|
Log-Analyse und Auswertung: Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nichtWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
01.01.2014, 14:28 | #1 |
| Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht Hallo, ich habe folgendes Problem: Auf meinem Laptop ist der Bundestrojaner aufgetreten... Dieser ließ sich zuvor immer über den abgesicherten Modus beheben. Dies ist nun nicht möglich. Ich habe bereits einen Scan mit FRST erstellt und den Logfile auf meinen USB-Stick gezogen, jedoch kann ich damit nichts anfangen, weil ich nicht weiß was der Inhalt des Logfiles bedeutet. Bitte um Hilfe den Fix zu erstellen, MFG und danke im Voraus, SBK 22 PS: der Logfile wäre folgender Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-12-2013 01 Ran by SYSTEM on MININT-P010D68 on 01-01-2014 13:59:37 Running from F:\ Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9636896 2009-12-16] (Realtek Semiconductor) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [208384 2009-11-04] (Alps Electric Co., Ltd.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Java\jre6\bin\jusched.exe [171520 2009-01-01] (Sun Microsystems, Inc.) HKLM\...\Run: [Zune Launcher] - C:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation) HKLM\...\Run: [Allin1Convert Home Page Guard 64 bit] - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\AppIntegrator64.exe [548936 2013-09-21] () HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-11-20] (Intel Corporation) HKLM-x32\...\Run: [ISBMgr.exe] - C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe [320880 2009-08-26] (Sony Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-01-13] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [MarketingTools] - C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe [26624 2009-01-01] (Sony Corporation) HKLM-x32\...\Run: [SHTtray.exe] - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe [99696 2010-09-10] (Sony Corporation) HKLM-x32\...\Run: [RegUse] - C:\Program Files (x86)\RegUse\RegUse.exe HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254696 2011-06-09] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Blackcomb] - C:\Program Files (x86)\Samsung Connection Manager\ModemPnPService.exe [131072 2011-02-11] (Samsung Electronics.) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] () HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-02-18] (Apple Inc.) HKLM-x32\...\Run: [eBook Library Launcher] - C:\Program Files (x86)\SONY\Reader\Data\bin\launcher\eBook Library Launcher.exe [902440 2009-07-03] (Sony Corporation) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-26] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Allin1Convert Search Scope Monitor] - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hSrchMn.exe [44784 2013-09-21] (MindSpark) HKLM-x32\...\Run: [Allin1Convert_8h Browser Plugin Loader] - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbrmon.exe [30096 2013-09-21] (VER_COMPANY_NAME) HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1673680 2013-10-23] (APN) HKLM-x32\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Users\Thomas\AppData\Roaming\appConf32.exe,C:\Users\Thomas\AppData\Roaming\jabconf32.exe, [x] Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\Thomas\...\Run: [msnmsgr] - "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background HKU\Thomas\...\Run: [ICQ] - "C:\Program Files (x86)\ICQ7.4\ICQ.exe" silent loginmode=4 HKU\Thomas\...\Run: [Facebook Update] - C:\Users\Thomas\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-22] (Facebook Inc.) Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> (No File) Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qdawlfb.lnk ShortcutTarget: qdawlfb.lnk -> C:\ProgramData\bflwadq.dss (Корпорация Майкрософт) ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) S2 Allin1Convert_8hService; C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbarsvc.exe [42504 2013-09-21] (COMPANYVERS_NAME) S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-26] (Avira Operations GmbH & Co. KG) S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-26] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-11-26] (Avira Operations GmbH & Co. KG) S2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.) S2 bufssvr; C:\Program Files (x86)\BUFFALO\SLManagerEasy\Bufssvr.exe [90112 2010-03-12] (BUFFALO INC.) S3 Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [313840 2009-08-31] (Sonic Solutions) S2 Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [362992 2009-08-31] (Sonic Solutions) S2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) S2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [74496 2010-09-27] (Sony Corporation) S2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [864000 2010-09-27] (Sony Corporation) S3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1286784 2012-10-26] (Sony Corporation) S2 Winmgmt; C:\ProgramData\qdawlfb.pss [60528 2013-11-26] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S2 6077757b; C:\Windows\system32\drivers\regi.sys [14112 2007-04-17] (InterVideo) S3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [106904 2013-11-26] (Avira Operations GmbH & Co. KG) S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-11-26] (Avira Operations GmbH & Co. KG) S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG) S3 C2XXCOM; C:\Windows\System32\DRIVERS\C2XXCOM76.sys [49920 2010-08-09] (Samsung Electronics) S3 C2xxUSB; C:\Windows\System32\DRIVERS\C2xxUSB76.sys [46080 2010-11-04] (Samsung Electronics) S3 C2xxUsbStorage; C:\Windows\System32\DRIVERS\C2xSTR76.sys [9216 2010-06-10] (Samsung Electronics) S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [28416 2008-04-16] (Research In Motion Limited) S3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-11-12] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-01 13:59 - 2014-01-01 13:59 - 00000000 ____D C:\FRST ==================== One Month Modified Files and Folders ======= 2014-01-01 13:59 - 2014-01-01 13:59 - 00000000 ____D C:\FRST 2014-01-01 13:47 - 2013-11-26 10:57 - 95025368 ____T C:\ProgramData\qdawlfb.bxx 2014-01-01 13:44 - 2013-08-20 09:12 - 00000000 ___RD C:\Users\Thomas\Dropbox 2014-01-01 13:44 - 2013-08-20 09:10 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Dropbox 2014-01-01 13:43 - 2013-11-26 10:57 - 00000000 _____ C:\ProgramData\qdawlfb.fvv 2014-01-01 13:43 - 2009-01-01 18:26 - 00156010 _____ C:\Windows\setupact.log 2014-01-01 13:42 - 2009-01-01 03:00 - 00686992 _____ C:\Windows\PFRO.log Files to move or delete: ==================== C:\ProgramData\00etadpu.pad C:\ProgramData\6447463.pad C:\ProgramData\bflwadq.dss C:\ProgramData\dsgsdgdsgdsgw.pad C:\ProgramData\qdawlfb.bxx C:\ProgramData\qdawlfb.fdd C:\ProgramData\qdawlfb.fvv C:\ProgramData\qdawlfb.pss C:\ProgramData\qdawlfb.reg Some content of TEMP: ==================== C:\Users\Thomas\AppData\Local\Temp\0a50e25a83046228c11dcaa7eeed09bb.exe C:\Users\Thomas\AppData\Local\Temp\AskSLib.dll C:\Users\Thomas\AppData\Local\Temp\avgnt.exe C:\Users\Thomas\AppData\Local\Temp\BI_RunOnce.exe C:\Users\Thomas\AppData\Local\Temp\bundlesweetimsetup.exe C:\Users\Thomas\AppData\Local\Temp\Dvff.dll C:\Users\Thomas\AppData\Local\Temp\eTypeSetup.exe C:\Users\Thomas\AppData\Local\Temp\FileSystemView.dll C:\Users\Thomas\AppData\Local\Temp\ICReinstall_CodecPackage.exe C:\Users\Thomas\AppData\Local\Temp\IminentSetup.exe C:\Users\Thomas\AppData\Local\Temp\incredibar_installer.exe C:\Users\Thomas\AppData\Local\Temp\Installer.exe C:\Users\Thomas\AppData\Local\Temp\installhelper.dll C:\Users\Thomas\AppData\Local\Temp\jre-6u23-windows-i586-iftw-rv.exe C:\Users\Thomas\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe C:\Users\Thomas\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe C:\Users\Thomas\AppData\Local\Temp\jre-6u30-windows-i586-iftw-rv.exe C:\Users\Thomas\AppData\Local\Temp\jre-6u38-windows-i586-iftw.exe C:\Users\Thomas\AppData\Local\Temp\k-lite-mega-codec-pack.exe C:\Users\Thomas\AppData\Local\Temp\minibar-master-v1.exe C:\Users\Thomas\AppData\Local\Temp\MyBabylonTB_google_20120807.exe C:\Users\Thomas\AppData\Local\Temp\nsg7F6E.tmp.tbFLV_.dll C:\Users\Thomas\AppData\Local\Temp\nsh22ED.tmp.tbFLV_.dll C:\Users\Thomas\AppData\Local\Temp\ose00000.exe C:\Users\Thomas\AppData\Local\Temp\SkypeSetup.exe C:\Users\Thomas\AppData\Local\Temp\TB_89C6.exe C:\Users\Thomas\AppData\Local\Temp\uninst1.exe C:\Users\Thomas\AppData\Local\Temp\UpdateCheckerSetup.exe C:\Users\Thomas\AppData\Local\Temp\xvstnmnutprdljmakoi.bfg ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2013-09-25 09:39:02 Restore point made on: 2013-09-28 10:12:36 Restore point made on: 2013-10-02 13:49:41 Restore point made on: 2013-10-07 19:40:39 Restore point made on: 2013-10-09 21:08:38 Restore point made on: 2013-10-11 11:19:54 Restore point made on: 2013-10-12 14:51:25 Restore point made on: 2013-10-19 18:36:55 Restore point made on: 2013-10-22 19:07:31 Restore point made on: 2013-10-22 20:55:52 Restore point made on: 2013-10-26 09:18:46 Restore point made on: 2013-10-30 13:47:39 Restore point made on: 2013-11-02 16:27:54 Restore point made on: 2013-11-02 17:56:20 Restore point made on: 2013-11-05 17:50:01 Restore point made on: 2013-11-13 11:52:20 Restore point made on: 2013-11-13 14:24:14 Restore point made on: 2013-11-18 16:10:30 Restore point made on: 2013-11-22 21:11:12 Restore point made on: 2013-11-26 10:12:36 ==================== Memory info =========================== Percentage of memory in use: 17% Total physical RAM: 3950.1 MB Available physical RAM: 3268.56 MB Total Pagefile: 3948.25 MB Available Pagefile: 3305.27 MB Total Virtual: 8192 MB Available Virtual: 8191.87 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:456.37 GB) (Free:363.82 GB) NTFS Drive e: (Recovery) (Fixed) (Total:9.29 GB) (Free:0.72 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (19 Aug 2013) (CDROM) (Total:4.38 GB) (Free:3.23 GB) UDF Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 369480EA) Partition 1: (Not Active) - (Size=9 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=456 GB) - (Type=07 NTFS) LastRegBack: 2013-08-21 23:19 ==================== End Of Log ============================ |
01.01.2014, 14:45 | #2 |
/// TB-Ausbilder | Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht Hi,
__________________startet der Rechner nach diesem Fix wieder normal? Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKLM-x32\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Users\Thomas\AppData\Roaming\appConf32.exe,C:\Users\Thomas\AppData\Roaming\jabconf32.exe, [x] Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qdawlfb.lnk ShortcutTarget: qdawlfb.lnk -> C:\ProgramData\bflwadq.dss (Корпорация Майкрософт) S2 Winmgmt; C:\ProgramData\qdawlfb.pss [60528 2013-11-26] (Microsoft Corporation) C:\ProgramData\00etadpu.pad C:\ProgramData\6447463.pad C:\ProgramData\bflwadq.dss C:\ProgramData\dsgsdgdsgdsgw.pad C:\ProgramData\qdawlfb.bxx C:\ProgramData\qdawlfb.fdd C:\ProgramData\qdawlfb.fvv C:\ProgramData\qdawlfb.pss C:\ProgramData\qdawlfb.reg C:\Users\Thomas\AppData\Local\Temp\*.dll C:\Users\Thomas\AppData\Local\Temp\*.exe C:\Users\Thomas\AppData\Local\Temp\xvstnmnutprdljmakoi.bfg
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.
__________________ |
01.01.2014, 15:30 | #3 |
| Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht ich kann die fixlist nicht speichern ohne das Dateien verloren gehen...
__________________es erscheint, dass Informationen verloren gehen, wenn er es im ANSI-Format schreibt und ich in den Unicode-Optionen eine"Codierung" auswählen soll... kannst du damit was anfangen? oder ist das für den fix uninteressant Code:
ATTFilter HKLM-x32\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Users\Thomas\AppData\Roaming\appConf32.exe,C:\Users\Thomas\AppData\Roaming\jabconf32.exe, [x] Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qdawlfb.lnk ShortcutTarget: qdawlfb.lnk -> C:\ProgramData\bflwadq.dss (?????????? ??????????) S2 Winmgmt; C:\ProgramData\qdawlfb.pss [60528 2013-11-26] (Microsoft Corporation) C:\ProgramData\00etadpu.pad C:\ProgramData\6447463.pad C:\ProgramData\bflwadq.dss C:\ProgramData\dsgsdgdsgdsgw.pad C:\ProgramData\qdawlfb.bxx C:\ProgramData\qdawlfb.fdd C:\ProgramData\qdawlfb.fvv C:\ProgramData\qdawlfb.pss C:\ProgramData\qdawlfb.reg C:\Users\Thomas\AppData\Local\Temp\*.dll C:\Users\Thomas\AppData\Local\Temp\*.exe C:\Users\Thomas\AppData\Local\Temp\xvstnmnutprdljmakoi.bfg |
01.01.2014, 15:41 | #4 |
/// TB-Ausbilder | Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht Also wie ich das sehe, gehen nur die kyrillischen Zeichen verloren und werden durch ??? ersetzt, ist das korrekt? Das wäre total egal, du kannst die fixlist.txt trotzdem so verwenden und es wird funktionieren.
