![]() |
|
Log-Analyse und Auswertung: Windows 7: 'Nation Zoom' auto-öffnet sich in allen BrowsernWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
|
![]() | #1 |
| ![]() Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern Frohes neues Jahr, Ähnlich wie in diesem Post [ http://www.trojaner-board.de/146908-...-browsern.html ], habe auch ich (bzw mein Vater) folgendes Problem: Nation-zoom (.com) öffnet sich automatisch sowohl beim Öffnen von Chrome, als auch beim Öffnen des Internet Explorers. Ich habe bereits (pro forma) versucht, die Startseite zu ändern, was nichts brachte. In den letzten Tagen wurde ein 7-zip file manager installiert, allerdings weiß mein Vater nicht mehr von welcher Seite, könnte also das Einfallstor gewesen sein. Der Virusscan zeigt nichts an. Schritt 1: Laufwerksemulationen abschalten mit Defogger -wurde gemacht Schritt 2: Systemscan mit FRST FRST : Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-01-2014 01 Ran by Hans Desktop PC (administrator) on HANSDESKTOPPC on 02-01-2014 13:01:26 Running from C:\Users\Hans Desktop PC\Downloads Windows 7 Professional N Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\eEBAPI\eEBSvc.exe (AVM GmbH) C:\Program Files (x86)\FRITZ!Powerline\PowerlineService.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe () C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe () D:\Program Files (x86)\Kies\Kies.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe () D:\Program Files (x86)\Kies\KiesTrayAgent.exe () D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation) C:\Windows\splwow64.exe () C:\Users\Hans Desktop PC\Downloads\Defogger.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [KiesTrayAgent] - D:\Program Files (x86)\Kies\KiesTrayAgent.exe HKLM-x32\...\Run: [NBAgent] - C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe [1493288 2012-01-13] (Nero AG) HKCU\...\Run: [KiesPreload] - D:\Program Files (x86)\Kies\Kies.exe /preload HKCU\...\Run: [] - D:\Program Files (x86)\Kies\External\FirmwareUpdate\KiesPDLR.exe Run HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2741616 2011-03-04] (Hewlett-Packard Company) HKCU\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\Hans Desktop PC\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.tagesschau.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x84E3C03977D6CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.nationzoom.com/?type=sc&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms} SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=NIS&chn=retail&geo=DE&ver=20&locale=de_DE&gct=sb&qsrc=2869 BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\IPS\IPSBHO.dll (Symantec Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation) DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Chrome: ======= CHR HomePage: hxxp://tagesschau.de/ CHR RestoreOnStartup: "hxxp://www.nationzoom.com/?type=hp&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B" CHR Extension: (Google Docs) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Extended Protection) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0 CHR Extension: (Google Search) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Lightning Newtab) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.1.7.9_0 CHR Extension: (Norton Identity Protection) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0 CHR Extension: (Google Wallet) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 CHR Extension: (MySearchDial __MSG_newtab__) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff\9.4.4_0 CHR Extension: (Gmail) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\HANSDE~1\AppData\Local\mysearchdial-speeddial.crx CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\Exts\Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\HANSDE~1\AppData\Local\mysearchdial-speeddial.crx CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.nationzoom.com/?type=sc&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B ==================== Services (Whitelisted) ================= R2 AVMPowerlineService; C:\Program Files (x86)\FRITZ!Powerline\PowerlineService.exe [126976 2013-10-11] (AVM GmbH) R2 EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\eEBAPI\eEBSVC.exe [90112 2004-11-17] (SEIKO EPSON CORPORATION) R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe [275696 2013-10-08] (Symantec Corporation) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143072 2012-07-04] (TuneUp Software) R2 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [248704 2013-08-14] () ==================== Drivers (Whitelisted) ==================== R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20131203.001\BHDrvx64.sys [1526488 2013-12-03] (Symantec Corporation) R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1501000.012\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-24] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-11-24] (Symantec Corporation) R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20140101.001\IDSvia64.sys [521944 2013-12-14] (Symantec Corporation) R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140101.021\ENG64.SYS [126040 2013-12-26] (Symantec Corporation) R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140101.021\EX64.SYS [2099288 2013-12-26] (Symantec Corporation) R1 SRTSP; C:\Windows\System32\Drivers\NISx64\1501000.012\SRTSP64.SYS [858200 2013-09-27] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1501000.012\SRTSPX64.SYS [36952 2013-09-10] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NISx64\1501000.012\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NISx64\1501000.012\SYMEFA64.SYS [1147480 2013-09-27] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-14] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1501000.012\Ironx64.SYS [264280 2013-09-27] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1501000.012\SYMNETS.SYS [590936 2013-09-26] (Symantec Corporation) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2012-05-03] (TuneUp Software) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-02 13:01 - 2014-01-02 13:01 - 00015190 _____ C:\Users\Hans Desktop PC\Downloads\FRST.txt 2014-01-02 13:01 - 2014-01-02 13:01 - 00000000 ____D C:\FRST 2014-01-02 13:00 - 2014-01-02 13:00 - 01931426 _____ (Farbar) C:\Users\Hans Desktop PC\Downloads\FRST64.exe 2014-01-02 12:59 - 2014-01-02 12:59 - 00000492 _____ C:\Users\Hans Desktop PC\Downloads\defogger_disable.log 2014-01-02 12:59 - 2014-01-02 12:59 - 00000000 _____ C:\Users\Hans Desktop PC\defogger_reenable 2014-01-02 12:58 - 2014-01-02 12:58 - 00050477 _____ C:\Users\Hans Desktop PC\Downloads\Defogger.exe 2014-01-02 11:53 - 2014-01-02 11:53 - 00002770 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 2014-01-02 11:32 - 2014-01-02 11:35 - 00003990 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{8C789A6B-65A8-4A76-A311-F27A13C4B32B} 2014-01-01 17:51 - 2014-01-01 17:52 - 00063044 _____ C:\Users\Hans Desktop PC\Downloads\Bravo Hits - Vol. 32.rar.nzb 2014-01-01 15:12 - 2014-01-01 15:16 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Mp3tag 2014-01-01 14:57 - 2014-01-02 12:03 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\newnext.me 2014-01-01 14:57 - 2014-01-01 14:59 - 00000000 ____D C:\ProgramData\WPM 2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\genienext 2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\.android 2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Program Files (x86)\7-Zip 2014-01-01 14:44 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero 2014-01-01 13:24 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero_AG 2014-01-01 11:57 - 2014-01-01 11:57 - 00000000 ____D C:\Program Files (x86)\MarkAny 2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Nero 2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\ProgramData\LightScribe 2014-01-01 11:44 - 2014-01-01 11:44 - 00002213 _____ C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk 2014-01-01 11:44 - 2014-01-01 11:44 - 00002193 _____ C:\Users\Public\Desktop\TuneUp Utilities 2012.lnk 2014-01-01 11:44 - 2014-01-01 11:44 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2012 2014-01-01 11:44 - 2012-07-04 10:49 - 00034656 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2014-01-01 11:44 - 2012-07-04 10:49 - 00025952 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2014-01-01 11:44 - 2012-07-04 10:49 - 00021344 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll 2014-01-01 11:16 - 2014-01-01 11:37 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CrashDumps 2013-12-31 11:13 - 2014-01-02 11:27 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-Q5-TTL.DAT 2013-12-24 19:01 - 2013-12-24 19:02 - 00259770 _____ C:\Windows\msxml4-KB2758694-enu.LOG 2013-12-24 18:38 - 2013-12-24 18:38 - 02634152 _____ C:\Users\Hans Desktop PC\Downloads\mp3tagv258setup.exe 2013-12-24 18:38 - 2013-12-24 18:38 - 00000983 _____ C:\Users\Public\Desktop\Mp3tag.lnk 2013-12-24 18:38 - 2013-12-24 18:38 - 00000000 ____D C:\Program Files (x86)\Mp3tag 2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Hausverwalter 2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl Data Service 2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl Data Service 2013-12-24 11:13 - 2013-12-24 11:13 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2013-12-22 17:38 - 2013-12-22 17:38 - 00001181 _____ C:\Users\Public\Desktop\MAGIX Video easy TERRATEC Edition.lnk 2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\MAGIX 2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\ProgramData\MAGIX 2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Program Files (x86)\MAGIX 2013-12-22 17:37 - 2013-12-22 17:37 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0 2013-12-22 17:34 - 2013-12-22 17:36 - 211870088 _____ (MAGIX AG) C:\Users\Hans Desktop PC\Downloads\MAGIX_Video_easy_TERRATEC_Edition.exe 2013-12-22 17:34 - 2013-12-22 17:34 - 00000000 ____D C:\ProgramData\CMUV 2013-12-22 17:33 - 2013-12-22 17:33 - 00000000 ____D C:\Program Files\DIFX 2013-12-22 17:32 - 2013-12-22 17:32 - 00000000 ____D C:\Program Files (x86)\TERRATEC 2013-12-22 17:29 - 2013-12-22 17:32 - 03311568 _____ C:\Users\Hans Desktop PC\Downloads\TERRATEC_CINERGY_HTC_Stick_HD_Driver_Setup_7.0.122.90_XP_Vista_7_8.exe 2013-12-22 17:28 - 2013-12-22 17:28 - 00001137 _____ C:\Users\Hans Desktop PC\Desktop\DVBViewer TERRATEC Edition.lnk 2013-12-22 17:28 - 2013-12-22 17:28 - 00000000 ____D C:\Program Files (x86)\DVBViewer TERRATEC Edition 2013-12-22 16:51 - 2013-12-22 16:51 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\TuneUp Software 2013-12-22 16:50 - 2013-12-22 16:51 - 00000000 ____D C:\ProgramData\TuneUp Software 2013-12-22 16:50 - 2013-12-22 16:50 - 00000000 __SHD C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936} 2013-12-22 15:54 - 2013-12-22 15:54 - 00002881 _____ C:\Users\Public\Desktop\Nero 11.lnk 2013-12-22 15:54 - 2013-12-22 15:54 - 00002797 _____ C:\Users\Public\Desktop\Nero Video 11.lnk 2013-12-22 15:54 - 2013-12-22 15:54 - 00002783 _____ C:\Users\Public\Desktop\Nero BackItUp 11.lnk 2013-12-22 15:54 - 2013-12-22 15:54 - 00002109 _____ C:\Users\Public\Desktop\Nero Kwik Media.lnk 2013-12-22 15:53 - 2013-12-22 15:53 - 00002843 _____ C:\Users\Public\Desktop\Nero Burning ROM 11.lnk 2013-12-22 15:52 - 2013-12-22 16:01 - 00000000 ____D C:\ProgramData\Nero 2013-12-22 15:10 - 2013-12-22 15:56 - 00000000 ____D C:\Program Files (x86)\Nero 2013-12-22 15:10 - 2011-12-01 11:42 - 00072240 _____ (Nero AG) C:\Windows\system32\Drivers\NBVol.sys 2013-12-22 15:10 - 2011-12-01 11:42 - 00015920 _____ (Nero AG) C:\Windows\system32\Drivers\NBVolUp.sys 2013-12-22 15:04 - 2013-12-22 15:04 - 00002037 _____ C:\Users\Public\Desktop\LightScribe.lnk 2013-12-22 15:04 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2013-12-22 15:04 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2013-12-22 15:04 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2013-12-22 15:04 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2013-12-22 15:04 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2013-12-22 15:03 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2013-12-22 15:03 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2013-12-22 15:03 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2013-12-22 15:03 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2013-12-22 15:03 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2013-12-22 15:03 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll 2013-12-18 16:56 - 2013-12-25 11:15 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mein Steuer-Sparbuch Heute 2013-12-15 16:46 - 2013-12-15 16:46 - 00001000 _____ C:\Users\Public\Desktop\WISO Hausverwalter 2014.lnk 2013-12-15 16:34 - 2013-12-15 16:34 