-12-2013 20:45:21 Geplanter Prüfpunkt 09-12-2013 17:23:20 Geplanter Prüfpunkt 10-12-2013 20:31:11 Geplanter Prüfpunkt 12-12-2013 18:56:50 Geplanter Prüfpunkt 12-12-2013 18:58:33 Windows Update 16-12-2013 19:08:52 Geplanter Prüfpunkt 17-12-2013 18:21:15 Geplanter Prüfpunkt 22-12-2013 11:34:17 Geplanter Prüfpunkt 23-12-2013 19:47:57 Geplanter Prüfpunkt 24-12-2013 08:19:35 Geplanter Prüfpunkt 25-12-2013 22:19:10 Geplanter Prüfpunkt 26-12-2013 15:33:08 Gerätetreiber-Paketinstallation: Apple Netzwerkadapter ==================== Hosts content: ========================== 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {292472D7-5C57-4A7B-8756-C3182F944308} - System32\Tasks\SONY\VAIO Wallpaper Setting Tool\VAIO Wallpaper Setting Tool => C:\Program Files\sony\VAIO Wallpaper Setting Tool\VWSet.exe [2008-06-27] (Sony Corporation) Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {3E8A15CB-B8FE-453D-BCDE-6199DC002ABA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-07] (Google Inc.) Task: {415A322E-9312-4A23-8D5F-C3515A6C8B31} - System32\Tasks\SONY\VAIO Update\VAIO Update => C:\Program Files\sony\VAIO Update 4\VAIOUpdt.exe [2008-08-28] (Sony Corporation) Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {8879B9B2-AC2E-4364-A3F5-3003B5E5F859} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {8BDB90A4-BE1A-4580-B4A4-7D77E657454B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-07] (Google Inc.) Task: {9638A763-2266-4C8D-8813-30E1105D3618} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {A4DCE0E8-5B84-4B5B-BB72-37DE28A0A218} - System32\Tasks\SONY\Me&My VAIO\Me&My VAIO => C:\Program Files\Sony\Me&My VAIO\QLGuide.exe Task: {DB9473B2-B3B4-4F2E-AA68-15BD9A4B1C7D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-09-19] (Piriform Ltd) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] () Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2008-10-23 19:48 - 2008-10-07 02:47 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 01242952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-10-10 22:31 - 2013-10-10 22:31 - 01920512 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.UI\30692e977b98ee8676445954a1fd4275\Kies.UI.ni.dll 2013-08-14 23:22 - 2013-08-14 23:22 - 00078848 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.MVVM\73e3aae136f67d671daf3a36793777fc\Kies.MVVM.ni.dll 2013-08-14 23:22 - 2013-08-14 23:22 - 00184832 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\ae1c9ecb8ec8e593f51cbbe7979c7767\Kies.Common.DeviceServiceLib.Interface.ni.dll 2013-10-10 22:37 - 2013-10-10 22:37 - 00347648 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePhoto\0649849ea953692629ff06fb35daff11\DevicePhoto.ni.dll 2013-10-10 22:37 - 2013-10-10 22:37 - 00293888 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceVideo\0ade19d3962a554148e84631b24910ba\DeviceVideo.ni.dll 2013-10-10 22:37 - 2013-10-10 22:37 - 00615424 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePodcast\a6e186c248600b767efb4b728ed480f2\DevicePodcast.ni.dll 2013-08-14 23:23 - 2013-08-14 23:23 - 00307200 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DummyStorePlugin\5c4dbc3c1e024e1d417763383ccde01e\DummyStorePlugin.ni.dll 2013-08-14 23:23 - 2013-08-14 23:23 - 13033984 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Theme\1b83ce8db8f120b5e463846c0bf4ab0f\Kies.Theme.ni.dll 2013-10-10 22:31 - 2013-10-10 22:31 - 00571392 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\7263a97f5423c5667fa809c67da42edb\Kies.Common.DeviceServiceLib.FileService.ni.dll 2013-07-12 21:25 - 2013-07-12 21:25 - 00038912 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\84472d2ceeb937633639e4252adb85bb\Kies.Common.DeviceServiceLib.FirmwareUpdate.FirmwareUpdateAgentHelper.ni.dll 2013-08-14 23:22 - 2013-08-14 23:22 - 00232960 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ASF_cSharpAPI\6a4bcf254a32a7a34c46cad07a50bd0a\ASF_cSharpAPI.ni.dll 2008-12-04 05:32 - 2008-12-04 05:32 - 00014848 _____ () C:\Windows\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll 2008-08-26 11:41 - 2008-08-26 11:41 - 00016384 ____R () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll 2006-12-10 20:51 - 2006-12-10 20:51 - 00065536 ____R () C:\Program Files\HP\Digital Imaging\bin\crm\xmlparse.dll 2006-12-10 20:51 - 2006-12-10 20:51 - 00077824 ____R () C:\Program Files\HP\Digital Imaging\bin\crm\xmltok.dll 2013-12-05 21:02 - 2013-12-04 03:48 - 04055504 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-05 21:02 - 2013-12-04 03:48 - 00399312 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-05 21:01 - 2013-12-04 03:47 - 01619408 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll 2013-12-05 21:02 - 2013-12-04 03:48 - 13586896 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= Error: (05/30/2013 08:30:41 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error: (07/03/2009 01:34:52 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error: (06/26/2009 05:42:56 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 7 seconds with 0 seconds of active time. This session ended with a crash. Error: (06/26/2009 05:42:18 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 4 seconds with 0 