__________________ cheers, Leo |
01.01.2014, 16:06 | #5 |
| Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht ok, super, dachte nur das könnte zu Problemen führen. der erstellte fixlog Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-12-2013 01 Ran by SYSTEM at 2014-01-01 16:04:56 Run:1 Running from F:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** HKLM-x32\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Users\Thomas\AppData\Roaming\appConf32.exe,C:\Users\Thomas\AppData\Roaming\jabconf32.exe, [x] Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qdawlfb.lnk ShortcutTarget: qdawlfb.lnk -> C:\ProgramData\bflwadq.dss (?????????? ??????????) S2 Winmgmt; C:\ProgramData\qdawlfb.pss [60528 2013-11-26] (Microsoft Corporation) C:\ProgramData\00etadpu.pad C:\ProgramData\6447463.pad C:\ProgramData\bflwadq.dss C:\ProgramData\dsgsdgdsgdsgw.pad C:\ProgramData\qdawlfb.bxx C:\ProgramData\qdawlfb.fdd C:\ProgramData\qdawlfb.fvv C:\ProgramData\qdawlfb.pss C:\ProgramData\qdawlfb.reg C:\Users\Thomas\AppData\Local\Temp\*.dll C:\Users\Thomas\AppData\Local\Temp\*.exe C:\Users\Thomas\AppData\Local\Temp\xvstnmnutprdljmakoi.bfg ***************** HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => Value was restored successfully. C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qdawlfb.lnk => Moved successfully. C:\ProgramData\bflwadq.dss => Moved successfully. Winmgmt => Service restored successfully. C:\ProgramData\00etadpu.pad => Moved successfully. C:\ProgramData\6447463.pad => Moved successfully. "C:\ProgramData\bflwadq.dss" => File/Directory not found. C:\ProgramData\dsgsdgdsgdsgw.pad => Moved successfully. C:\ProgramData\qdawlfb.bxx => Moved successfully. C:\ProgramData\qdawlfb.fdd => Moved successfully. C:\ProgramData\qdawlfb.fvv => Moved successfully. C:\ProgramData\qdawlfb.pss => Moved successfully. C:\ProgramData\qdawlfb.reg => Moved successfully. C:\Users\Thomas\AppData\Local\Temp\*.dll => Moved successfully. C:\Users\Thomas\AppData\Local\Temp\*.exe => Moved successfully. C:\Users\Thomas\AppData\Local\Temp\xvstnmnutprdljmakoi.bfg => Moved successfully. ==== End of Fixlog ==== |
01.01.2014, 20:50 | #6 |
/// TB-Ausbilder | Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht Sehr gut. Dann verschiebe die frst64.exe vom USB-Stick auf den Desktop.
__________________ --> Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht |
02.01.2014, 10:34 | #7 |
| Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht so, die beiden logfiles FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-01-2014 01 Ran by Thomas (administrator) on THOMAS-VAIO on 02-01-2014 10:29:42 Running from C:\Users\Thomas\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (COMPANYVERS_NAME) C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbarsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (BUFFALO INC.) C:\Program Files (x86)\BUFFALO\SLManagerEasy\Bufssvr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (BUFFALO INC.) C:\Program Files (x86)\BUFFALO\SLManagerEasy\Inputps.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (AMD) C:\Windows\System32\atieclxx.exe (Sony Corporation) C:\Program Files (x86)\SONY\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe (Microsoft Corporation) C:\Program Files\Zune\ZuneLauncher.exe () C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\AppIntegrator64.exe (Facebook Inc.) C:\Users\Thomas\AppData\Local\Facebook\Update\FacebookUpdate.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Dropbox, Inc.) C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Sony Corporation) C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Sony Corporation) C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe (Samsung Electronics.) C:\Program Files (x86)\Samsung Connection Manager\ModemPnPService.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Sony Corporation) C:\Program Files (x86)\SONY\Reader\Data\bin\launcher\eBook Library Launcher.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (VER_COMPANY_NAME) C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbrmon.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9636896 2009-12-16] (Realtek Semiconductor) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [208384 2009-11-04] (Alps Electric Co., Ltd.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Java\jre6\bin\jusched.exe [171520 2009-01-01] (Sun Microsystems, Inc.) HKLM\...\Run: [Zune Launcher] - C:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation) HKLM\...\Run: [Allin1Convert Home Page Guard 64 bit] - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\AppIntegrator64.exe [548936 2013-09-21] () HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-11-20] (Intel Corporation) HKLM-x32\...\Run: [ISBMgr.exe] - C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe [320880 2009-08-26] (Sony Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-01-13] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [MarketingTools] - C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe [26624 2009-01-01] (Sony Corporation) HKLM-x32\...\Run: [SHTtray.exe] - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe [99696 2010-09-10] (Sony Corporation) HKLM-x32\...\Run: [RegUse] - C:\Program Files (x86)\RegUse\RegUse.exe HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254696 2011-06-09] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Blackcomb] - C:\Program Files (x86)\Samsung Connection Manager\ModemPnPService.exe [131072 2011-02-11] (Samsung Electronics.) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] () HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-02-18] (Apple Inc.) HKLM-x32\...\Run: [eBook Library Launcher] - C:\Program Files (x86)\SONY\Reader\Data\bin\launcher\eBook Library Launcher.exe [902440 2009-07-03] (Sony Corporation) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2014-01-01] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Allin1Convert Search Scope Monitor] - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hSrchMn.exe [44784 2013-09-21] (MindSpark) HKLM-x32\...\Run: [Allin1Convert_8h Browser Plugin Loader] - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbrmon.exe [30096 2013-09-21] (VER_COMPANY_NAME) HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1673680 2013-10-23] (APN) HKLM-x32\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Users\Thomas\AppData\Roaming\appConf32.exe,C:\Users\Thomas\AppData\Roaming\jabconf32.exe, [x] Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [msnmsgr] - "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background HKCU\...\Run: [ICQ] - "C:\Program Files (x86)\ICQ7.4\ICQ.exe" silent loginmode=4 HKCU\...\Run: [Facebook Update] - C:\Users\Thomas\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-22] (Facebook Inc.) MountPoints2: {8b6f7920-69ef-11e1-8cd8-506313e09590} - G:\Windows\CHECK\DriveNavigator.exe MountPoints2: {cb89c71b-7c0e-11e1-ae19-506313e09590} - G:\AutoInstaller.exe MountPoints2: {cb89c721-7c0e-11e1-ae19-506313e09590} - G:\AutoInstaller.exe Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SVEC&bmod=EU01 HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd URLSearchHook: HKLM-x32 - FLV Runner Toolbar - {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV2.dll (Conduit Ltd.) URLSearchHook: HKCU - (No Name) - {5bcf818d-78c8-41b8-ba89-65c5fdac4fc4} - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll (MindSpark) SearchScopes: HKLM-x32 - DefaultScope {14F59211-E81D-41E0-95DB-6528D5AF51C9} URL = SearchScopes: HKLM-x32 - {75b4241f-171e-44a3-bf44-23613b6e3e03} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^AYY^xdm070^YYA^de&si=flvrunner&ptb=790C2CC8-A335-48AA-AEB3-118EC7308978&ind=2013092113&n=77fd5911&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {75b4241f-171e-44a3-bf44-23613b6e3e03} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^AYY^xdm070^YYA^de&si=flvrunner&ptb=790C2CC8-A335-48AA-AEB3-118EC7308978&ind=2013092113&n=77fd5911&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± vË°!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL = BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: FLV Runner Toolbar - {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV2.dll (Conduit Ltd.) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Search Assistant BHO - {a4c2fb10-84c3-44eb-9f9e-860fa1d9a797} - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll (MindSpark) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Toolbar BHO - {fbcbc43a-dca9-4192-a4c8-b57fd0f77d4d} - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbar.dll (MindSpark) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - No Name - {DFEFCDEE-CF1A-4FC8-89AF-189327213627} - No File Toolbar: HKLM-x32 - FLV Runner Toolbar - {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV2.dll (Conduit Ltd.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Toolbar: HKLM-x32 - Allin1Convert - {cd1a63ba-a08c-431b-9a34-f240aadc728d} - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbar.dll (MindSpark) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - No Name - {3BBD3C14-4C16-4989-8366-95BC9179779D} - No File DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL No File Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}: [NameServer]192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default FF SelectedSearchEngine: Hola Search FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF Plugin-x32: @Allin1Convert_8h.com/Plugin - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\NP8hStub.dll (MindSpark) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @sony.com/eBookLibrary - C:\Program Files (x86)\Sony\Reader\Data\bin\npebldetectmoz.dll (Sony Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Thomas\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF SearchPlugin: C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\searchplugins\holasearch.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\StartWeb.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: VideoDownloadConverter - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\Extensions\4zffxtbr-bs@VideoDownloadConverter_4z.com FF Extension: Allin1Convert - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\Extensions\8hffxtbr@Allin1Convert_8h.com FF Extension: HolaSearch - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\Extensions\ffxtlbr@holasearch.com FF Extension: Iminent - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\Extensions\webbooster@iminent.com.xpi FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF HKLM-x32\...\Firefox\Extensions: [8hffxtbr@Allin1Convert_8h.com] - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin FF Extension: Allin1Convert - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx CHR HKLM-x32\...\Chrome\Extension: [igdhbblpcellaljokkpfhcjlagemhgjl] - C:\Program Files (x86)\Iminent\Iminent.crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 Allin1Convert_8hService; C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbarsvc.exe [42504 2013-09-21] (COMPANYVERS_NAME) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2014-01-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-26] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2014-01-01] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.) R2 bufssvr; C:\Program Files (x86)\BUFFALO\SLManagerEasy\Bufssvr.exe [90112 2010-03-12] (BUFFALO INC.) S3 Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [313840 2009-08-31] (Sonic Solutions) S2 Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [362992 2009-08-31] (Sonic Solutions) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [74496 2010-09-27] (Sony Corporation) R2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [864000 2010-09-27] (Sony Corporation) S3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1286784 2012-10-26] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R2 6077757b; C:\Windows\system32\drivers\regi.sys [14112 2007-04-17] (InterVideo) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-01-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-01-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG) S3 C2XXCOM; C:\Windows\System32\DRIVERS\C2XXCOM76.sys [49920 2010-08-09] (Samsung Electronics) S3 C2xxUSB; C:\Windows\System32\DRIVERS\C2xxUSB76.sys [46080 2010-11-04] (Samsung Electronics) S3 C2xxUsbStorage; C:\Windows\System32\DRIVERS\C2xSTR76.sys [9216 2010-06-10] (Samsung Electronics) S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [28416 2008-04-16] (Research In Motion Limited) R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-11-12] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-02 10:29 - 2014-01-02 10:30 - 00022213 _____ C:\Users\Thomas\Desktop\FRST.txt 2014-01-02 10:27 - 2014-01-02 10:29 - 01931426 _____ (Farbar) C:\Users\Thomas\Desktop\FRST64.exe 2014-01-02 10:27 - 2014-01-02 10:27 - 00000286 ____H C:\Windows\Tasks\User_Feed_Synchronization-{D30B1914-6D71-46E4-813A-B2B3835BF810}.job 2014-01-02 03:09 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2014-01-02 03:04 - 2014-01-02 03:04 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-01-02 03:04 - 2014-01-02 03:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-02 03:04 - 2014-01-02 03:04 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-02 03:04 - 2014-01-02 03:04 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-01-02 03:04 - 2014-01-02 03:04 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-01-01 16:17 - 2014-01-02 03:09 - 00017589 _____ C:\Windows\IE11_main.log 2014-01-01 13:59 - 2014-01-02 10:29 - 00000000 ____D C:\FRST ==================== One Month Modified Files and Folders ======= 2014-01-02 10:30 - 2014-01-02 10:29 - 00022213 _____ C:\Users\Thomas\Desktop\FRST.txt 2014-01-02 10:29 - 2014-01-02 10:27 - 01931426 _____ (Farbar) C:\Users\Thomas\Desktop\FRST64.exe 2014-01-02 10:29 - 2014-01-01 13:59 - 00000000 ____D C:\FRST 2014-01-02 10:29 - 2009-07-14 06:13 - 01507406 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-02 10:29 - 2009-01-01 03:02 - 01310893 _____ C:\Windows\WindowsUpdate.log 2014-01-02 10:29 - 2009-01-01 02:56 - 00657910 _____ C:\Windows\system32\perfh007.dat 2014-01-02 10:29 - 2009-01-01 02:56 - 00131250 _____ C:\Windows\system32\perfc007.dat 2014-01-02 10:27 - 2014-01-02 10:27 - 00000286 ____H C:\Windows\Tasks\User_Feed_Synchronization-{D30B1914-6D71-46E4-813A-B2B3835BF810}.job 2014-01-02 10:27 - 2013-08-20 09:12 - 00000000 ___RD C:\Users\Thomas\Dropbox 2014-01-02 10:27 - 2013-08-20 09:10 