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl 2013-12-15 12:45 - 2013-12-24 11:46 - 00000651 _____ C:\Windows\wiso.ini 2013-12-15 12:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl 2013-12-15 12:45 - 2013-12-15 12:45 - 00000986 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2014.lnk 2013-12-15 12:12 - 2013-12-24 11:45 - 00000000 ____D C:\ProgramData\Buhl Data Service GmbH 2013-12-11 17:08 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-11 17:08 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-11 17:08 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-11 17:08 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-11 17:07 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-11 17:07 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-11 17:07 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-11 17:07 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-11 17:07 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-11 17:07 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-11 17:07 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-11 17:07 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-11 17:07 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-11 17:07 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-11 17:07 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-11 17:07 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-11 17:07 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-11 17:07 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-11 17:07 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-11 17:07 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-11 17:07 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-11 17:07 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-11 17:07 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-11 17:07 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-11 17:07 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-11 17:07 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-11 17:07 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-11 17:07 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-11 17:07 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-11 17:07 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-11 17:07 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-11 17:07 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-11 17:07 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-11 17:07 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-11 17:07 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-11 15:22 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-11 15:22 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-11 15:22 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-11 15:22 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-11 15:22 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-11 15:22 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-11 15:22 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 15:22 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 15:22 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-11 15:22 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 15:22 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 15:22 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-11 15:22 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-11 15:22 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 15:22 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 15:22 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-11 15:22 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-11 15:22 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 15:22 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-04 19:13 - 2014-01-02 11:27 - 00000100 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WB.CFG 2013-12-04 19:13 - 2014-01-02 11:27 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-TTL.DAT 2013-12-03 12:19 - 2013-12-03 12:20 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CUSTPDF Writer 2013-12-03 12:14 - 2014-01-01 14:58 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Mobogenie 2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\wangzhisong\AppData\Local\Mobogenie 2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\wangzhisong 2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mobogenie 2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\cache 2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 _____ C:\Users\Hans Desktop PC\daemonprocess.txt 2013-12-03 12:13 - 2014-01-02 12:13 - 00000318 _____ C:\Windows\Tasks\DigitalSite.job 2013-12-03 12:13 - 2014-01-01 14:58 - 00000000 ____D C:\Program Files (x86)\Mobogenie 2013-12-03 12:13 - 2013-12-03 12:13 - 00351124 _____ C:\Users\Hans Desktop PC\AppData\Local\mysearchdial-speeddial.crx 2013-12-03 12:13 - 2013-12-03 12:13 - 00003288 _____ C:\Windows\System32\Tasks\DigitalSite 2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\DigitalSite 2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\0D0S1L2Z1P1B 2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Program Files\PDFCreator 2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Program Files (x86)\GPLGS 2013-12-03 12:13 - 2011-10-04 22:43 - 00087552 _____ C:\Windows\system32\custmon64i.dll 2013-12-03 12:12 - 2013-12-03 12:12 - 01295288 _____ C:\Users\Hans Desktop PC\Downloads\PDFCreatorSetup.exe ==================== One Month Modified Files and Folders ======= 2014-01-02 13:01 - 2014-01-02 13:01 - 00015190 _____ C:\Users\Hans Desktop PC\Downloads\FRST.txt 2014-01-02 13:01 - 2014-01-02 13:01 - 00000000 ____D C:\FRST 2014-01-02 13:00 - 2014-01-02 13:00 - 01931426 _____ (Farbar) C:\Users\Hans Desktop PC\Downloads\FRST64.exe 2014-01-02 12:59 - 2014-01-02 12:59 - 00000492 _____ C:\Users\Hans Desktop PC\Downloads\defogger_disable.log 2014-01-02 12:59 - 2014-01-02 12:59 - 00000000 _____ C:\Users\Hans Desktop PC\defogger_reenable 2014-01-02 12:59 - 2013-10-31 19:40 - 00000000 ____D C:\Users\Hans Desktop PC 2014-01-02 12:58 - 2014-01-02 12:58 - 00050477 _____ C:\Users\Hans Desktop PC\Downloads\Defogger.exe 2014-01-02 12:28 - 2013-11-01 18:59 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-02 12:13 - 2013-12-03 12:13 - 00000318 _____ C:\Windows\Tasks\DigitalSite.job 2014-01-02 12:09 - 2009-07-14 05:50 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-02 