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2013-12-30 10:02:42.110 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-30 10:02:41.915 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-30 10:02:41.717 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-30 10:02:41.519 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-30 10:02:41.322 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-30 10:02:41.129 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-30 10:02:40.931 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-30 10:02:40.731 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-30 09:45:28.907 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-30 09:45:28.673 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 50% Total physical RAM: 3038.13 MB Available physical RAM: 1495.4 MB Total Pagefile: 6285.24 MB Available Pagefile: 4541.75 MB Total Virtual: 2047.88 MB Available Virtual: 1899.46 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:288.23 GB) (Free:2.23 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive f: (Sims2EP8) (CDROM) (Total:0.98 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298 GB) (Disk ID: 6C9DCDDD) Partition 1: (Not Active) - (Size=10 GB) - (Type=27) Partition 2: (Active) - (Size=288 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
30.12.2013, 11:22 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | optimizer pro Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM) Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ --> optimizer pro |
31.12.2013, 14:24 | #7 |
| optimizer proCode:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.12.31.03 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 8.0.6001.19489 Sarah :: SARAH-PC [Administrator] Schutz: Aktiviert 31.12.2013 13:56:41 mbam-log-2013-12-31 (13-56-41).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 226165 Laufzeit: 13 Minute(n), 16 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Gruss Sarah |
31.12.2013, 16:27 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | optimizer pro Mach das erstmal ohne die nicht genutzten externen Datenträger.
__________________ Logfiles bitte immer in CODE-Tags posten |
01.01.2014, 10:36 | #9 |
| optimizer pro Ein gutes neues Jahr! Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=9ccae4b6e3a6b34e90fe0a81cff645f9 # engine=16463 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-01 09:15:06 # local_time=2014-01-01 10:15:06 (+0100, Mitteleuropäische Zeit) # country="Switzerland" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=1799 16775165 100 97 77028 253990996 69738 0 # compatibility_mode=5892 16776638 100 95 127795324 226100434 0 0 # scanned=271439 # found=1 # cleaned=0 # scan_time=60491 sh=A87B7647DC34B5B6186209377786E946B677C574 ft=1 fh=c2834f18f25710d9 vn="multiple threats" ac=I fn="C:\Users\Sarah\AppData\Local\Temp\{E954524A-244C-424C-9BDB-0CB366CE0201}\setup.exe" |
01.01.2014, 19:15 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | optimizer pro TFC - Temp File Cleaner Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
Sieht soweit ok aus Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat. Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie ) Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird. Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________ Logfiles bitte immer in CODE-Tags posten |
03.01.2014, 22:22 | #11 |
| optimizer pro Dann sollte es nun ok sein? Vielen Dank für die Hilfe!!! Liebe Grüsse Sarah |
04.01.2014, 12:48 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | optimizer pro Dann wären wir durch! Falls du noch Lob oder Kritik loswerden möchtest => Lob, Kritik und Wünsche - Trojaner-Board Die Programme, die hier zum Einsatz kamen, können alle deinstalliert werden. Helfen kann dir dabei delfix: Die Reihenfolge ist hier entscheidend.
Bitte abschließend noch die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden. Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern. Microsoftupdate Windows XP:Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren. Windows Vista/7: Start, Systemsteuerung, Windows-Update PDF-Reader aktualisieren Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast) Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader. Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers: Prüfen => Adobe - Flash Player Downloadlinks findest du hier => Browsers and Plugins - FilePony.de Alle Plugins im Firefox-Browser kannst du auch ganz einfach hier auf Aktualität prüfen => https://www.mozilla.org/de/plugincheck Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind. Java-Update Veraltete Java-Installationen sind ein großes Sicherheitsrisiko, daher solltest Du die alten Versionen deinstallieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software (bzw. Programme und Funktionen) und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu optimizer pro |
ad-aware, antivir, antivirus, avira, bonjour, branding, converter, desktop, device driver, email, error, excel, firefox, flash player, google, home, homepage, icloud, installation, mozilla, msiinstaller, officejet, optimizer pro, plug-in, realtek, registry, scan, security, server, software, svchost.exe, windows |