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Dropbox 2014-01-02 03:34 - 2009-07-14 05:45 - 00013936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-02 03:34 - 2009-07-14 05:45 - 00013936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-02 03:30 - 2011-01-28 20:04 - 00001421 _____ C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-02 03:26 - 2009-01-01 18:26 - 00156122 _____ C:\Windows\setupact.log 2014-01-02 03:24 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2014-01-02 03:09 - 2014-01-01 16:17 - 00017589 _____ C:\Windows\IE11_main.log 2014-01-02 03:04 - 2014-01-02 03:04 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-01-02 03:04 - 2014-01-02 03:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-02 03:04 - 2014-01-02 03:04 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-02 03:04 - 2014-01-02 03:04 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-01-02 03:04 - 2014-01-02 03:04 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-01-02 03:02 - 2011-03-16 08:41 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-01-01 16:25 - 2013-08-21 11:33 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-01-01 16:25 - 2013-08-21 11:28 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-01-01 16:25 - 2013-08-21 11:28 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-01-01 16:04 - 2011-01-28 20:04 - 00000000 ___RD C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-01 13:42 - 2009-01-01 03:00 - 00686992 _____ C:\Windows\PFRO.log Some content of TEMP: ==================== C:\Users\Thomas\AppData\Local\Temp\avgnt.exe C:\Users\Thomas\AppData\Local\Temp\k-lite-mega-codec-pack.exe C:\Users\Thomas\AppData\Local\Temp\{E62D6E10-6436-4FDB-BF6A-A825C4133D61}-GoogleUpdateSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-21 23:19 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-01-2014 01 Ran by Thomas at 2014-01-02 10:32:28 Running from C:\Users\Thomas\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (x32 Version: - Microsoft) 7-Zip 9.20 (x32 Version: - ) Adobe Flash Player 10 Plugin (x32 Version: 10.3.183.7 - Adobe Systems Incorporated) Adobe Flash Player 11 ActiveX 64-bit (Version: 11.1.102.55 - Adobe Systems Incorporated) Adobe Reader 9.5.0 - Deutsch (x32 Version: 9.5.0 - Adobe Systems Incorporated) Adobe SVG Viewer 3.0 (x32 Version: 3.0 - ) Allin1Convert Firefox Toolbar (x32 Version: - Mindspark Interactive Network) Allin1Convert Internet Explorer Toolbar (x32 Version: - Mindspark Interactive Network) Alps Pointing-device for VAIO (Version: - ALPS ELECTRIC CO., LTD.) Apple Application Support (x32 Version: 2.3.3 - Apple Inc.) Apple Mobile Device Support (Version: 6.1.0.13 - Apple Inc.) Apple Software Update (x32 Version: 2.1.3.127 - Apple Inc.) ArcSoft Magic-i Visual Effects 2 (x32 Version: 2.0.1.85 - ArcSoft) ArcSoft WebCam Companion 3 (x32 Version: 3.0.21.390 - ArcSoft) ATI Catalyst Install Manager (Version: 3.0.750.0 - ATI Technologies, Inc.) Avira Free Antivirus (x32 Version: 14.0.2.286 - Avira) Avira SearchFree Toolbar (x32 Version: 12.6.0.1900 - APN, LLC) Bonjour (Version: 3.0.0.10 - Apple Inc.) BUFFALO SecureLockManagerEasy for HD (x32 Version: - ) calibre (x32 Version: 1.9.0 - Kovid Goyal) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Core Implementation (x32 Version: 2010.0113.2257.41150 - ATI) Hidden Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0113.2257.41150 - ATI) Hidden Catalyst Control Center Graphics Full New (x32 Version: 2010.0113.2257.41150 - ATI) Hidden Catalyst Control Center Graphics Light (x32 Version: 2010.0113.2257.41150 - ATI) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0113.2257.41150 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0113.2257.41150 - ATI) Hidden Catalyst Control Center InstallProxy (x32 Version: 2010.0113.2257.41150 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2010.0113.2257.41150 - ATI) Hidden CCC Help Chinese Standard (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Chinese Traditional (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Czech (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Danish (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Dutch (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help English (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Finnish (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help French (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help German (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Greek (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Hungarian (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Italian (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Japanese (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Korean (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Norwegian (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Polish (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Portuguese (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Russian (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Spanish (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Swedish (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Thai (x32 Version: 2010.0113.2256.41150 - ATI) Hidden CCC Help Turkish (x32 Version: 2010.0113.2256.41150 - ATI) Hidden ccc-core-static (x32 Version: 2010.0113.2257.41150 - Ihr Firmenname) Hidden ccc-utility64 (Version: 2010.0113.2257.41150 - ATI) Hidden Corel WinDVD (x32 Version: 10.0.5.296 - Corel Inc.) DivX-Setup (x32 Version: 2.6.1.9 - DivX, LLC) Dropbox (HKCU Version: 2.0.26 - Dropbox, Inc.) eBook Library by Sony (x32 Version: 3.0.00.08040 - Sony) Einstellungen für VAIO-Inhaltsüberwachung (x32 Version: 2.6.0.11050 - Sony Corporation) Facebook Video Calling 1.2.0.287 (x32 Version: 1.2.287 - Skype Limited) FLV Runner Toolbar (x32 Version: 6.8.9.0 - FLV Runner) Free Audio CD Burner version 1.4.7 (x32 Version: - DVDVideoSoft Limited.) Free Studio version 5.1.7 (x32 Version: - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.9.35.324 (x32 Version: - DVDVideoSoft Limited.) Google Chrome (x32 Version: 3.0.195.21 - Google Inc.) Google Update Helper (x32 Version: 1.3.21.165 - Google Inc.) Hidden iCloud (Version: 2.1.1.3 - Apple Inc.) ICQ7.5 (x32 Version: 7.5 - ICQ) Iminent (x32 Version: 6.18.21.0 - Iminent) <==== ATTENTION Iminent (x32 Version: 6.18.21.0 - Iminent) Hidden <==== ATTENTION Intel(R) Control Center (x32 Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179 - Intel Corporation) Intel(R) Rapid Storage Technology (x32 Version: 9.5.4.1001 - Intel Corporation) Intel(R) Turbo Boost Technology Driver (x32 Version: 01.00.01.1002 - Intel Corporation) iTunes (Version: 11.0.2.25 - Apple Inc.) Java Auto Updater (x32 Version: 2.0.6.1 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 16 (64-bit) (Version: 6.0.160 - Sun Microsystems, Inc.) Java(TM) 6 Update 29 (x32 Version: 6.0.290 - Sun Microsystems, Inc.) Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden jZip (HKCU Version: 2.0.0.130920 - Bandoo Media Inc) Malwarebytes Anti-Malware Version 1.65.0.1400 (x32 Version: 1.65.0.1400 - Malwarebytes Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP1 English (x32 Version: 3.5.5692.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP1 x64 English (Version: 3.5.5692.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 11.0 (x86 de) (x32 Version: 11.0 - Mozilla) MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) MusicStation (x32 Version: 2.0.4.1199 - Omnifone) PMB VAIO Edition Guide (x32 Version: 1.0.00.09250 - Sony Corporation) PMB VAIO Edition Guide (x32 Version: 1.0.00.09250 - Sony Corporation) Hidden PMB VAIO Edition plug-in (Click to Disc) (x32 Version: 3.2.00.16060 - Sony Corporation) PMB VAIO Edition plug-in (Click to Disc) (x32 Version: 3.2.00.16060 - Sony Corporation) Hidden PMB VAIO Edition plug-in (VAIO Image Optimizer) (x32 Version: 1.0.00.10150 - Sony Corporation) PMB VAIO Edition plug-in (VAIO Image Optimizer) (x32 Version: 1.0.00.10150 - Sony Corporation) Hidden PMB VAIO Edition plug-in (VAIO Movie Story) (x32 Version: 2.2.00.15250 - Sony Corporation) PMB VAIO Edition plug-in (VAIO Movie Story) (x32 Version: 2.2.00.15250 - Sony Corporation) Hidden QuickTime (x32 Version: 7.73.80.64 - Apple Inc.) Realtek HDMI Audio Driver for ATI (x32 Version: 6.0.1.5992 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (x32 Version: 6.0.1.5992 - Realtek Semiconductor Corp.) Roxio Central Audio (x32 Version: 3.8.0 - Roxio) Hidden Roxio Central Copy (x32 Version: 3.8.0 - Roxio) Hidden Roxio Central Core (x32 Version: 3.8.0 - Roxio) Hidden Roxio Central Data (x32 Version: 3.8.0 - Roxio) Hidden Roxio Central Tools (x32 Version: 3.8.0 - Roxio) Hidden Roxio Easy Media Creator 10 LJ (x32 Version: 10.3 - Roxio) Roxio Easy Media Creator Home (x32 Version: 10.3.183 - Roxio) Hidden Safari (x32 Version: 5.34.57.2 - Apple Inc.) Samsung Connection Manager (x32 Version: 112 - Samsung Electronics) Setting Utility Series (x32 Version: 5.1.0.11200 - Sony Corporation) Setup_msm_VCMS_x64 (Version: 2.6.0.06040 - Sony Corporation) Hidden Setup_msm_VOFS_x64 (Version: 2.3.0.09270 - Sony Corporation) Hidden Setup_VEP_x64_Contain_SSDB (Version: 3.9.0.09270 - Sony Corporation) Hidden Skype Click to Call (x32 Version: 5.6.8442 - Skype Technologies S.A.) Skype™ 5.10 (x32 Version: 5.10.116 - Skype Technologies S.A.) SOHLib Merge Module (x32 Version: 2.2.0.11240 - Sony Corporation) Hidden Sony Home Network Library (x32 Version: 2.0.1.10160 - Sony Corporation) Hidden Sony Home Network Library (x32 Version: 2.2.0.11240 - Sony Corporation) toolplugin (x32 Version: - ) Uninstall 1.0.0.1 (x32 Version: - ) Update for 2007 Microsoft Office System (KB967642) (x32 Version: - Microsoft) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2825642) 32-Bit Edition (x32 Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (x32 Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (x32 Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32 Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (x32 Version: - Microsoft) Updater Service (x32 Version: 15,9,28,27 - ) <==== ATTENTION UseNeXT by Tangysoft (x32 Version: - Tangysoft Ltd.) VAIO Care (x32 Version: 6.4.2.11150 - Sony Corporation) Hidden VAIO Content Metadata Intelligent Analyzing Manager (Version: 3.9.0.11260 - Sony Corporation) VAIO Content Metadata Intelligent Analyzing Manager (x32 Version: 3.6.0.09250 - Sony Corporation) Hidden VAIO Content Metadata Intelligent Network Service Manager (Version: 3.9.0.11180 - Sony Corporation) VAIO Content Metadata Manager Settings (Version: 3.9.0.11180 - Sony Corporation) VAIO Content Metadata XML Interface Library (Version: 3.9.0.11180 - Sony Corporation) VAIO Control Center (x32 Version: 4.1.0.10160 - Sony Corporation) VAIO Data Restore Tool (x32 Version: 1.2.0.09150 - Sony Corporation) Hidden VAIO DVD Menu Data (x32 Version: 2.0.00.10130 - Sony Corporation) VAIO Energie Verwaltung (x32 Version: 5.0.0.11300 - Sony Corporation) VAIO Entertainment Platform (x32 Version: 3.9.0.11160 - Sony Corporation) VAIO Event Service (x32 Version: 5.1.0.12010 - Sony Corporation) VAIO Gate (x32 Version: 1.2.0.09240 - Sony Corporation) VAIO Gate Default (x32 Version: 1.0.0.10290 - Sony Corporation) VAIO Hardware Diagnostics (x32 Version: 3.9.1 - Sony Corporation) Hidden VAIO Marketing Tools (x32 Version: - Sony Corporation) VAIO Media plus (x32 Version: 2.0.1.10160 - Sony Corporation) VAIO Media plus Opening Movie (x32 Version: 1.2.0.09100 - Sony Corporation) VAIO Movie Story MergeModules x64 (Version: 1.0.14240 - Sony Corporation) Hidden VAIO Movie Story Template Data (x32 Version: 2.0.00.09240 - Sony Corporation) VAIO Movie Story Template Data (x32 Version: 2.0.00.09240 - Sony Corporation) Hidden VAIO Original Funktion Einstellungen (x32 Version: 2.3.0.11240 - Sony Corporation) VAIO Personalization Manager (Version: 3.0.0.11160 - Sony Corporation) VAIO Premium Partners (x32 Version: 1.0 - Sony Europe) VAIO Quick Web Access (x32 Version: 1.2.2.3 - Sony Corporation) VAIO Quick Web Access (x32 Version: 1.2.2.3 - Sony Corporation) Hidden VAIO screensaver (x32 Version: 1.0.0.0 - Sony Europe) VAIO Smart Network (x32 Version: 3.1.0.11250 - Sony Corporation) VAIO Update (x32 Version: 6.1.1.10250 - Sony Corporation) VAIO Wallpaper Contents (x32 Version: 2.0.0.06010 - Sony Corporation) VAIO-Support für Übertragungen (x32 Version: 1.1.2.06030 - Sony Corporation) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player 0.9.9 (x32 Version: 0.9.9 - VideoLAN Team) VU5x64 (Version: 1.1.0 - Sony Corporation ) Hidden VU5x86 (x32 Version: 1.0.0 - Sony Corporation ) Hidden VU5x86 (x32 Version: 1.1.0 - Sony Corporation ) Hidden WIDCOMM Bluetooth Software (Version: 6.2.1.500 - Broadcom Corporation) Windows Driver Package - Broadcom Bluetooth (09/09/2009 6.2.0.9405) (Version: 09/09/2009 6.2.0.9405 - Broadcom) Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (Version: 07/28/2009 6.2.0.9800 - Broadcom) Windows Live Anmelde-Assistent (x32 Version: 5.000.818.5 - Microsoft Corporation) Windows Live Call (x32 Version: 14.0.8064.0206 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 14.0.8064.206 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Windows Live Essentials (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 14.0.8093.805 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 14.0.8081.709 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Windows Live Sync (x32 Version: 14.0.8089.726 - Microsoft Corporation) Windows Live Writer (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Windows Live-Uploadtool (x32 Version: 14.0.8014.1029 - Microsoft Corporation) Windows Mobile Device Updater Component (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Windows Phone Intro Video (DEU) (x32 Version: 04.07.0975.00 - Microsoft Corporation) Hidden WinZip 16.0 (x32 Version: 16.0.9715 - WinZip Computing, S.L. ) Zune (Version: 04.08.2345.00 - Microsoft Corporation) Zune (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (CHS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (CHT) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (CSY) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (DAN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (DEU) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (ELL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (ESP) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (FIN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (FRA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (HUN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (IND) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (ITA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (JPN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (KOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (MSL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (NLD) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (NOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (PLK) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (PTB) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (PTG) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (RUS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (SVE) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden ==================== Restore Points ========================= 09-10-2013 20:08:23 Windows Update 11-10-2013 10:19:34 Windows Update 12-10-2013 13:51:02 Windows Update 19-10-2013 17:36:36 Windows Update 22-10-2013 18:07:08 Windows Update 22-10-2013 19:55:37 Windows Update 26-10-2013 08:18:26 Windows Update 30-10-2013 12:47:21 Windows Update 02-11-2013 15:27:26 Windows Update 02-11-2013 16:56:07 Installed calibre 05-11-2013 16:49:42 Windows Update 13-11-2013 10:52:03 Windows Update 13-11-2013 13:24:00 Windows Update 18-11-2013 15:10:10 Windows Update 22-11-2013 20:10:52 Windows Update 26-11-2013 09:12:14 Windows Update 01-01-2014 15:16:38 Windows Update 02-01-2014 02:00:23 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0D634B41-3D8C-417C-AF46-8877B4EBC848} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2012-10-26] (Sony Corporation) Task: {12E2C88D-5265-4EF3-BF19-1C88B6855752} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2012-10-26] (Sony Corporation) Task: {17115F43-92BD-4A6C-BB09-11A4B4B9E0F2} - System32\Tasks\SONY\VAIO Power Management\VPM Logon Start => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2009-11-30] (Sony Corporation) Task: {26CF50A5-0A3E-44C7-A1B6-C95644007C0F} - System32\Tasks\SONY\SUS-BCF\Level4Month => C:\Program Files (x86)\SONY\Setting Utility Series\WBCBatteryCare.exe [2009-11-20] (Sony Corporation) Task: {26D345C1-4E49-4757-8B9C-69C713EDDCF0} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation) Task: {279EFC06-34F1-460F-808A-5E1D2C64539A} - System32\Tasks\RegUse => C:\Program Files (x86)\RegUse\RegUse.exe Task: {29DF8B71-4CEC-48B6-A4A7-77DC85E12CAE} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION Task: {412ABB40-7002-4501-9E00-5C311EDB33A4} - System32\Tasks\SONY\SUS-BCF\Level4Daily => C:\Program Files (x86)\SONY\Setting Utility Series\WBCBatteryCare.exe [2009-11-20] (Sony Corporation) Task: {5E323F20-9468-4BD1-A12F-9805228ADC84} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation) Task: {63F24587-8EA8-4A4D-9701-8CB1A0EE5385} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-901852694-1798116289-1978641750-1000UA => C:\Users\Thomas\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-22] (Facebook Inc.) Task: {66DB33D0-82F4-49B5-9491-AB6214A97E17} - System32\Tasks\BrowserProtect => Sc.exe start BrowserProtect <==== ATTENTION Task: {6E54256F-573A-400B-BC1C-CC594BBE1237} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {6FC85711-96B4-4465-9464-60375F0CD58B} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-901852694-1798116289-1978641750-1000Core => C:\Users\Thomas\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-22] (Facebook Inc.) Task: {799C2BA9-1F93-4D7E-A010-FDA139F7ACA8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2009-01-01] (Google Inc.) Task: {8157DBF9-BE51-4DDC-AFA6-FC3D174AA42A} - System32\Tasks\Sony Corporation\VAIO Personalization Manager\VpmLM Task Music Thomas => C:\Program Files\Sony\VAIO Personalization Manager\VpmLM.exe [2010-11-05] (Sony Corporation) Task: {83F6C560-E461-4F03-BDE0-E55F7D4F8255} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {BE8EAA0E-B25A-4A40-A643-B2CC184C86CA} - System32\Tasks\EPUpdater => C:\Users\Thomas\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe <==== ATTENTION Task: {BFF72DE6-5A53-4347-B064-CECFB0C87D00} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2009-09-24] (Sony Corporation) Task: {C86D85FA-BE01-4E6D-9A56-E21F8371B881} - System32\Tasks\SONY\VAIO Power Management\VPM Session Change => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2009-11-30] (Sony Corporation) Task: {D032FB42-F20E-4F35-B96B-55FBB93BA1CF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2009-01-01] (Google Inc.) Task: {DB694396-3B7C-41B1-90A6-5AAD2EC78468} - System32\Tasks\PC Performer_DEFAULT => C:\Program Files (x86)\PC Performer\PCPerformer.exe <==== ATTENTION Task: {EC1A3A36-B589-45CB-9A88-42FCAC845447} - System32\Tasks\PC Performer_UPDATES => C:\Program Files (x86)\PC Performer\PCPerformer.exe <==== ATTENTION Task: {F7DBA22C-9363-41B7-BCFF-0A0844669278} - System32\Tasks\SONY\VAIO Power Management\VPM Unlock => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2009-11-30] (Sony Corporation) Task: {F9764432-8CD1-4ECA-B8F5-7FEBF3D292F6} - System32\Tasks\PC Performer => C:\Program Files (x86)\PC Performer\PCPerformer.exe <==== ATTENTION Task: {FDB7CD64-F907-4EB5-8288-750FA05D1467} - System32\Tasks\{AAE6E6C6-EA37-402C-BB93-0856669ACE4F} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2012-07-13] (Skype Technologies S.A.) Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-901852694-1798116289-1978641750-1000Core.job => C:\Users\Thomas\AppData\Local\Facebook\Update\FacebookUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-901852694-1798116289-1978641750-1000UA.job => C:\Users\Thomas\AppData\Local\Facebook\Update\FacebookUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cec509cef32515.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\PC Performer_DEFAULT.job => C:\Program Files (x86)\PC Performer\PCPerformer.exe <==== ATTENTION Task: C:\Windows\Tasks\PC Performer_UPDATES.job => C:\Program Files (x86)\PC Performer\PCPerformer.exe <==== ATTENTION Task: C:\Windows\Tasks\RegUse.job => C:\Program Files (x86)\RegUse\RegUse.exe <==== ATTENTION Task: C:\Windows\Tasks\User_Feed_Synchronization-{D30B1914-6D71-46E4-813A-B2B3835BF810}.job => C:\Windows\system32\msfeedssync.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2013-09-21 18:31 - 2013-09-21 18:31 - 00292424 _____ () C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\AppIntegratorStub64.dll 2013-09-21 18:31 - 2013-09-21 18:31 - 00442952 _____ () C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\HPG64.DLL 2008-08-26 11:41 - 2008-08-26 11:41 - 00016384 ____R () c:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2009-01-01 03:07 - 2009-01-01 03:07 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2013-08-21 11:28 - 2013-08-21 11:11 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2011-09-27 07:23 - 2011-09-27 07:23 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2011-09-27 07:22 - 2011-09-27 07:22 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2010-09-10 08:47 - 2010-09-10 08:47 - 00135168 _____ () C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\Extension\MrsMpegParser.dll 2009-01-01 03:20 - 2009-12-01 22:03 - 00010752 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESBasePS.dll 2009-01-01 03:20 - 2009-12-01 22:03 - 00009728 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSubPS.dll 2010-05-19 22:42 - 2009-11-20 23:19 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2013-03-13 21:48 - 2013-03-13 21:48 - 24978944 _____ () C:\Users\Thomas\AppData\Roaming\Dropbox\bin\libcef.dll 2011-07-29 00:09 - 2011-07-29 00:09 - 00096112 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2009-07-03 13:55 - 2009-07-03 13:55 - 00876544 _____ () C:\Program Files (x86)\SONY\Reader\Data\bin\launcher\fsk.dll 2009-06-25 15:38 - 2009-06-25 15:38 - 00806912 _____ () C:\Program Files (x86)\SONY\Reader\Data\bin\launcher\LIBEAY32.dll 2009-06-25 15:38 - 2009-06-25 15:38 - 00155648 _____ () C:\Program Files (x86)\SONY\Reader\Data\bin\launcher\SSLEAY32.dll 2009-07-03 13:57 - 2009-07-03 13:57 - 00010240 _____ () C:\Program Files (x86)\SONY\Reader\Data\bin\launcher\FskMobileMediaDevice.dll 2009-07-03 13:57 - 2009-07-03 13:57 - 00233472 _____ () C:\Program Files (x86)\SONY\Reader\Data\bin\launcher\Fskin.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: regi Description: regi Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: regi Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (01/02/2014 09:41:15 AM) (Source: Google Update) (User: Thomas-VAIO) Description: Network Request Error. Error: 0x80072ee7. Http status code: 0. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http s Error: (01/02/2014 06:41:15 AM) (Source: Google Update) (User: Thomas-VAIO) Description: Network Request Error. Error: 0x80072ee7. Http status code: 0. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http s Error: (01/02/2014 03:41:15 AM) (Source: Google Update) (User: Thomas-VAIO) Description: Network Request Error. Error: 0x80072ee7. Http status code: 0. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http s Error: (01/02/2014 03:30:33 AM) (Source: Google Update) (User: Thomas-VAIO) Description: Network Request Error. Error: 0x80072ee7. Http status code: 0. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http s Error: (01/01/2014 04:34:36 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15585 Error: (01/01/2014 04:34:36 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 15585 Error: (01/01/2014 04:34:36 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (01/01/2014 01:27:00 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: ACDaemon.exe, Version: 1.1.0.49, Zeitstempel: 0x4cc808ec Name des fehlerhaften Moduls: ACDaemon.exe, Version: 1.1.0.49, Zeitstempel: 0x4cc808ec Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001af76 ID des fehlerhaften Prozesses: 0x15b4 Startzeit der fehlerhaften Anwendung: 0xACDaemon.exe0 Pfad der fehlerhaften Anwendung: ACDaemon.exe1 Pfad des fehlerhaften Moduls: ACDaemon.exe2 Berichtskennung: ACDaemon.exe3 Error: (11/26/2013 10:05:38 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921 Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00001487 ID des fehlerhaften Prozesses: 0x10c0 Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0 Pfad der fehlerhaften Anwendung: avnotify.exe1 Pfad des fehlerhaften Moduls: avnotify.exe2 Berichtskennung: avnotify.exe3 Error: (11/24/2013 11:08:17 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921 Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00001487 ID des fehlerhaften Prozesses: 0x100c Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0 Pfad der fehlerhaften Anwendung: avnotify.exe1 Pfad des fehlerhaften Moduls: avnotify.exe2 Berichtskennung: avnotify.exe3 System errors: ============= Error: (01/02/2014 10:26:49 AM) (Source: NetBT) (User: ) Description: Der Name "THOMAS-VAIO :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.2.102 registriert werden. Der Computer mit IP-Adresse 192.168.2.100 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (01/02/2014 10:26:48 AM) (Source: NetBT) (User: ) Description: Der Name "THOMAS-VAIO :20" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.2.102 registriert werden. Der Computer mit IP-Adresse 192.168.2.100 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (01/02/2014 10:26:48 AM) (Source: Server) (User: ) Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error: (01/02/2014 03:34:42 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80242016 fehlgeschlagen: Kumulatives Sicherheitsupdate für Internet Explorer 10 unter Windows 7 Service Pack 1 für x64-basierte Systeme (KB2898785) Error: (01/02/2014 03:26:23 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Roxio Upnp Server 10 erreicht. Error: (01/02/2014 03:26:23 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "regi" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/01/2014 04:31:03 PM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (01/01/2014 04:21:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Internet Explorer 11 für Windows 7 für x64-basierte Systeme Error: (01/01/2014 04:13:01 PM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (01/01/2014 04:10:36 PM) (Source: NetBT) (User: ) Description: Ein doppelter Name wurde im TCP-Netzwerk entdeckt. Die IP-Adresse des Computers, der die Meldung gesendet hat, steht in den Daten. Verwenden Sie NBTSTAT -n an der Eingabeaufforderung, um den doppelten Namen zu bestimmen. Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2012-04-10 22:40:56.540 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-04-10 22:40:56.475 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-04-10 22:40:56.406 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-04-10 22:40:56.350 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-04-10 22:40:56.252 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-04-10 22:40:56.180 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-04-10 22:40:56.099 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-04-10 22:40:56.022 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-04-10 22:40:55.782 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-04-10 22:40:55.683 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 52% Total physical RAM: 3950.1 MB Available physical RAM: 1893.74 MB Total Pagefile: 7898.38 MB Available Pagefile: 5451.73 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:456.37 GB) (Free:362.95 GB) NTFS Drive e: (19 Aug 2013) (CDROM) (Total:4.38 GB) (Free:3.22 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 369480EA) Partition 1: (Not Active) - (Size=9 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=456 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
02.01.2014, 10:56 | #8 |
/// TB-Ausbilder | Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht Weiter: Schritt 1
Schritt 2 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 3 Scan mit Combofix
Schritt 4 Starte noch einmal FRST.
__________________ cheers, Leo |
03.01.2014, 10:25 | #9 |
| Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht hey Leo, ich würde dir ja gerne weitere fortschritte melden, aber flv toolbar, sowie auch Update Service lassen sich auch nach mehrmaligem Versuchen nicht deinstallieren... soll ich nun einfach tzd den weiteren weg beschreiten oder hast du eine Idee woran das liegen könnte? Gruß |
03.01.2014, 13:14 | #10 |
/// TB-Ausbilder | Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht Hallo, das macht nichts, dann fahre einfach mit dem nächsten Punkt weiter.