12:09 - 2009-07-14 05:50 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-02 12:07 - 2011-04-12 09:14 - 00653928 _____ C:\Windows\system32\perfh007.dat 2014-01-02 12:07 - 2011-04-12 09:14 - 00129800 _____ C:\Windows\system32\perfc007.dat 2014-01-02 12:07 - 2009-07-14 06:12 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-02 12:05 - 2013-10-31 19:36 - 01701272 _____ C:\Windows\WindowsUpdate.log 2014-01-02 12:04 - 2013-11-03 19:48 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-02 12:04 - 2013-11-03 19:48 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-02 12:03 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\newnext.me 2014-01-02 12:02 - 2013-10-31 19:44 - 00000000 _____ C:\Windows\system32\Drivers\lvuvc.hs 2014-01-02 12:02 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-02 12:02 - 2009-07-14 05:56 - 00037809 _____ C:\Windows\setupact.log 2014-01-02 11:53 - 2014-01-02 11:53 - 00002770 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 2014-01-02 11:35 - 2014-01-02 11:32 - 00003990 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{8C789A6B-65A8-4A76-A311-F27A13C4B32B} 2014-01-02 11:27 - 2013-12-31 11:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-Q5-TTL.DAT 2014-01-02 11:27 - 2013-12-04 19:13 - 00000100 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WB.CFG 2014-01-02 11:27 - 2013-12-04 19:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-TTL.DAT 2014-01-02 10:28 - 2010-11-21 04:47 - 00049552 _____ C:\Windows\PFRO.log 2014-01-01 17:52 - 2014-01-01 17:51 - 00063044 _____ C:\Users\Hans Desktop PC\Downloads\Bravo Hits - Vol. 32.rar.nzb 2014-01-01 15:16 - 2014-01-01 15:12 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Mp3tag 2014-01-01 14:59 - 2014-01-01 14:57 - 00000000 ____D C:\ProgramData\WPM 2014-01-01 14:58 - 2013-12-03 12:14 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Mobogenie 2014-01-01 14:58 - 2013-12-03 12:13 - 00000000 ____D C:\Program Files (x86)\Mobogenie 2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\genienext 2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\.android 2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Program Files (x86)\7-Zip 2014-01-01 14:57 - 2013-11-03 19:48 - 00002373 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-01 14:57 - 2013-10-31 19:41 - 00001635 _____ C:\Users\Hans Desktop PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-01 14:44 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero 2014-01-01 14:44 - 2014-01-01 13:24 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero_AG 2014-01-01 11:58 - 2013-11-01 19:08 - 00000793 _____ C:\Users\Public\Desktop\Samsung Kies (Lite).lnk 2014-01-01 11:57 - 2014-01-01 11:57 - 00000000 ____D C:\Program Files (x86)\MarkAny 2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Nero 2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\ProgramData\LightScribe 2014-01-01 11:44 - 2014-01-01 11:44 - 00002213 _____ C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk 2014-01-01 11:44 - 2014-01-01 11:44 - 00002193 _____ C:\Users\Public\Desktop\TuneUp Utilities 2012.lnk 2014-01-01 11:44 - 2014-01-01 11:44 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2012 2014-01-01 11:37 - 2014-01-01 11:16 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CrashDumps 2013-12-25 11:15 - 2013-12-18 16:56 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mein Steuer-Sparbuch Heute 2013-12-24 19:02 - 2013-12-24 19:01 - 00259770 _____ C:\Windows\msxml4-KB2758694-enu.LOG 2013-12-24 18:38 - 2013-12-24 18:38 - 02634152 _____ C:\Users\Hans Desktop PC\Downloads\mp3tagv258setup.exe 2013-12-24 18:38 - 2013-12-24 18:38 - 00000983 _____ C:\Users\Public\Desktop\Mp3tag.lnk 2013-12-24 18:38 - 2013-12-24 18:38 - 00000000 ____D C:\Program Files (x86)\Mp3tag 2013-12-24 11:46 - 2013-12-15 12:45 - 00000651 _____ C:\Windows\wiso.ini 2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Hausverwalter 2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl Data Service 2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl Data Service 2013-12-24 11:45 - 2013-12-15 12:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl 2013-12-24 11:45 - 2013-12-15 12:12 - 00000000 ____D C:\ProgramData\Buhl Data Service GmbH 2013-12-24 11:13 - 2013-12-24 11:13 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2013-12-24 10:14 - 2013-10-31 19:40 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\VirtualStore 2013-12-22 18:12 - 2013-10-31 21:27 - 00154336 _____ C:\Users\Hans Desktop PC\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-22 17:42 - 2009-07-14 05:50 - 00507536 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-22 17:38 - 2013-12-22 17:38 - 00001181 _____ C:\Users\Public\Desktop\MAGIX Video easy TERRATEC Edition.lnk 2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\MAGIX 2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\ProgramData\MAGIX 2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Program Files (x86)\MAGIX 2013-12-22 17:37 - 2013-12-22 17:37 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0 2013-12-22 17:36 - 2013-12-22 17:34 - 211870088 _____ (MAGIX AG) C:\Users\Hans Desktop PC\Downloads\MAGIX_Video_easy_TERRATEC_Edition.exe 2013-12-22 17:34 - 2013-12-22 17:34 - 00000000 ____D C:\ProgramData\CMUV 2013-12-22 17:33 - 2013-12-22 17:33 - 00000000 ____D C:\Program Files\DIFX 2013-12-22 17:33 - 2013-10-31 23:07 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-12-22 17:32 - 2013-12-22 17:32 - 00000000 ____D C:\Program Files (x86)\TERRATEC 2013-12-22 17:32 - 2013-12-22 17:29 - 03311568 _____ C:\Users\Hans Desktop PC\Downloads\TERRATEC_CINERGY_HTC_Stick_HD_Driver_Setup_7.0.122.90_XP_Vista_7_8.exe 2013-12-22 17:28 - 2013-12-22 17:28 - 00001137 _____ C:\Users\Hans Desktop PC\Desktop\DVBViewer TERRATEC Edition.lnk 2013-12-22 17:28 - 2013-12-22 17:28 - 00000000 ____D C:\Program Files (x86)\DVBViewer TERRATEC Edition 2013-12-22 17:27 - 2013-11-01 19:01 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Downloaded Installations 2013-12-22 16:51 - 2013-12-22 16:51 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\TuneUp Software 2013-12-22 16:51 - 2013-12-22 16:50 - 00000000 ____D C:\ProgramData\TuneUp Software 2013-12-22 16:50 - 2013-12-22 16:50 - 00000000 __SHD C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936} 2013-12-22 16:01 - 2013-12-22 15:52 - 00000000 ____D C:\ProgramData\Nero 2013-12-22 15:56 - 2013-12-22 15:10 - 00000000 ____D C:\Program Files (x86)\Nero 2013-12-22 15:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Cursors 2013-12-22 15:54 - 2013-12-22 15:54 - 00002881 _____ C:\Users\Public\Desktop\Nero 11.lnk 2013-12-22 15:54 - 2013-12-22 15:54 - 00002797 _____ C:\Users\Public\Desktop\Nero Video 11.lnk 2013-12-22 15:54 - 2013-12-22 15:54 - 00002783 _____ C:\Users\Public\Desktop\Nero BackItUp 11.lnk 2013-12-22 15:54 - 2013-12-22 15:54 - 00002109 _____ C:\Users\Public\Desktop\Nero Kwik Media.lnk 2013-12-22 15:53 - 2013-12-22 15:53 - 00002843 _____ C:\Users\Public\Desktop\Nero Burning ROM 11.lnk 2013-12-22 15:04 - 2013-12-22 15:04 - 00002037 _____ C:\Users\Public\Desktop\LightScribe.lnk 2013-12-15 19:30 - 2013-11-01 19:08 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Samsung 2013-12-15 16:46 - 2013-12-15 16:46 - 00001000 _____ C:\Users\Public\Desktop\WISO Hausverwalter 2014.lnk 2013-12-15 16:34 - 2013-12-15 16:34 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl 2013-12-15 12:45 - 2013-12-15 12:45 - 00000986 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2014.lnk 2013-12-15 12:08 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-12-15 00:13 - 2013-11-03 19:48 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Google 2013-12-14 17:34 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-11 17:08 - 2013-10-31 20:26 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-11 15:28 - 2013-11-01 18:59 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-11 15:28 - 2013-11-01 18:59 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-11 15:28 - 2013-11-01 18:59 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-08 17:20 - 2013-10-31 23:34 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\ChessBase 2013-12-08 11:59 - 2013-11-03 19:48 - 00004124 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-08 11:59 - 2013-11-03 19:48 - 00003872 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-12-03 12:20 - 2013-12-03 12:19 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CUSTPDF Writer 2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\wangzhisong\AppData\Local\Mobogenie 2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\wangzhisong 2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mobogenie 2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\cache 2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 _____ C:\Users\Hans Desktop PC\daemonprocess.txt 2013-12-03 12:13 - 2013-12-03 12:13 - 00351124 _____ C:\Users\Hans Desktop PC\AppData\Local\mysearchdial-speeddial.crx 2013-12-03 12:13 - 2013-12-03 12:13 - 00003288 _____ C:\Windows\System32\Tasks\DigitalSite 2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\DigitalSite 2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\0D0S1L2Z1P1B 2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Program Files\PDFCreator 2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Program Files (x86)\GPLGS 2013-12-03 12:12 - 2013-12-03 12:12 - 01295288 _____ C:\Users\Hans Desktop PC\Downloads\PDFCreatorSetup.exe Some content of TEMP: ==================== C:\Users\Hans Desktop PC\AppData\Local\Temp\opsrnrpevolrwo.exe C:\Users\Hans Desktop PC\AppData\Local\Temp\TUUUninstallHelper.exe C:\Users\Hans Desktop PC\AppData\Local\Temp\twnplxhj.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit Addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-01-2014 01 Ran by Hans Desktop PC at 2014-01-02 13:01:48 Running from C:\Users\Hans Desktop PC\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Norton Internet Security (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Internet Security (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} ==================== Installed Programs ====================== 7-Zip 9.20 (x32 Version: - ) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05 - Adobe Systems Incorporated) Alt.Binz Prepaid Usenet edition Version 0.39.14 (x32 Version: 0.39.14 - Prepaid usenet) ChessBase 12 64-bit (Version: 12.0.0.0 - ChessBase) DRAGON 1.7 (x32 Version: 1.7 - PREPAID-USENET LIMITED) DVBViewer TERRATEC Edition (x32 Version: - CM&V) EPSON Scan (x32 Version: - ) EPSON Speed Dial Utility (x32 Version: 3.0.202 - SEIKO EPSON CORP.) Epson Universal Laser P6 (Version: - ) EPSON-Drucker-Software (Version: - ) EpsonNet Config V2 (x32 Version: 2.2b - SEIKO EPSON CORPORATION) EpsonNet SetupManager (x32 Version: 1.5.dE - SEIKO EPSON CORPORATION) EpsonNet SetupManager (x32 Version: 1.5.dE - SEIKO EPSON CORPORATION) Hidden eWallet 7.4.3 for Windows PCs (x32 Version: 7.4.3 - Ilium Software) Fritz 13 (x32 Version: 13.0.0.0 - ChessBase) FRITZ!Powerline (x32 Version: 01.00.54 - AVM Berlin) Google Chrome (x32 Version: 31.0.1650.63 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Toolbar for Internet Explorer (x32 Version: 7.5.4805.320 - Google Inc.) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden High-Definition Video Playback (x32 Version: 11.1.11100.4.196 - Nero AG) Hidden Houdini 3 Pro (x32 Version: 13.12.0.0 - ChessBase) K-Lite Codec Pack 10.1.0 Full (x32 Version: 10.1.0 - ) LightScribe System Software (x32 Version: 1.18.22.2 - LightScribe) Magic DVD Copier Version 4.9 build 5 (x32 Version: - Magic DVD Software, Inc.) MAGIX Video easy TERRATEC Edition (Version: 3.0.1.50 - MAGIX AG) Hidden MAGIX Video easy TERRATEC Edition (x32 Version: 3.0.1.50 - MAGIX AG) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Mp3tag v2.58 (x32 Version: v2.58 - Florian Heidenreich) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0 - Microsoft Corporation) MyFreeCodec (HKCU Version: - ) Nero 11 Cliparts (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden Nero 11 Disc Menus 1 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden Nero 11 Disc Menus 2 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden Nero 11 Disc Menus 3 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden Nero 11 Disc Menus Basic (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden Nero 11 Effects Basic (x32 Version: 11.0.11400.14.0 - Nero AG) Hidden Nero 11 Image Samples (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden Nero 11 Kwik Themes 1 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden Nero 11 Kwik Themes 2 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden Nero 11 Kwik Themes 3 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden Nero 11 Kwik Themes 4 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden Nero 11 Kwik Themes Basic (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden Nero 11 PiP Effects 1 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden Nero 11 PiP Effects Basic (x32 Version: 11.0.11400.14.0 - Nero AG) Hidden Nero 11 Platinum (x32 Version: 11.2.00700 - Nero AG) Nero 11 Video Samples (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden Nero 11 Video Transitions 1 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden Nero Audio Pack 1 (x32 Version: 11.0.11500.110.0 - Nero AG) Hidden Nero BackItUp 11 (x32 Version: 6.2.18400.2.100 - Nero AG) Hidden Nero BackItUp 11 Help (CHM) (x32 Version: 11.0.10400 - Nero AG) Hidden Nero Backup Drivers (Version: 1.0.11100.8.0 - Nero AG) Nero Burning ROM 11 (x32 Version: 11.2.10300.0.0 - Nero AG) Hidden Nero Burning ROM 11 Help (CHM) (x32 Version: 11.0.10300 - Nero AG) Hidden Nero ControlCenter 11 (x32 Version: 11.0.12700.0.27 - Nero AG) Hidden Nero ControlCenter 11 Help (CHM) (x32 Version: 11.0.10300 - Nero AG) Hidden Nero Core Components 11 (x32 Version: 11.0.16300.1.23 - Nero AG) Hidden Nero CoverDesigner 11 (x32 Version: 6.0.11000.13.100 - Nero AG) Hidden Nero CoverDesigner 11 Help (CHM) (x32 Version: 11.0.10300 - Nero AG) Hidden Nero Express 11 (x32 Version: 11.2.10300.0.0 - Nero AG) Hidden Nero Express 11 Help (CHM) (x32 Version: 11.0.10300 - Nero AG) Hidden Nero Kwik Media (x32 Version: 1.10.24800.146.100 - Nero AG) Hidden Nero Kwik Media Help (CHM) (x32 Version: 11.0.10200 - Nero AG) Hidden Nero Recode 11 (x32 Version: 5.2.10900.0.0 - Nero AG) Hidden Nero Recode 11 Help (CHM) (x32 Version: 11.0.10600 - Nero AG) Hidden Nero RescueAgent 11 (x32 Version: 4.0.10600.10.100 - Nero AG) Hidden Nero RescueAgent 11 Help (CHM) (x32 Version: 11.0.10400 - Nero AG) Hidden Nero SharedVideoCodecs (x32 Version: 1.0.11500.1.5 - Nero AG) Hidden Nero SoundTrax 11 (x32 Version: 5.0.10700.6.100 - Nero AG) Hidden Nero SoundTrax 11 Help (CHM) (x32 Version: 11.0.10400 - Nero AG) Hidden Nero Update (x32 Version: 11.0.11500.28.0 - Nero AG) Hidden Nero Video 11 (x32 Version: 8.2.15700.3.100 - Nero AG) Hidden Nero Video 11 Help (CHM) (x32 Version: 11.0.10300 - Nero AG) Hidden Nero WaveEditor 11 (x32 Version: 6.2.11300.0.100 - Nero AG) Hidden Nero WaveEditor 11 Help (CHM) (x32 Version: 11.0.10400 - Nero AG) Hidden nero.prerequisites.msi (x32 Version: 11.0.20010 - Nero AG) Hidden Norton Internet Security (x32 Version: 21.1.0.18 - Symantec Corporation) PDF Creator (Version: - ) PDF Creator Packages (HKCU Version: - ) Samsung Kies (x32 Version: 2.6.1.13105_6 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.6.1.13105_6 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (Version: 1.5.29.0 - SAMSUNG Electronics Co., Ltd.) Synology Assistant (remove only) (x32 Version: - ) TERRATEC CINERGY HTC Stick HD (64Bit) (x32 Version: 7.0.122.90 - TERRATEC) TERRATEC CINERGY HTC Stick HD (x32 Version: 7.0.122.90 - TERRATEC) TuneUp Utilities 2012 (x32 Version: 12.0.3600.114 - TuneUp Software) TuneUp Utilities 2012 (x32 Version: 12.0.3600.114 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.114 - TuneUp Software) Hidden Update for 2007 Microsoft Office System (KB967642) (x32 Version: - Microsoft) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition (x32 Version: - Microsoft) Update for PDF Creator (HKCU Version: - ) <==== ATTENTION Update für Microsoft Office Excel 2007 Help (KB963678) (x32 Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (x32 Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32 Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (x32 Version: - Microsoft) Welcome App (Start-up experience) (x32 Version: 11.0.23500.0.0 - Nero AG) Hidden Windows-Treiberpaket - TERRATEC (CXIR) HIDClass (06/04/2013 7.0.122.9) (Version: 06/04/2013 7.0.122.9 - TERRATEC) Windows-Treiberpaket - TERRATEC (CXPOLARIS) Media (06/04/2013 7.0.122.9) (Version: 06/04/2013 7.0.122.9 - TERRATEC) WISO Hausverwalter 2014 (x32 Version: 8.00.8332 - Buhl Data Service GmbH) WISO Steuer-Sparbuch 2014 (x32 Version: 21.00.8480 - Buhl Data Service GmbH) ==================== Restore Points ========================= 01-01-2014 12:51:07 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {1D9BBA07-34D3-4EEE-93E8-03513A16D453} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {3E804A6C-C97E-4DCE-B4E4-518162A21706} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\symerr.exe [2013-08-01] (Symantec Corporation) Task: {42926C80-5756-4BC0-B43B-84C1D7B75D96} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-03] (Google Inc.) Task: {54D916DD-808F-43F0-94F5-EB42E960B7FD} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe [2012-07-04] (TuneUp Software) Task: {85D5354C-5AA1-426B-AD66-5CCC71F65602} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\symerr.exe [2013-08-01] (Symantec Corporation) Task: {AD3516DE-A407-4723-9697-36A1F9E93AB0} - System32\Tasks\DigitalSite => C:\Users\Hans Desktop PC\AppData\Roaming\DigitalSite\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {C5C94D19-5421-4B9B-8B21-788D065F45B2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated) Task: {C7AE8B62-AE23-4FEC-BA85-145B9241F746} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\WSCStub.exe [2013-10-08] (Symantec Corporation) Task: {E3B687E7-6B87-4064-B2FC-FD3B55EC102E} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-09-05] (Adobe Systems Incorporated) Task: {E666C32A-9E5C-4F5C-AFFC-002E80FAFEE7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-03] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe <==== ATTENTION Task: C:\Windows\Tasks\DigitalSite.job => C:\Users\HANSDE~1\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2011-03-04 12:02 - 2011-03-04 12:02 - 02121728 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll 2011-03-04 12:02 - 2011-03-04 12:02 - 07745536 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll 2011-03-04 12:02 - 2011-03-04 12:02 - 00135168 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll 2013-12-08 12:07 - 2013-12-04 03:47 - 00702416 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libglesv2.dll 2013-12-08 12:07 - 2013-12-04 03:47 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libegl.dll 2013-12-08 12:07 - 2013-12-04 03:48 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-08 12:07 - 