__________________ cheers, Leo |
06.01.2014, 15:34 | #11 |
| Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht Sorry für die verspätete Antwort!! Logfile von FRST FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014 Ran by Thomas (administrator) on THOMAS-VAIO on 06-01-2014 15:30:36 Running from C:\Users\Thomas\Desktop\Viren-Beseitigung Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exeac (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (BUFFALO INC.) C:\Program Files (x86)\BUFFALO\SLManagerEasy\Bufssvr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (BUFFALO INC.) C:\Program Files (x86)\BUFFALO\SLManagerEasy\Inputps.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe (Microsoft Corporation) C:\Program Files\Zune\ZuneLauncher.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Sony Corporation) C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Sony Corporation) C:\Program Files (x86)\SONY\Reader\Data\bin\launcher\eBook Library Launcher.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Sony Corporation) C:\Program Files (x86)\SONY\VAIO Event Service\VESMgrSub.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9636896 2009-12-16] (Realtek Semiconductor) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [208384 2009-11-04] (Alps Electric Co., Ltd.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Java\jre6\bin\jusched.exe [171520 2009-01-01] (Sun Microsystems, Inc.) HKLM\...\Run: [Zune Launcher] - C:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-11-20] (Intel Corporation) HKLM-x32\...\Run: [ISBMgr.exe] - C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe [320880 2009-08-26] (Sony Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-01-13] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [MarketingTools] - C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe [26624 2009-01-01] (Sony Corporation) HKLM-x32\...\Run: [SHTtray.exe] - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe [99696 2010-09-10] (Sony Corporation) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254696 2011-06-09] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Blackcomb] - C:\Program Files (x86)\Samsung Connection Manager\ModemPnPService.exe [131072 2011-02-11] (Samsung Electronics.) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] () HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-02-18] (Apple Inc.) HKLM-x32\...\Run: [eBook Library Launcher] - C:\Program Files (x86)\SONY\Reader\Data\bin\launcher\eBook Library Launcher.exe [902440 2009-07-03] (Sony Corporation) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2014-01-01] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1778640 2013-12-20] (APN) HKLM-x32\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Users\Thomas\AppData\Roaming\appConf32.exe,C:\Users\Thomas\AppData\Roaming\jabconf32.exe, [x] Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Facebook Update] - C:\Users\Thomas\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-22] (Facebook Inc.) Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 - {75b4241f-171e-44a3-bf44-23613b6e3e03} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^AYY^xdm070^YYA^de&si=flvrunner&ptb=790C2CC8-A335-48AA-AEB3-118EC7308978&ind=2013092113&n=77fd5911&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - {75b4241f-171e-44a3-bf44-23613b6e3e03} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^AYY^xdm070^YYA^de&si=flvrunner&ptb=790C2CC8-A335-48AA-AEB3-118EC7308978&ind=2013092113&n=77fd5911&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± vË°!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL = BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL No File Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}: [NameServer]192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default FF SelectedSearchEngine: Hola Search FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @sony.com/eBookLibrary - C:\Program Files (x86)\Sony\Reader\Data\bin\npebldetectmoz.dll (Sony Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Thomas\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: VideoDownloadConverter - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\Extensions\4zffxtbr-bs@VideoDownloadConverter_4z.com FF Extension: No Name - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\Extensions\8hffxtbr@Allin1Convert_8h.com FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2014-01-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-26] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2014-01-01] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] (APN LLC.) R2 bufssvr; C:\Program Files (x86)\BUFFALO\SLManagerEasy\Bufssvr.exe [90112 2010-03-12] (BUFFALO INC.) S3 Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [313840 2009-08-31] (Sonic Solutions) S2 Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [362992 2009-08-31] (Sonic Solutions) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [74496 2010-09-27] (Sony Corporation) R2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [864000 2010-09-27] (Sony Corporation) S3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1286784 2012-10-26] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R2 6077757b; C:\Windows\system32\drivers\regi.sys [14112 2007-04-17] (InterVideo) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-01-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-01-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG) S3 C2XXCOM; C:\Windows\System32\DRIVERS\C2XXCOM76.sys [49920 2010-08-09] (Samsung Electronics) S3 C2xxUSB; C:\Windows\System32\DRIVERS\C2xxUSB76.sys [46080 2010-11-04] (Samsung Electronics) S3 C2xxUsbStorage; C:\Windows\System32\DRIVERS\C2xSTR76.sys [9216 2010-06-10] (Samsung Electronics) S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [28416 2008-04-16] (Research In Motion Limited) R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-11-12] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) U3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-06 14:05 - 2014-01-06 14:05 - 00025997 _____ C:\ComboFix.txt 2014-01-06 12:35 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-06 12:35 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-06 12:35 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-06 12:35 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-06 12:35 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-06 12:35 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-06 12:35 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-06 12:35 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-06 12:31 - 2014-01-06 14:05 - 00000000 ____D C:\Qoobox 2014-01-06 12:30 - 2014-01-06 13:06 - 00000000 ____D C:\Windows\erdnt 2014-01-04 01:19 - 2014-01-04 01:22 - 00000000 ____D C:\AdwCleaner 2014-01-03 03:02 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2014-01-03 03:02 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2014-01-03 03:02 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2014-01-03 03:02 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2014-01-03 01:03 - 2014-01-03 01:03 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf08172e6a9e70.job 2014-01-02 10:35 - 2014-01-06 15:30 - 00000000 ____D C:\Users\Thomas\Desktop\Viren-Beseitigung 2014-01-02 10:28 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-01-02 10:28 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-01-02 10:28 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-01-02 10:28 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2014-01-02 10:28 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-02 10:28 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2014-01-02 10:28 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2014-01-02 10:27 - 2014-01-02 10:27 - 00000286 ____H C:\Windows\Tasks\User_Feed_Synchronization-{D30B1914-6D71-46E4-813A-B2B3835BF810}.job 2014-01-02 10:27 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-01-02 10:27 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-01-02 10:27 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2014-01-02 10:27 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2014-01-02 10:27 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2014-01-02 10:27 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2014-01-02 10:27 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2014-01-02 10:27 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2014-01-02 10:27 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2014-01-02 10:27 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2014-01-02 10:27 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2014-01-02 10:27 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2014-01-02 03:09 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2014-01-02 03:04 - 2014-01-02 03:04 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-01-02 03:04 - 2014-01-02 03:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-02 03:04 - 2014-01-02 03:04 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-02 03:04 - 2014-01-02 03:04 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-01-02 03:04 - 2014-01-02 03:04 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-01-01 16:17 - 2014-01-02 03:09 - 00017589 _____ C:\Windows\IE11_main.log 2014-01-01 13:59 - 2014-01-06 15:30 - 00000000 ____D C:\FRST ==================== One Month Modified Files and Folders ======= 2014-01-06 15:30 - 2014-01-02 10:35 - 00000000 ____D C:\Users\Thomas\Desktop\Viren-Beseitigung 2014-01-06 15:30 - 2014-01-01 13:59 - 00000000 ____D C:\FRST 2014-01-06 14:05 - 2014-01-06 14:05 - 00025997 _____ C:\ComboFix.txt 2014-01-06 14:05 - 2014-01-06 12:31 - 00000000 ____D C:\Qoobox 2014-01-06 13:50 - 2009-01-01 18:26 - 00000215 _____ C:\Windows\system.ini 2014-01-06 13:45 - 2009-01-01 03:02 - 01534689 _____ C:\Windows\WindowsUpdate.log 2014-01-06 13:12 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2014-01-06 13:06 - 2014-01-06 12:30 - 00000000 ____D C:\Windows\erdnt 2014-01-06 12:47 - 2011-01-28 20:03 - 00000000 ____D C:\Users\Thomas 2014-01-04 03:02 - 2009-07-14 05:45 - 00013936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-04 03:02 - 2009-07-14 05:45 - 00013936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-04 01:29 - 2009-07-14 06:13 - 01507406 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-04 01:29 - 2009-01-01 02:56 - 00657910 _____ C:\Windows\system32\perfh007.dat 2014-01-04 01:29 - 2009-01-01 02:56 - 00131250 _____ C:\Windows\system32\perfc007.dat 2014-01-04 01:26 - 2013-08-20 09:12 - 00000000 ___RD C:\Users\Thomas\Dropbox 2014-01-04 01:26 - 2013-08-20 09:10 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Dropbox 2014-01-04 01:23 - 2009-01-01 18:26 - 00156290 _____ C:\Windows\setupact.log 2014-01-04 01:22 - 2014-01-04 01:19 - 00000000 ____D C:\AdwCleaner 2014-01-04 01:22 - 2011-06-04 17:50 - 00000000 ____D C:\ProgramData\ICQ 2014-01-03 03:20 - 2009-07-14 05:45 - 00446640 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-03 03:18 - 2009-01-01 03:00 - 00693530 _____ C:\Windows\PFRO.log 2014-01-03 03:01 - 2011-03-16 08:41 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-01-03 01:03 - 2014-01-03 01:03 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf08172e6a9e70.job 2014-01-02 10:27 - 2014-01-02 10:27 - 00000286 ____H C:\Windows\Tasks\User_Feed_Synchronization-{D30B1914-6D71-46E4-813A-B2B3835BF810}.job 2014-01-02 03:30 - 2011-01-28 20:04 - 00001421 _____ C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-02 03:24 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2014-01-02 03:09 - 2014-01-01 16:17 - 00017589 _____ C:\Windows\IE11_main.log 2014-01-02 03:04 - 2014-01-02 03:04 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-01-02 03:04 - 2014-01-02 03:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-02 03:04 - 2014-01-02 03:04 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-02 03:04 - 2014-01-02 03:04 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-01-02 03:04 - 2014-01-02 03:04 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-01-01 16:25 - 2013-08-21 11:33 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-01-01 16:25 - 2013-08-21 11:28 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-01-01 16:25 - 2013-08-21 11:28 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-01-01 16:04 - 2011-01-28 20:04 - 00000000 ___RD C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Some content of TEMP: ==================== C:\Users\Thomas\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-21 23:19 ==================== End Of Log ============================ Combofix Code:
ATTFilter ComboFix 14-01-04.03 - Thomas 06.01.2014 13:40:02.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3950.2100 [GMT 1:00] ausgeführt von:: c:\users\Thomas\Desktop\ComboFix.exe AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2013-12-06 bis 2014-01-06 )))))))))))))))))))))))))))))) . . 2014-01-06 12:50 . 2014-01-06 12:50 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-01-06 11:38 . 2014-01-06 11:38 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{AEEBB7D1-026F-44AD-A0E3-089C3033F572}\offreg.dll 2014-01-04 00:19 . 2014-01-04 00:22 -------- d-----w- C:\AdwCleaner 2014-01-03 09:22 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{AEEBB7D1-026F-44AD-A0E3-089C3033F572}\mpengine.dll 2014-01-03 02:02 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL 2014-01-03 02:02 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe 2014-01-03 02:02 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe 2014-01-03 02:02 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL 2014-01-03 02:02 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll 2014-01-02 09:28 . 2013-10-30 02:32 335360 ----a-w- c:\windows\system32\msieftp.dll 2014-01-02 09:28 . 2013-10-30 02:19 301568 ----a-w- c:\windows\SysWow64\msieftp.dll 2014-01-02 09:28 . 2013-10-30 01:24 3155968 ----a-w- c:\windows\system32\win32k.sys 2014-01-02 09:28 . 2013-11-23 18:26 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2014-01-02 09:28 . 2013-11-23 17:47 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2014-01-02 09:28 . 2013-10-19 02:18 81408 ----a-w- c:\windows\system32\imagehlp.dll 2014-01-02 09:28 . 2013-10-19 01:36 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll 2014-01-02 09:27 . 2013-11-12 02:23 2048 ----a-w- c:\windows\system32\tzres.dll 2014-01-02 09:27 . 2013-11-12 02:07 2048 ----a-w- c:\windows\SysWow64\tzres.dll 2014-01-02 09:27 . 2013-10-04 02:16 116736 ----a-w- c:\windows\system32\drivers\drmk.sys 2014-01-02 09:27 . 2013-10-04 01:36 230400 ----a-w- c:\windows\system32\drivers\portcls.sys 2014-01-02 09:27 . 2013-10-12 02:32 150016 ----a-w- c:\windows\system32\wshom.ocx 2014-01-02 09:27 . 2013-10-12 02:31 202752 ----a-w- c:\windows\system32\scrrun.dll 2014-01-02 09:27 . 2013-10-12 02:04 121856 ----a-w- c:\windows\SysWow64\wshom.ocx 2014-01-02 09:27 . 2013-10-12 02:03 163840 ----a-w- c:\windows\SysWow64\scrrun.dll 2014-01-02 09:27 . 2013-10-12 01:33 156160 ----a-w- c:\windows\system32\cscript.exe 2014-01-02 09:27 . 2013-10-12 01:33 168960 ----a-w- c:\windows\system32\wscript.exe 2014-01-02 09:27 . 2013-10-12 01:15 141824 ----a-w- c:\windows\SysWow64\wscript.exe 2014-01-02 09:27 . 2013-10-12 01:15 126976 ----a-w- c:\windows\SysWow64\cscript.exe 2014-01-02 02:09 . 2013-10-14 17:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE 2014-01-01 12:59 . 2014-01-02 09:29 -------- d-----w- C:\FRST . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-01-01 15:25 . 2013-08-21 10:33 84720 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2014-01-01 15:25 . 2013-08-21 10:28 131576 ----a-w- c:\windows\system32\drivers\avipbb.sys 2014-01-01 15:25 . 2013-08-21 10:28 108440 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-11-26 11:25 . 2011-03-30 16:05 267936 ------w- c:\windows\system32\MpSigStub.exe 2013-11-26 09:21 . 2013-08-21 10:28 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2013-10-12 02:30 . 2013-11-13 11:05 830464 ----a-w- c:\windows\system32\nshwfp.dll 2013-10-12 02:29 . 2013-11-13 11:05 859648 ----a-w- c:\windows\system32\IKEEXT.DLL 2013-10-12 02:29 . 2013-11-13 11:05 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL 2013-10-12 02:03 . 2013-11-13 11:05 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll 2013-10-12 02:01 . 2013-11-13 11:05 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}] 2013-12-20 19:17 12240 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" [2013-12-20 12240] . [HKEY_CLASSES_ROOT\clsid\{41564952-412d-5637-00a7-7a786e7484d7}] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 130736 ----a-w- c:\users\Thomas\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 130736 ----a-w- c:\users\Thomas\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 130736 ----a-w- c:\users\Thomas\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 130736 ----a-w- c:\users\Thomas\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Facebook Update"="c:\users\Thomas\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-22 138096] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-11-20 284696] "ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2009-08-26 320880] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-13 98304] "MarketingTools"="c:\program files (x86)\Sony\Marketing Tools\MarketingTools.exe" [2009-01-01 26624] "SHTtray.exe"="c:\program files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe" [2010-09-10 99696] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "Blackcomb"="c:\program files (x86)\Samsung Connection Manager\ModemPnPService.exe" [2011-02-11 131072] "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-18 152392] "eBook Library Launcher"="c:\program files (x86)\Sony\Reader\Data\bin\launcher\eBook Library Launcher.exe" [2009-07-03 902440] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-01-01 684600] "ApnTBMon"="c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-12-20 1778640] . c:\users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-6-5 27370808] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-9-4 1081632] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="c:\windows\system32\userinit.exe,c:\users\Thomas\AppData\Roaming\appConf32.exe,c:\users\Thomas\AppData\Roaming\jabconf32.exe," . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon] 2009-12-01 21:03 98304 ----a-w- c:\windows\System32\VESWinlogon.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] R2 regi;regi;c:\windows\system32\drivers\regi.sys;c:\windows\SYSNATIVE\drivers\regi.sys [x] R2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe;c:\program files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 C2XXCOM;LTE/HSPA COM Port USB Device;c:\windows\system32\DRIVERS\C2XXCOM76.sys;c:\windows\SYSNATIVE\DRIVERS\C2XXCOM76.sys [x] R3 C2xxUSB;Samsung CMC2xx USB Network Driver;c:\windows\system32\DRIVERS\C2xxUSB76.sys;c:\windows\SYSNATIVE\DRIVERS\C2xxUSB76.sys [x] R3 C2xxUsbStorage;Samsung CMC2xx USB LTE Storage Driver;c:\windows\system32\DRIVERS\C2xSTR76.sys;c:\windows\SYSNATIVE\DRIVERS\C2xSTR76.