2013-12-04 03:48 - 00399312 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-08 12:07 - 2013-12-04 03:47 - 01619408 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll 2013-12-08 12:07 - 2013-12-04 03:48 - 13586896 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll 2013-07-10 18:07 - 2013-07-10 18:07 - 00756888 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Standardtastatur (PS/2) Description: Standardtastatur (PS/2) Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standardtastaturen) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Cinergy HTC USB XS Description: Cinergy HTC USB XS Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Microsoft PS/2-Maus Description: Microsoft PS/2-Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (01/02/2014 00:04:33 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/02/2014 10:29:50 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/01/2014 03:10:57 PM) (Source: .NET Runtime) (User: ) Description: .NET Runtime version 4.0.30319.1008 - Fehler beim Initialisieren der Profilerstellungs-API-Anfügeinfrastruktur. Dieser Prozess ermöglicht einem Profiler das Anfügen nicht. HRESULT: 0x80004005. Prozess-ID (dezimal): 2232. Meldungs-ID: [0x2509]. Error: (01/01/2014 01:32:41 PM) (Source: .NET Runtime Optimization Service) (User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: D:\Program Files (x86)\Kies\Kies.exe . Error code = 0x800700d8 Error: (01/01/2014 01:32:41 PM) (Source: .NET Runtime Optimization Service) (User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: D:\Program Files (x86)\Kies\Kies.exe . Error code = 0x800700d8 Error: (01/01/2014 11:57:15 AM) (Source: .NET Runtime) (User: ) Description: Anwendung: Kies.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.NullReferenceException Stapel: bei Kies.Plugin.DeviceHost.DeviceHostVM.threadOutlookFolder(System.Object) bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) bei System.Threading.ThreadHelper.ThreadStart(System.Object) Error: (01/01/2014 11:45:37 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16428, Zeitstempel: 0x525b664c Name des fehlerhaften Moduls: nvwgf2um.dll, Version: 8.15.11.8593, Zeitstempel: 0x4a5be117 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000423de ID des fehlerhaften Prozesses: 0xdf4 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (01/01/2014 11:36:47 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: OneClick.exe, Version: 12.0.3600.114, Zeitstempel: 0x4ff402dc Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1116 Ausnahmecode: 0x0eedfade Fehleroffset: 0x0000c41f ID des fehlerhaften Prozesses: 0x103c Startzeit der fehlerhaften Anwendung: 0xOneClick.exe0 Pfad der fehlerhaften Anwendung: OneClick.exe1 Pfad des fehlerhaften Moduls: OneClick.exe2 Berichtskennung: OneClick.exe3 Error: (01/01/2014 11:16:44 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: OneClick.exe, Version: 12.0.3600.114, Zeitstempel: 0x4ff402dc Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1116 Ausnahmecode: 0x0eedfade Fehleroffset: 0x0000c41f ID des fehlerhaften Prozesses: 0x13bc Startzeit der fehlerhaften Anwendung: 0xOneClick.exe0 Pfad der fehlerhaften Anwendung: OneClick.exe1 Pfad des fehlerhaften Moduls: OneClick.exe2 Berichtskennung: OneClick.exe3 Error: (01/01/2014 11:08:21 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (01/02/2014 00:02:44 PM) (Source: Ntfs) (User: ) Description: Auf dem Volume "F:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (01/02/2014 00:02:42 PM) (Source: atapi) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort7 gefunden. Error: (01/02/2014 10:28:02 AM) (Source: Ntfs) (User: ) Description: Auf dem Volume "F:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (01/02/2014 10:27:59 AM) (Source: atapi) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort7 gefunden. Error: (01/01/2014 01:49:53 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (01/01/2014 11:06:32 AM) (Source: Ntfs) (User: ) Description: Auf dem Volume "F:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (01/01/2014 11:06:30 AM) (Source: atapi) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort7 gefunden. Error: (12/31/2013 11:20:08 AM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (12/31/2013 11:20:02 AM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (12/31/2013 11:20:02 AM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 36% Total physical RAM: 6135.17 MB Available physical RAM: 3924.49 MB Total Pagefile: 12268.52 MB Available Pagefile: 9614.11 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:119.14 GB) (Free:54.59 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive e: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (Volume) (Fixed) (Total:1863.01 GB) (Free:81.13 GB) NTFS Drive g: (Acer) (Fixed) (Total:691.95 GB) (Free:374.16 GB) NTFS Drive h: (DATA) (Fixed) (Total:692.21 GB) (Free:0.01 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: 42BEBAC4) Partition 1: (Not Active) - (Size=100 MB) - (Type=27) Partition 2: (Active) - (Size=119 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 1397 GB) (Disk ID: F41CCCF5) Partition 1: (Not Active) - (Size=13 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=692 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=692 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 74D6C828) Partition 1: (Not Active) - (Size=-198626508800) - (Type=07 NTFS) ==================== End Of Log ============================ Scan mit GMER Gmer: Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2014-01-02 13:10:11 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 M4-CT128M4SSD2 rev.0002 119,24GB Running: gmer_2.1.19163.exe; Driver: C:\Users\HANSDE~1\AppData\Local\Temp\pwtdipod.