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] R3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe;c:\program files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe;c:\program files\Sony\VAIO Power Management\SPMService.exe [x] R3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [x] R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [x] R3 VCService;VCService;c:\program files\Sony\VAIO Care\VCService.exe;c:\program files\Sony\VAIO Care\VCService.exe [x] R3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update\VUAgent.exe;c:\program files\Sony\VAIO Update\VUAgent.exe [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S2 6077757b;6077757b;c:\windows\system32\drivers\regi.sys;c:\windows\SYSNATIVE\drivers\regi.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x] S2 APNMCP;Ask Aktualisierungsdienst;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x] S2 bufssvr;bufssvr;c:\program files (x86)\BUFFALO\SLManagerEasy\Bufssvr.exe;c:\program files (x86)\BUFFALO\SLManagerEasy\Bufssvr.exe [x] S2 rimspci;rimspci;c:\windows\system32\drivers\rimssne64.sys;c:\windows\SYSNATIVE\drivers\rimssne64.sys [x] S2 risdsnpe;risdsnpe;c:\windows\system32\drivers\risdsne64.sys;c:\windows\SYSNATIVE\drivers\risdsne64.sys [x] S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe;c:\program files\Sony\VAIO Care\VCPerfService.exe [x] S2 SOHCImp;VAIO Media plus Content Importer;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [x] S2 SOHDms;VAIO Media plus Digital Media Server;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe [x] S2 SOHDs;VAIO Media plus Device Searcher;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [x] S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [x] S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [x] S2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [x] S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe;c:\program files\Sony\VAIO Smart Network\VSNService.exe [x] S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftKsUFilter.sys [x] S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys;c:\windows\SYSNATIVE\drivers\btusbflt.sys [x] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys;c:\windows\SYSNATIVE\drivers\Impcd.sys [x] S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys;c:\windows\SYSNATIVE\drivers\SFEP.sys [x] S3 SpfService;VAIO Entertainment Common Service;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [x] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2013-08-25 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-901852694-1798116289-1978641750-1000Core.job - c:\users\Thomas\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-21 08:32] . 2013-08-25 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-901852694-1798116289-1978641750-1000UA.job - c:\users\Thomas\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-21 08:32] . 2014-01-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cf08172e6a9e70.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-01-01 02:08] . 2013-08-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-01-01 02:08] . 2014-01-02 c:\windows\Tasks\User_Feed_Synchronization-{D30B1914-6D71-46E4-813A-B2B3835BF810}.job - c:\windows\system32\msfeedssync.exe [2014-01-02 02:04] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}] 2013-12-20 19:17 13776 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll" [2013-12-20 13776] . [HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 164016 ----a-w- c:\users\Thomas\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 164016 ----a-w- c:\users\Thomas\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 164016 ----a-w- c:\users\Thomas\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 164016 ----a-w- c:\users\Thomas\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-16 9636896] "Apoint"="c:\program files (x86)\Apoint\Apoint.exe" [BU] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-01 171520] "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 163552] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = https://www.google.de/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Free YouTube Download - c:\users\Thomas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm IE: Free YouTube to MP3 Converter - c:\users\Thomas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000 IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll TCP: DhcpNameServer = 192.168.2.1 TCP: Interfaces\{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}: NameServer = 192.168.2.1 TCP: Interfaces\{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}\4584F4D41435D2651494F4F5E4564777F627B6: NameServer = 192.168.2.1 TCP: Interfaces\{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}\5416379724F687D2636333341303: NameServer = 192.168.2.1 FF - ProfilePath - c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\ FF - prefs.js: browser.search.selectedEngine - Hola Search FF - ExtSQL: !HIDDEN! 2013-09-21 19:31; 8hffxtbr@Allin1Convert_8h.com; c:\program files (x86)\Allin1Convert_8h\bar\1.bin . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKLM-Run-<NO NAME> - (no file) . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SampleCollector] "ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=c:\programdata\Sony Corporation\VAIO Care\inteldata\"" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-01-06 14:04:58 ComboFix-quarantined-files.txt 2014-01-06 13:04 ComboFix2.txt 2014-01-06 12:12 . Vor Suchlauf: 21 Verzeichnis(se), 400.767.692.800 Bytes frei Nach Suchlauf: 22 Verzeichnis(se), 400.456.286.208 Bytes frei . - - End Of File - - CBE9E6781AE59260F79241DE05C61253 Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 04/01/2014 um 01:22:24 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Thomas - THOMAS-VAIO # Gestartet von : C:\Users\Thomas\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Iminent Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro Ordner Gelöscht : C:\Program Files (x86)\Iminent Ordner Gelöscht : C:\Program Files (x86)\jZip Ordner Gelöscht : C:\Program Files (x86)\FLV_Runner Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB Ordner Gelöscht : C:\Users\Thomas\AppData\Local\iac Ordner Gelöscht : C:\Users\Thomas\AppData\Local\jZip Ordner Gelöscht : C:\Users\Thomas\AppData\Local\Temp\AskSearch Ordner Gelöscht : C:\Users\Thomas\AppData\Local\Temp\boost_interprocess Ordner Gelöscht : C:\Users\Thomas\AppData\Local\Temp\Iminent Ordner Gelöscht : C:\Users\Thomas\AppData\Local\Temp\jZip Ordner Gelöscht : C:\Users\Thomas\AppData\Local\Temp\Smartbar Ordner Gelöscht : C:\Users\Thomas\AppData\LocalLow\holasearch Ordner Gelöscht : C:\Users\Thomas\AppData\LocalLow\FLV_Runner Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\Extensions\ffxtlbr@holasearch.com Datei Gelöscht : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\Extensions\webbooster@iminent.com.xpi Datei Gelöscht : C:\Windows\System32\roboot64.exe Datei Gelöscht : C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\jZip.lnk Datei Gelöscht : C:\Users\Thomas\Desktop\jZip.lnk Datei Gelöscht : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\searchplugins\holasearch.xml Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\StartWeb.xml Datei Gelöscht : C:\Windows\System32\Tasks\BrowserProtect Datei Gelöscht : C:\Windows\System32\Tasks\EPUpdater Datei Gelöscht : C:\Windows\System32\Tasks\PC Performer Datei Gelöscht : C:\Windows\Tasks\PC Performer_DEFAULT.job Datei Gelöscht : C:\Windows\System32\Tasks\PC Performer_DEFAULT Datei Gelöscht : C:\Windows\Tasks\PC Performer_UPDATES.job Datei Gelöscht : C:\Windows\System32\Tasks\PC Performer_UPDATES Datei Gelöscht : C:\Windows\System32\Tasks\RegClean Pro ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\*\shell\filescout Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\jZip.file Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\jZip_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\jZip_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppPath\jZip.exe Schlüssel Gelöscht : HKCU\Software\fe8ad8b638ee49 Schlüssel Gelöscht : HKLM\SOFTWARE\fe8ad8b638ee49 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{58B41DCD-55B2-48EB-A55A-E330070FFC00} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{01A602A0-D0B9-445B-8081-719E4177C4A7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02C9C7B0-C7C8-4AAC-A9E4-55295BF60F8F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0398B101-6DA7-473F-A290-17D2FBC88CC0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0CC36196-8589-4B80-A771-D659411D7F90} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{143D96F9-EB64-48B3-B192-91C2C41A1F43} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{14F7D91F-F669-45C9-9F42-BACBFDB86EAD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{187A6488-6E71-4A2A-B118-7BEFBFE58257} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{26C9BBE4-6D45-4AB6-A5B4-E068C9F5EF6D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2D065204-A024-4C39-8A38-EE7078EC7ACF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{30F5476C-677B-4DB0-B397-51F5BFD86840} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3223F2FB-D9B9-45FC-9D66-CD717FFA4EE5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{351798B1-C1D2-45AB-92B4-4D6C2D6AB5AF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3AEA1BEF-6195-46F4-ACA2-0ED14F7EFA1B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3D7F9AC3-BAC3-4E51-81D7-D121D79E550A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4498C5E9-93C6-4142-B6BE-F0C6DC48B77A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{479BF2D6-E362-4A99-B1AB-BC764D7B97AE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{492A108F-51D0-4BD8-899D-AD4AB2893064} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4B6D6E60-FBD2-4E79-BF4B-886BC98F1797} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{60893E02-2E5B-43F9-A93A-BAD60C2DF6EF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6D39931F-451E-4BDD-BAF4-37FB96DBBA5D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{76C684D2-C35D-4284-976A-D862F53ADB81} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{796D822A-C3F9-4A97-BAAB-42FE7628EA63} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{79EF3691-EC1A-4705-A01A-D2E36EC11758} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82F41418-8E64-47EB-A7F1-4702A974D289} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{85D920CE-63A7-46DC-8992-41D1D2E07FAD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{895ED5E8-ABB4-40C3-A0CA-2571964268E2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8AAC123A-1959-4A45-BFC5-E2D50783098A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A07956CD-81F8-4A03-B524-5D87E690DC83} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B5E3B26B-6E5C-4865-A63D-58D04B10E245} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B84D2DC5-42B2-4E5E-BF61-7B48152FF8EF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B89D5309-0367-4494-A92F-3D4C94F88307} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C014EBF8-8854-448B-B5A4-557C4090EDCE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C31191DB-2F64-464C-B97C-6AC81ACB7AAC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C342C7A7-F622-4EF3-8B7F-ABB9FBE73F14} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C4765B07-BC2F-477B-925C-B2BF24887823} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C875C0A1-09E3-48D5-9F8E-BD337796FD14} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD126DA6-FF5B-4181-AC13-54A62240D2FA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D8F01233-2DE6-4EE7-8988-37263F00651B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DD438708-AAB4-422D-A322-B619589F5680} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E812AE43-7799-4E67-8CF8-4104297A2D16} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F0BAAEC7-9AE0-49FF-9C4B-86E774FF397F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F92193FD-2243-4401-9ACC-49FF30885898} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD21B8A2-910B-45AC-9C10-45E6A8B84984} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3BBD3C14-4C16-4989-8366-95BC9179779D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{07CEA379-7178-4758-9C80-969876E32395} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ACA608DB-A210-4253-B799-3FD24E9A7BF5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3BBD3C14-4C16-4989-8366-95BC9179779D} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7CAEFAFC-9A1E-4BCC-94DD-BC7D8D52717A} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3BBD3C14-4C16-4989-8366-95BC9179779D} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07CEA379-7178-4758-9C80-969876E32395} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3BBD3C14-4C16-4989-8366-95BC9179779D} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07CEA379-7178-4758-9C80-969876E32395} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0AF350D9-3916-454B-AC53-0B0B65F41301} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3614D305-2DBB-4991-9297-750DD60FFC73} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CD19E8A2-8024-4030-B2E8-E85888DFD2FC} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C9C6B54F-9AD5-454A-9367-28AB345CFD79} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{DFEFCDEE-CF1A-4FC8-89AF-189327213627}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{3BBD3C14-4C16-4989-8366-95BC9179779D}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{3BBD3C14-4C16-4989-8366-95BC9179779D}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{3BBD3C14-4C16-4989-8366-95BC9179779D}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{53F6A516-3DCC-48F4-835C-6C670CB39CEA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ACA608DB-A210-4253-B799-3FD24E9A7BF5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Schlüssel Gelöscht : HKCU\Software\jZip Schlüssel Gelöscht : HKCU\Software\FLV_Runner Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\FLV_Runner Schlüssel Gelöscht : HKLM\Software\DeviceVM Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar Schlüssel Gelöscht : HKLM\Software\jZip Schlüssel Gelöscht : HKLM\Software\FLV_Runner Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\jZip Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{491C9A4E-6E50-4B53-911D-861BA8DA3C21} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\toolplugin Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FLV_Runner Toolbar Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DeviceVM ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] -\\ Mozilla Firefox v11.0 (de) [ Datei : C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\prefs.js ] Zeile gelöscht : user_pref("extensions.enabledAddons", "webbooster@iminent.com:7.41.2.1,{972ce4c6-7e08-4474-a285-3208198ce6fd}:11.0"); Zeile gelöscht : user_pref("extensions.holasearch.admin", false); Zeile gelöscht : user_pref("extensions.holasearch.aflt", "babsst"); Zeile gelöscht : user_pref("extensions.holasearch.appId", "{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}"); Zeile gelöscht : user_pref("extensions.holasearch.autoRvrt", "false"); Zeile gelöscht : user_pref("extensions.holasearch.dfltLng", "de"); Zeile gelöscht : user_pref("extensions.holasearch.excTlbr", false); Zeile gelöscht : user_pref("extensions.holasearch.ffxUnstlRst", false); Zeile gelöscht : user_pref("extensions.holasearch.id", "d8d124280000000000002a8158fa0218"); Zeile gelöscht : user_pref("extensions.holasearch.instlDay", "15888"); Zeile gelöscht : user_pref("extensions.holasearch.instlRef", "sst"); Zeile gelöscht : user_pref("extensions.holasearch.newTab", false); Zeile gelöscht : user_pref("extensions.holasearch.prdct", "holasearch"); Zeile gelöscht : user_pref("extensions.holasearch.prtnrId", "holasearch"); Zeile gelöscht : user_pref("extensions.holasearch.rvrt", "false"); Zeile gelöscht : user_pref("extensions.holasearch.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.holasearch.tlbrId", "base"); Zeile gelöscht : user_pref("extensions.holasearch.tlbrSrchUrl", ""); Zeile gelöscht : user_pref("extensions.holasearch.vrsn", "1.8.16.16"); Zeile gelöscht : user_pref("extensions.holasearch.vrsnTs", "1.8.16.1614:00:21"); Zeile gelöscht : user_pref("extensions.holasearch.vrsni", "1.8.16.16"); Zeile gelöscht : user_pref("iminent.LayoutId", "1"); Zeile gelöscht : user_pref("iminent.ShowThankyouPixel", "0"); Zeile gelöscht : user_pref("iminent.displayFavLinks", "1"); Zeile gelöscht : user_pref("iminent.registerToolbarEvent101", "1381597230039"); Zeile gelöscht : user_pref("iminent.registerToolbarEvent102", "1381593601823"); Zeile gelöscht : user_pref("iminent.version", "7.41.2.1"); Zeile gelöscht : user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.33.3.1\",\"InstallEventCTime\":1376939623395,\"InstallEvent\":\"True\",\"UpdateEventCTime\":1385287886904}"); ************************* AdwCleaner[R0].txt - [24405 octets] - [04/01/2014 01:21:08] AdwCleaner[S0].txt - [23879 octets] - [04/01/2014 01:22:24] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [23940 octets] ########## |
06.01.2014, 15:50 | #12 |
/// TB-Ausbilder | Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht Wie läuft der Rechner jetzt? Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKLM-x32\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Users\Thomas\AppData\Roaming\appConf32.exe,C:\Users\Thomas\AppData\Roaming\jabconf32.exe, [x] SearchScopes: HKLM-x32 - {75b4241f-171e-44a3-bf44-23613b6e3e03} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^AYY^xdm070^YYA^de&si=flvrunner&ptb=790C2CC8-A335-48AA-AEB3-118EC7308978&ind=2013092113&n=77fd5911&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - {75b4241f-171e-44a3-bf44-23613b6e3e03} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^AYY^xdm070^YYA^de&si=flvrunner&ptb=790C2CC8-A335-48AA-AEB3-118EC7308978&ind=2013092113&n=77fd5911&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± vË°!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL = FF Extension: VideoDownloadConverter - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\Extensions\4zffxtbr-bs@VideoDownloadConverter_4z.com FF Extension: No Name - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\Extensions\8hffxtbr@Allin1Convert_8h.com FF SelectedSearchEngine: Hola Search Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2
Schritt 3 ESET Online Scanner
Schritt 4 Starte noch einmal FRST.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
07.01.2014, 12:44 | #13 |
| Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht Fixlog Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-01-2014 Ran by Thomas at 2014-01-06 16:23:29 Run:2 Running from C:\Users\Thomas\Desktop\Viren-Beseitigung Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM-x32\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Users\Thomas\AppData\Roaming\appConf32.exe,C:\Users\Thomas\AppData\Roaming\jabconf32.exe, [x] SearchScopes: HKLM-x32 - {75b4241f-171e-44a3-bf44-23613b6e3e03} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^AYY^xdm070^YYA^de&si=flvrunner&ptb=790C2CC8-A335-48AA-AEB3-118EC7308978&ind=2013092113&n=77fd5911&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - {75b4241f-171e-44a3-bf44-23613b6e3e03} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^AYY^xdm070^YYA^de&si=flvrunner&ptb=790C2CC8-A335-48AA-AEB3-118EC7308978&ind=2013092113&n=77fd5911&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± vË°!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL = FF Extension: VideoDownloadConverter - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\Extensions\4zffxtbr-bs@VideoDownloadConverter_4z.com FF Extension: No Name - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\Extensions\8hffxtbr@Allin1Convert_8h.com FF SelectedSearchEngine: Hola Search ***************** HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{75b4241f-171e-44a3-bf44-23613b6e3e03} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{75b4241f-171e-44a3-bf44-23613b6e3e03} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{75b4241f-171e-44a3-bf44-23613b6e3e03} => Key deleted successfully. HKCR\CLSID\{75b4241f-171e-44a3-bf44-23613b6e3e03} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± vË°!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* => Key not found. HKCR\CLSID\ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± vË°!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* => Key not found. C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\Extensions\4zffxtbr-bs@VideoDownloadConverter_4z.com => Moved successfully. C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default\Extensions\8hffxtbr@Allin1Convert_8h.com => Moved successfully. Firefox SelectedSearchEngine deleted successfully. ==== End of Fixlog ==== Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.06.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16428 Thomas :: THOMAS-VAIO [Administrator] Schutz: Aktiviert 06.01.2014 17:13:30 mbam-log-2014-01-06 (17-13-30).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 216365 Laufzeit: 6 Minute(n), 25 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 1 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Userinit (Hijack.UserInit) -> Bösartig: (C:\Windows\system32\userinit.exe,C:\Users\Thomas\AppData\Roaming\appConf32.exe,C:\Users\Thomas\AppData\Roaming\jabconf32.exe,) Gut: (userinit.exe) -> Erfolgreich ersetzt und in Quarantäne gestellt. Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 4 C:\Users\Thomas\Downloads\FLV_Runner.exe (PUP.Optional.Conduit) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Thomas\Downloads\setup_codec_3dx.exe (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Installer\44ebde.msi (PUP.Optional.Iminent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Thomas\AppData\Local\2433f433 (Trojan.Agent.TPL) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=797f862b261eac4c95ff6db1c3568226 # engine=16541 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-06 07:29:38 # local_time=2014-01-06 08:29:38 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 94 256637 159707883 249409 0 # compatibility_mode=5893 16776573 100 94 16847 140666428 0 0 # scanned=198938 # found=6 # cleaned=0 # scan_time=9793 sh=78A930CDFED1C2CA6159474B34E0290BAE5866DB ft=1 fh=76a58d5fcca4bf08 vn="a variant of Win32/Kryptik.BPSQ trojan" ac=I fn="C:\FRST\Quarantine\bflwadq.dss" sh=D90357A9E8E4BE5EE7E9EDC118F883E5331762C4 ft=1 fh=c2c520f71863cf5b vn="a variant of Win32/Reveton.W trojan" ac=I fn="C:\FRST\Quarantine\qdawlfb.fdd" sh=95FDF5F9C610127F97D13FF4138507C82ACD6199 ft=1 fh=cd19fd3c4e8c3748 vn="a variant of Win64/Kryptik.FG trojan" ac=I fn="C:\FRST\Quarantine\qdawlfb.pss" sh=EBECF03FE0F94322C4A6AF2D7A2712ECB405DE6F ft=1 fh=6b26bef07139ba86 vn="a variant of Win32/Kryptik.BHOH trojan" ac=I fn="C:\FRST\Quarantine\xvstnmnutprdljmakoi.bfg" sh=6B8E3F1E1DD6681C4B014CAD616DA9EFB4CC4109 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\2e49382-7fbd8652" sh=E654A5C91EC4B33C925BE28641368B2207A75B13 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2012-0507.FQ trojan" ac=I fn="C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\1352636b-2ed467bf" FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014 Ran by Thomas (administrator) on THOMAS-VAIO on 07-01-2014 05:33:03 Running from C:\Users\Thomas\Desktop\Viren-Beseitigung Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (BUFFALO INC.) C:\Program Files (x86)\BUFFALO\SLManagerEasy\Bufssvr.exe (BUFFALO INC.) C:\Program Files (x86)\BUFFALO\SLManagerEasy\Inputps.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (AMD) C:\Windows\System32\atieclxx.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Sony Corporation) C:\Program Files (x86)\SONY\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (Microsoft Corporation) C:\Program Files\Zune\ZuneLauncher.exe (Facebook Inc.) C:\Users\Thomas\AppData\Local\Facebook\Update\FacebookUpdate.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Dropbox, Inc.) C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Sony Corporation) C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe (Sony Corporation) C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Samsung Electronics.) C:\Program Files (x86)\Samsung Connection Manager\ModemPnPService.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Sony Corporation) C:\Program Files (x86)\SONY\Reader\Data\bin\launcher\eBook Library Launcher.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9636896 2009-12-16] (Realtek Semiconductor) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [208384 2009-11-04] (Alps Electric Co., Ltd.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Java\jre6\bin\jusched.exe [171520 2009-01-01] (Sun Microsystems, Inc.) HKLM\...\Run: [Zune Launcher] - C:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-11-20] (Intel Corporation) HKLM-x32\...\Run: [ISBMgr.exe] - C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe [320880 2009-08-26] (Sony Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-01-13] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [MarketingTools] - C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe [26624 2009-01-01] (Sony Corporation) HKLM-x32\...\Run: [SHTtray.exe] - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe [99696 2010-09-10] (Sony Corporation) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254696 2011-06-09] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Blackcomb] - C:\Program Files (x86)\Samsung Connection Manager\ModemPnPService.exe [131072 2011-02-11] (Samsung Electronics.) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] () HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-02-18] (Apple Inc.) HKLM-x32\...\Run: [eBook Library Launcher] - C:\Program Files (x86)\SONY\Reader\Data\bin\launcher\eBook Library Launcher.exe [902440 2009-07-03] (Sony Corporation) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2014-01-01] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1778640 2013-12-20] (APN) HKLM-x32\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Users\Thomas\AppData\Roaming\appConf32.exe,C:\Users\Thomas\AppData\Roaming\jabconf32.exe, [x] Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Facebook Update] - C:\Users\Thomas\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-22] (Facebook Inc.) Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± vË°!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL = BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL No File Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}: [NameServer]192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @sony.com/eBookLibrary - C:\Program Files (x86)\Sony\Reader\Data\bin\npebldetectmoz.dll (Sony Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Thomas\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2014-01-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-26] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2014-01-01] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] (APN LLC.) R2 bufssvr; C:\Program Files (x86)\BUFFALO\SLManagerEasy\Bufssvr.exe [90112 2010-03-12] (BUFFALO INC.) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [313840 2009-08-31] (Sonic Solutions) S2 Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [362992 2009-08-31] (Sonic Solutions) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [74496 2010-09-27] (Sony Corporation) R2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [864000 2010-09-27] (Sony Corporation) S3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1286784 2012-10-26] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R2 6077757b; C:\Windows\system32\drivers\regi.sys [14112 2007-04-17] (InterVideo) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-01-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-01-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG) S3 C2XXCOM; C:\Windows\System32\DRIVERS\C2XXCOM76.sys [49920 2010-08-09] (Samsung Electronics) S3 C2xxUSB; C:\Windows\System32\DRIVERS\C2xxUSB76.sys [46080 2010-11-04] (Samsung Electronics) S3 C2xxUsbStorage; C:\Windows\System32\DRIVERS\C2xSTR76.sys [9216 2010-06-10] (Samsung Electronics) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [28416 2008-04-16] (Research In Motion Limited) R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-11-12] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-07 03:01 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-07 03:01 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-07 03:01 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-01-07 03:01 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-01-07 03:01 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-01-07 03:01 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-01-07 03:01 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-07 03:01 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-07 03:01 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-01-07 03:01 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-01-07 03:01 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-07 03:01 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-01-07 03:01 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-01-07 03:01 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-01-07 03:01 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-01-07 03:01 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-01-07 03:01 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-01-07 03:01 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-07 03:01 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-01-07 03:01 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-01-07 03:01 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-01-07 03:01 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-07 03:01 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-07 03:01 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-01-07 03:01 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-01-07 03:01 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-07 03:01 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-07 03:01 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-01-07 03:01 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-01-07 03:01 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-01-07 03:01 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-01-06 17:38 - 2014-01-06 17:38 - 00000000 ____D C:\Program Files (x86)\ESET 2014-01-06 17:37 - 2014-01-06 17:38 - 02347384 _____ (ESET) C:\Users\Thomas\Downloads\esetsmartinstaller_enu.exe 2014-01-06 16:27 - 2014-01-06 16:27 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Thomas\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-06 14:05 - 2014-01-06 14:05 - 00025997 _____ C:\ComboFix.txt 2014-01-06 12:35 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-06 12:35 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-06 12:35 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-06 12:35 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-06 12:35 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-06 12:35 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-06 12:35 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-06 12:35 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-06 12:31 - 2014-01-06 14:05 - 00000000 ____D C:\Qoobox 2014-01-06 12:30 - 2014-01-06 13:06 - 00000000 ____D C:\Windows\erdnt 2014-01-04 01:19 - 2014-01-04 01:22 - 00000000 ____D C:\AdwCleaner 2014-01-03 03:02 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2014-01-03 03:02 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2014-01-03 03:02 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2014-01-03 03:02 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2014-01-03 01:03 - 2014-01-03 01:03 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf08172e6a9e70.job 2014-01-02 10:35 - 2014-01-07 05:33 - 00000000 ____D C:\Users\Thomas\Desktop\Viren-Beseitigung 2014-01-02 10:28 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-01-02 10:28 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-01-02 10:28 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-01-02 10:28 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2014-01-02 10:28 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-02 10:28 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2014-01-02 10:28 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2014-01-02 10:27 - 2014-01-02 10:27 - 00000286 ____H C:\Windows\Tasks\User_Feed_Synchronization-{D30B1914-6D71-46E4-813A-B2B3835BF810}.job 2014-01-02 10:27 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-01-02 10:27 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-01-02 10:27 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2014-01-02 10:27 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2014-01-02 10:27 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2014-01-02 10:27 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2014-01-02 10:27 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2014-01-02 10:27 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2014-01-02 10:27 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2014-01-02 10:27 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2014-01-02 10:27 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2014-01-02 10:27 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2014-01-02 03:09 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2014-01-02 03:04 - 2014-01-02 03:04 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-01-01 16:17 - 2014-01-02 03:09 - 00017589 _____ C:\Windows\IE11_main.log 2014-01-01 13:59 - 2014-01-06 15:30 - 00000000 ____D C:\FRST ==================== One Month Modified Files and Folders ======= 2014-01-07 05:33 - 2014-01-02 10:35 - 00000000 ____D C:\Users\Thomas\Desktop\Viren-Beseitigung 2014-01-07 05:33 - 2009-07-14 06:13 - 01507406 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-07 05:33 - 2009-01-01 02:56 - 00657910 _____ C:\Windows\system32\perfh007.dat 2014-01-07 05:33 - 2009-01-01 02:56 - 00131250 _____ C:\Windows\system32\perfc007.dat 2014-01-07 04:51 - 2009-01-01 03:02 - 01619923 _____ C:\Windows\WindowsUpdate.log 2014-01-07 03:25 - 2009-07-14 05:45 - 00013936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-07 03:25 - 2009-07-14 05:45 - 00013936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-07 03:21 - 2013-08-20 09:10 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Dropbox 2014-01-07 03:18 - 2009-01-01 18:26 - 00156458 _____ C:\Windows\setupact.log 2014-01-06 17:38 - 2014-01-06 17:38 - 00000000 ____D C:\Program Files (x86)\ESET 2014-01-06 17:38 - 2014-01-06 17:37 - 02347384 _____ (ESET) C:\Users\Thomas\Downloads\esetsmartinstaller_enu.exe 2014-01-06 17:25 - 2013-08-20 09:12 - 00000000 ___RD C:\Users\Thomas\Dropbox 2014-01-06 17:21 - 2009-01-01 03:00 - 00695710 _____ C:\Windows\PFRO.log 2014-01-06 17:03 - 2012-09-27 14:16 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-06 17:03 - 2012-09-27 14:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-06 16:27 - 2014-01-06 16:27 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Thomas\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-06 15:30 - 2014-01-01 13:59 - 00000000 ____D C:\FRST 2014-01-06 14:05 - 2014-01-06 14:05 - 00025997 _____ C:\ComboFix.txt 2014-01-06 14:05 - 2014-01-06 12:31 - 00000000 ____D C:\Qoobox 2014-01-06 13:50 - 2009-01-01 18:26 - 00000215 _____ C:\Windows\system.ini 2014-01-06 13:12 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2014-01-06 13:06 - 2014-01-06 12:30 - 00000000 ____D C:\Windows\erdnt 2014-01-06 12:47 - 2011-01-28 20:03 - 00000000 ____D C:\Users\Thomas 2014-01-04 01:22 - 2014-01-04 01:19 - 00000000 ____D C:\AdwCleaner 2014-01-04 01:22 - 2011-06-04 17:50 - 00000000 ____D C:\ProgramData\ICQ 2014-01-03 03:20 - 2009-07-14 05:45 - 00446640 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-03 03:01 - 2011-03-16 08:41 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-01-03 01:03 - 2014-01-03 01:03 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf08172e6a9e70.job 2014-01-02 10:27 - 2014-01-02 10:27 - 00000286 ____H C:\Windows\Tasks\User_Feed_Synchronization-{D30B1914-6D71-46E4-813A-B2B3835BF810}.job 2014-01-02 03:30 - 2011-01-28 20:04 - 00001421 _____ C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-02 03:24 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2014-01-02 03:09 - 2014-01-01 16:17 - 00017589 _____ C:\Windows\IE11_main.log 2014-01-02 03:04 - 2014-01-02 03:04 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-01-01 16:25 - 2013-08-21 11:33 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-01-01 16:25 - 2013-08-21 11:28 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-01-01 16:25 - 2013-08-21 11:28 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-01-01 16:04 - 2011-01-28 20:04 - 00000000 ___RD C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Some content of TEMP: ==================== C:\Users\Thomas\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-21 23:19 ==================== End Of Log ============================ |
08.01.2014, 00:47 | #14 |
/// TB-Ausbilder | Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht Etwas passt da noch nicht so ganz: Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\Thomas\AppData\Roaming\appConf32.exe C:\Users\Thomas\AppData\Roaming\jabconf32.exe Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon REG: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /f REG: reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /t REG_SZ /d c:\windows\system32\userinit.exe /f Unlock: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon REG: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /f REG: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /t REG_SZ /d userinit.exe /f Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Starte noch einmal FRST.
__________________ cheers, Leo |
08.01.2014, 12:19 | #15 |
| Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht Fixlog: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-01-2014 Ran by Thomas at 2014-01-08 12:15:53 Run:3 Running from C:\Users\Thomas\Desktop\Viren-Beseitigung Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\Thomas\AppData\Roaming\appConf32.exe C:\Users\Thomas\AppData\Roaming\jabconf32.exe Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon REG: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /f REG: reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /t REG_SZ /d c:\windows\system32\userinit.exe /f Unlock: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon REG: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /f REG: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /t REG_SZ /d userinit.exe /f ***************** "C:\Users\Thomas\AppData\Roaming\appConf32.exe" => File/Directory not found. "C:\Users\Thomas\AppData\Roaming\jabconf32.exe" => File/Directory not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" => Key unlocked successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /t REG_SZ /d c:\windows\system32\userinit.exe /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon" => Key unlocked successfully. ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /t REG_SZ /d userinit.exe /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ==== End of Fixlog ==== FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014 Ran by Thomas (administrator) on THOMAS-VAIO on 08-01-2014 12:16:31 Running from C:\Users\Thomas\Desktop\Viren-Beseitigung Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (BUFFALO INC.) C:\Program Files (x86)\BUFFALO\SLManagerEasy\Bufssvr.exe (BUFFALO INC.) C:\Program Files (x86)\BUFFALO\SLManagerEasy\Inputps.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (Microsoft Corporation) C:\Program Files\Zune\ZuneLauncher.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe (Facebook Inc.) C:\Users\Thomas\AppData\Local\Facebook\Update\FacebookUpdate.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Sony Corporation) C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Samsung Electronics.) C:\Program Files (x86)\Samsung Connection Manager\ModemPnPService.exe (Dropbox, Inc.) C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Sony Corporation) C:\Program Files (x86)\SONY\Reader\Data\bin\launcher\eBook Library Launcher.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Sony Corporation) C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Sony Corporation) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files (x86)\SONY\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9636896 2009-12-16] (Realtek Semiconductor) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [208384 2009-11-04] (Alps Electric Co., Ltd.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Java\jre6\bin\jusched.exe [171520 2009-01-01] (Sun Microsystems, Inc.) HKLM\...\Run: [Zune Launcher] - C:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-11-20] (Intel Corporation) HKLM-x32\...\Run: [ISBMgr.exe] - C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe [320880 2009-08-26] (Sony Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-01-13] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [MarketingTools] - C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe [26624 2009-01-01] (Sony Corporation) HKLM-x32\...\Run: [SHTtray.exe] - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe [99696 2010-09-10] (Sony Corporation) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254696 2011-06-09] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Blackcomb] - C:\Program Files (x86)\Samsung Connection Manager\ModemPnPService.exe [131072 2011-02-11] (Samsung Electronics.) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] () HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-02-18] (Apple Inc.) HKLM-x32\...\Run: [eBook Library Launcher] - C:\Program Files (x86)\SONY\Reader\Data\bin\launcher\eBook Library Launcher.exe [902440 2009-07-03] (Sony Corporation) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2014-01-01] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1778640 2013-12-20] (APN) HKLM-x32\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Users\Thomas\AppData\Roaming\appConf32.exe,C:\Users\Thomas\AppData\Roaming\jabconf32.exe, [x] Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Facebook Update] - C:\Users\Thomas\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-22] (Facebook Inc.) Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± vË°!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL = BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL No File Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}: [NameServer]192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\m2ghze7x.default FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @sony.com/eBookLibrary - C:\Program Files (x86)\Sony\Reader\Data\bin\npebldetectmoz.dll (Sony Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Thomas\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2014-01-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-26] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2014-01-01] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] (APN LLC.) R2 bufssvr; C:\Program Files (x86)\BUFFALO\SLManagerEasy\Bufssvr.exe [90112 2010-03-12] (BUFFALO INC.) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [313840 2009-08-31] (Sonic Solutions) S2 Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [362992 2009-08-31] (Sonic Solutions) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [74496 2010-09-27] (Sony Corporation) R2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [864000 2010-09-27] (Sony Corporation) S3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1286784 2012-10-26] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R2 6077757b; C:\Windows\system32\drivers\regi.sys [14112 2007-04-17] (InterVideo) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-01-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-01-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG) S3 C2XXCOM; C:\Windows\System32\DRIVERS\C2XXCOM76.sys [49920 2010-08-09] (Samsung Electronics) S3 C2xxUSB; C:\Windows\System32\DRIVERS\C2xxUSB76.sys [46080 2010-11-04] (Samsung Electronics) S3 C2xxUsbStorage; C:\Windows\System32\DRIVERS\C2xSTR76.sys [9216 2010-06-10] (Samsung Electronics) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [28416 2008-04-16] (Research In Motion Limited) R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-11-12] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-07 03:01 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-07 03:01 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-07 03:01 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-01-07 03:01 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-01-07 03:01 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-01-07 03:01 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-01-07 03:01 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-07 03:01 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-07 03:01 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-01-07 03:01 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-01-07 03:01 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-07 03:01 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-01-07 03:01 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-01-07 03:01 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-01-07 03:01 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-01-07 03:01 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-01-07 03:01 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-01-07 03:01 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-07 03:01 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-01-07 03:01 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-01-07 03:01 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-01-07 03:01 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-07 03:01 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-07 03:01 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-01-07 03:01 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-01-07 03:01 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-07 03:01 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-07 03:01 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-01-07 03:01 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-01-07 03:01 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-01-07 03:01 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-01-06 17:38 - 2014-01-06 17:38 - 00000000 ____D C:\Program Files (x86)\ESET 2014-01-06 17:37 - 2014-01-06 17:38 - 02347384 _____ (ESET) C:\Users\Thomas\Downloads\esetsmartinstaller_enu.exe 2014-01-06 16:27 - 2014-01-06 16:27 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Thomas\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-06 14:05 - 2014-01-06 14:05 - 00025997 _____ C:\ComboFix.txt 2014-01-06 12:35 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-06 12:35 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-06 12:35 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-06 12:35 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-06 12:35 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-06 12:35 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-06 12:35 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-06 12:35 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-06 12:31 - 2014-01-06 14:05 - 00000000 ____D C:\Qoobox 2014-01-06 12:30 - 2014-01-06 13:06 - 00000000 ____D C:\Windows\erdnt 2014-01-04 01:19 - 2014-01-04 01:22 - 00000000 ____D C:\AdwCleaner 2014-01-03 03:02 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2014-01-03 03:02 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2014-01-03 03:02 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2014-01-03 03:02 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2014-01-03 01:03 - 2014-01-03 01:03 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf08172e6a9e70.job 2014-01-02 10:35 - 2014-01-08 12:16 - 00000000 ____D C:\Users\Thomas\Desktop\Viren-Beseitigung 2014-01-02 10:28 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-01-02 10:28 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-01-02 10:28 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-01-02 10:28 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2014-01-02 10:28 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-02 10:28 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2014-01-02 10:28 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2014-01-02 10:27 - 2014-01-02 10:27 - 00000286 ____H C:\Windows\Tasks\User_Feed_Synchronization-{D30B1914-6D71-46E4-813A-B2B3835BF810}.job 2014-01-02 10:27 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-01-02 10:27 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-01-02 10:27 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2014-01-02 10:27 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2014-01-02 10:27 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2014-01-02 10:27 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2014-01-02 10:27 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2014-01-02 10:27 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2014-01-02 10:27 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2014-01-02 10:27 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2014-01-02 10:27 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2014-01-02 10:27 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2014-01-02 03:09 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2014-01-02 03:04 - 2014-01-02 03:04 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-01-01 16:17 - 2014-01-02 03:09 - 00017589 _____ C:\Windows\IE11_main.log 2014-01-01 13:59 - 2014-01-06 15:30 - 00000000 ____D C:\FRST ==================== One Month Modified Files and Folders ======= 2014-01-08 12:16 - 2014-01-02 10:35 - 00000000 ____D C:\Users\Thomas\Desktop\Viren-Beseitigung 2014-01-08 12:16 - 2009-01-01 03:02 - 01704351 _____ C:\Windows\WindowsUpdate.log 2014-01-08 12:14 - 2009-07-14 06:13 - 01507406 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-08 12:14 - 2009-01-01 02:56 - 00657910 _____ C:\Windows\system32\perfh007.dat 2014-01-08 12:14 - 2009-01-01 02:56 - 00131250 _____ C:\Windows\system32\perfc007.dat 2014-01-08 12:09 - 2013-08-20 09:12 - 00000000 ___RD C:\Users\Thomas\Dropbox 2014-01-08 12:09 - 2013-08-20 09:10 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Dropbox 2014-01-08 12:08 - 2009-01-01 18:26 - 00156738 _____ C:\Windows\setupact.log 2014-01-07 20:34 - 2012-03-03 21:28 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\UseNeXT 2014-01-07 20:30 - 2012-03-03 21:28 - 00000000 ____D C:\Users\Thomas\Documents\UseNeXT 2014-01-07 20:14 - 2009-07-14 05:45 - 00013936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-07 20:14 - 2009-07-14 05:45 - 00013936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-07 20:05 - 2012-03-26 15:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-01-07 05:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2014-01-06 17:38 - 2014-01-06 17:38 - 00000000 ____D C:\Program Files (x86)\ESET 2014-01-06 17:38 - 2014-01-06 17:37 - 02347384 _____ (ESET) C:\Users\Thomas\Downloads\esetsmartinstaller_enu.exe 2014-01-06 17:21 - 2009-01-01 03:00 - 00695710 _____ C:\Windows\PFRO.log 2014-01-06 17:03 - 2012-09-27 14:16 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-06 17:03 - 2012-09-27 14:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-06 16:27 - 2014-01-06 16:27 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Thomas\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-06 15:30 - 2014-01-01 13:59 - 00000000 ____D C:\FRST 2014-01-06 14:05 - 2014-01-06 14:05 - 00025997 _____ C:\ComboFix.txt 2014-01-06 14:05 - 2014-01-06 12:31 - 00000000 ____D C:\Qoobox 2014-01-06 13:50 - 2009-01-01 18:26 - 00000215 _____ C:\Windows\system.ini 2014-01-06 13:12 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2014-01-06 13:06 - 2014-01-06 12:30 - 00000000 ____D C:\Windows\erdnt 2014-01-06 12:47 - 2011-01-28 20:03 - 00000000 ____D C:\Users\Thomas 2014-01-04 01:22 - 2014-01-04 01:19 - 00000000 ____D C:\AdwCleaner 2014-01-04 01:22 - 2011-06-04 17:50 - 00000000 ____D C:\ProgramData\ICQ 2014-01-03 03:20 - 2009-07-14 05:45 - 00446640 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-03 03:01 - 2011-03-16 08:41 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-01-03 01:03 - 2014-01-03 01:03 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf08172e6a9e70.job 2014-01-02 10:27 - 2014-01-02 10:27 - 00000286 ____H C:\Windows\Tasks\User_Feed_Synchronization-{D30B1914-6D71-46E4-813A-B2B3835BF810}.job 2014-01-02 03:30 - 2011-01-28 20:04 - 00001421 _____ C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-02 03:24 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2014-01-02 03:09 - 2014-01-01 16:17 - 00017589 _____ C:\Windows\IE11_main.log 2014-01-02 03:04 - 2014-01-02 03:04 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-02 03:04 - 2014-01-02 03:04 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-01-02 03:04 - 2014-01-02 03:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-01-02 03:04 - 2014-01-02 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-01-02 03:04 - 2014-01-02 03:04 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-02 03:04 - 2014-01-02 03:04 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-01-01 16:25 - 2013-08-21 11:33 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-01-01 16:25 - 2013-08-21 11:28 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-01-01 16:25 - 2013-08-21 11:28 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-01-01 16:04 - 2011-01-28 20:04 - 00000000 ___RD C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Some content of TEMP: ==================== C:\Users\Thomas\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-21 23:19 ==================== End Of Log ============================ |
Themen zu Bundestrojaner, Reparatur über den abgesicherten Modus funktioniert nicht |
abgesicherten modus funktioniert nicht, adobe, antivir, association, avg, avira, browser, desktop, explorer, google, home, icq, icreinstall, logfile, microsoft, mindspark, monitor, opera, problem, realtek, registry, scan, server, services.exe, svchost.exe, system, temp, thomas, winlogon, winlogon.exe |