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1612] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074fc1465 2 bytes [FC, 74] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1612] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074fc14bb 2 bytes [FC, 74] .text ... * 2 .text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[1812] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074fc1465 2 bytes [FC, 74] .text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[1812] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074fc14bb 2 bytes [FC, 74] .text ... * 2 ---- Processes - GMER 2.1 ---- Library D:\Program Files (x86)\Kies\Kies.exe (*** suspicious ***) @ D:\Program Files (x86)\Kies\Kies.exe [3264] 0000000000d40000 Library D:\Program Files (x86)\Kies\External\MACSSDK.dll (*** suspicious ***) @ D:\Program Files (x86)\Kies\Kies.exe [3264] 0000000010000000 Library D:\Program Files (x86)\Kies\KiesTrayAgent.exe (*** suspicious ***) @ D:\Program Files (x86)\Kies\KiesTrayAgent.exe [3576] 0000000000400000 Library D:\Program Files (x86)\Kies\External\DeviceModules\UPNPDevice_Kies.dll (*** suspicious ***) @ D:\Program Files (x86)\Kies\KiesTrayAgent.exe [3576] 0000000010000000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000001180000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\wgui14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000067cf0000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\rsdcom48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000072ac0000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\MSVCR100.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000071bc0000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\QtCorers48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000071940000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\MSVCP100.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000071830000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\QtGuirs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000066bd0000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\QtNetworkrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000069a20000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\SSLEAY32.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000069d00000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\LIBEAY32.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000069900000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\QtXmlrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000069800000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\QtSqlrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000069740000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\QtScriptrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000068950000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\Qt3Supportrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000068700000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\QtWebKitrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 00000000653d0000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\QtTestrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000069ca0000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\rscorewinapi48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000065380000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\rsguiwinapi48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000065330000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\wcore14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000064fa0000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\rsodbc48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000064f70000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\wfvie14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000064d10000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\QtXmlPatternsrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000064a80000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\QtSvgrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000064a30000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\wsteu14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000064860000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\wreli14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000064680000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\wauff14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000064260000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\clucene-core.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000064150000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\clucene-shared.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000064130000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\zlib.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000061b80000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\clucene-contribs-lib.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 00000000640e0000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\wmain14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000003da0000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\wbae114.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000067820000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\wbae214.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000067680000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\wbae314.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 00000000674c0000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\wbae414.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000063df0000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\whau114.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000063cd0000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\whau214.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000063b80000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\wwerb14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000063a40000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\wkont14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 00000000621c0000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\wimp14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 0000000063900000 Library D:\Program Files (x86)\WISO\Steuersoftware 2014\wfabu14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592] 00000000637b0000 ---- EOF - GMER 2.1 ---- |
Themen zu Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern |
7-zip, flash player, homepage, inf/autorun.gen, installation, lightning, mobogenie, mobogenie entfernen, msil/injector.ala, msil/injector.awm, msil/injector.bkj, msil/injector.bri, msil/injector.yj, mysearchdial, nation zoom, nation zoom entfernen, nationzoom, nationzoom entfernen, newtab, nextlive, pup.optional.bundleinstaller.a, pup.optional.nationzoom.a, pup.optional.wpmanager.a, samsung kies, sich automatisch, software, synology, win32/injector.amix, win32/injector.autoit.p, win32/spy.agent.nyu, ändern |