|
Plagegeister aller Art und deren Bekämpfung: Probleme mit vmtl. lollipop.exeWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
05.01.2014, 17:00 | #1 |
| Probleme mit vmtl. lollipop.exe Hallo, ich bitte um Hilfe bei - vermutlich - auch einem Problem durch "lollipop.exe". Mir ist schon vor 2-3 Wochen aufgefallen, dass mein PC oft "arbeitet", obwohl gerade überhaupt kein Programm läuft - im Task Manager ist mir bei den Prozessen dann die "Lollipop-Datei" aufgefallen. Und sei ein paar Tagen kam es beim Surfen mit Opera 18 ständig vor, dass im Hintergrund der I-Explorer mit Werbeseiten geöffnet wurde. Das Ändern der I-Einstellungen auf noch höhere Sicherheitsstufen in beiden Browsern hat nichts gebracht. Opera habe ich inzwischen deinstalliert. Im Moment surfe ich mit dem IE. Da bei den anderen threats zum "lollipop" jedes Mal die log-files gefordert waren, habe ich - hoffentlich nicht falsch - mir das Farbar-Tool heruntergeladen und stelle die beiden Dateien gleich mal hier rein: Anhang 63543 Anhang 63544 Vielen Dank schonmal!!! |
05.01.2014, 18:30 | #3 |
| Probleme mit vmtl. lollipop.exe Ok... sorry :-(
__________________FRST.txt Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2014 Ran by Nimmíra (administrator) on ROCK on 05-01-2014 16:43:26 Running from C:\Users\Nimmíra\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe () C:\Program Files (x86)\Bizzybolt\updateBizzybolt.exe () C:\Program Files (x86)\Bizzybolt\bin\utilBizzybolt.exe (MICRO-STAR INT'L,.LTD.) C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (MICRO-STAR INT'L,.LTD.) C:\Program Files\msi\WMIHookBtnFn\HookKey.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe () C:\Users\Nimmíra\AppData\Local\Lollipop\Lollipop.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Plus HD) C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-bg.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_11_9_900_170_ActiveX.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8123936 2009-09-30] (Realtek Semiconductor) HKLM\...\Run: [HookKey] - C:\Program Files\msi\WMIHookBtnFn\HookKey.exe [24576 2010-01-06] (MICRO-STAR INT'L,.LTD.) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [444904 2012-09-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [74752 2010-12-06] (Nullsoft, Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.) HKLM-x32\...\Run: [ISUSScheduler] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-16] (InstallShield Software Corporation) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKCU\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup HKCU\...\Run: [AVG-Secure-Search-Update_0913b] - C:\Users\Nimmíra\AppData\Roaming\AVG 0913b Campaign\AVG-Secure-Search-Update-0913b.exe /PROMPT --mid 9d541528125d47d187139128c07effa9-ad1491be2ce6c122f6b66faa90e70c2decf7d34c --CMPID 0913b Startup: C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\lollipop.lnk ShortcutTarget: lollipop.lnk -> C:\Users\Nimmíra\AppData\Local\Lollipop\Lollipop.exe () Startup: C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wetter.lnk ShortcutTarget: wetter.lnk -> C:\Program Files (x86)\wetter.com Desktop\wetter.com Desktop.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKCU - DefaultScope {D815FEEE-5EAB-48B5-B77E-A2A52D60075B} URL = SearchScopes: HKCU - {4C499952-9C89-4F6F-ACA9-BBDE2A5C5776} URL = SearchScopes: HKCU - {565E11A4-BCC7-417D-BEB0-9AF611C96216} URL = SearchScopes: HKCU - {D815FEEE-5EAB-48B5-B77E-A2A52D60075B} URL = BHO: Plus-HD-4.8 - {11111111-1111-1111-1111-110411591114} - C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-bho64.dll (Plus HD) BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll No File BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO-x32: Giant Savings Extension - {11111111-1111-1111-1111-110211181110} - C:\Program Files (x86)\Giant Savings Extension\Giant Savings Extension.dll (215 Apps) BHO-x32: Plus-HD-4.8 - {11111111-1111-1111-1111-110411591114} - C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-bho.dll (Plus HD) BHO-x32: Bizzybolt - {13070af0-bc6c-4185-8baa-40a4cf05b323} - C:\Program Files (x86)\Bizzybolt\BizzyboltBHO.dll (Bizzybolt) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java Runtime - {279384DD-3D1B-4086-8679-AA5EC7268BE1} - C:\Users\Nimmíra\AppData\Roaming\JavaRun\IE\JavaRun.dll (Oracle Corporation) BHO-x32: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll No File BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll () BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) BHO-x32: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files (x86)\Softonic\Softonic\1.5.21.0\bh\Softonic.dll (Softonic.com) Toolbar: HKLM-x32 - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll () Toolbar: HKLM-x32 - Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files (x86)\Softonic\Softonic\1.5.21.0\SoftonicTlbr.dll (Softonic.com) Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll No File Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Nimmíra\AppData\Roaming\Mozilla\Firefox\Profiles\hbv1q2wc.default FF user.js: detected! => C:\Users\Nimmíra\AppData\Roaming\Mozilla\Firefox\Profiles\hbv1q2wc.default\user.js FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ No File FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Extension: Plus-HD-4.8 - C:\Users\Nimmíra\AppData\Roaming\Mozilla\Firefox\Profiles\hbv1q2wc.default\Extensions\9a1cadcd-98ec-4413-87d3-0f7c4253cd27@31f19576-e1e2-40bc-81ac-be7a5f1cf67c.com FF Extension: Giant Savings Extension - C:\Users\Nimmíra\AppData\Roaming\Mozilla\Firefox\Profiles\hbv1q2wc.default\Extensions\crossriderapp21810@crossrider.com FF Extension: softonic.com - C:\Users\Nimmíra\AppData\Roaming\Mozilla\Firefox\Profiles\hbv1q2wc.default\Extensions\ffxtlbra@softonic.com FF HKLM-x32\...\Thunderbird\Extensions: [avgthb@avg.com] - C:\Program Files (x86)\AVG\AVG2012\Thunderbird\ Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (Plus-HD-4.8) - C:\Users\Nimmíra\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlnnachibjmjahfpoemhledlpakoicg\1.26.32_0 CHR HKLM-x32\...\Chrome\Extension: [halffneccaebicfdfajnbfgpglahfgoe] - C:\Users\Nimmíra\AppData\Local\Giant Savings Extension\Chrome\Giant Savings Extension.crx ==================== Services (Whitelisted) ================= R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171600 2012-09-17] (Adobe Systems Incorporated) R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () R2 Update Bizzybolt; C:\Program Files (x86)\Bizzybolt\updateBizzybolt.exe [66848 2013-11-20] () R2 Util Bizzybolt; C:\Program Files (x86)\Bizzybolt\bin\utilBizzybolt.exe [66848 2013-12-30] () R2 WMI_Hook_Service; C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe [105472 2010-01-07] (MICRO-STAR INT'L,.LTD.) S3 Ipci1cewemvh; ==================== Drivers (Whitelisted) ==================== S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31968 2012-10-08] (Wondershare) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-05] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [240920 2013-11-04] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [194872 2013-10-24] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.) R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [28192 2009-07-17] (NVIDIA Corporation) S3 PRESONUS_AUDIOBOX_MIDI; C:\Windows\System32\drivers\psabusbm.sys [37496 2009-12-04] (Ploytec GmbH) S3 PRESONUS_AUDIOBOX_USB; C:\Windows\System32\Drivers\psabusbu.sys [462968 2009-12-04] (Ploytec GmbH) S3 PRESONUS_AUDIOBOX_WDM; C:\Windows\System32\drivers\psabusba.sys [50808 2009-12-04] (Ploytec GmbH) R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-08-10] (Corel Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-05 16:43 - 2014-01-05 16:44 - 00016240 _____ C:\Users\Nimmíra\Desktop\FRST.txt 2014-01-05 16:42 - 2014-01-05 16:42 - 01931368 _____ (Farbar) C:\Users\Nimmíra\Desktop\FRST64.exe 2014-01-05 16:42 - 2014-01-05 16:42 - 00000000 ____D C:\FRST 2014-01-05 16:09 - 2013-08-22 18:22 - 00003323 _____ C:\Users\Nimmíra\Desktop\speeddial.ini 2013-12-30 14:33 - 2014-01-05 16:34 - 00000336 _____ C:\windows\setupact.log 2013-12-30 14:33 - 2013-12-30 14:33 - 00000614 _____ C:\windows\PFRO.log 2013-12-30 14:33 - 2013-12-30 14:33 - 00000000 _____ C:\windows\setuperr.log 2013-12-29 21:36 - 2013-12-30 14:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-12-29 17:48 - 2014-01-05 16:34 - 00001332 _____ C:\windows\Tasks\Plus-HD-4.8-updater.job 2013-12-29 17:48 - 2014-01-05 16:34 - 00001234 _____ C:\windows\Tasks\Plus-HD-4.8-codedownloader.job 2013-12-29 17:48 - 2014-01-05 16:34 - 00001134 _____ C:\windows\Tasks\Plus-HD-4.8-enabler.job 2013-12-29 17:48 - 2013-12-30 15:06 - 00000000 ____D C:\Program Files (x86)\Bizzybolt 2013-12-29 17:48 - 2013-12-29 17:48 - 00004362 _____ C:\windows\System32\Tasks\Plus-HD-4.8-updater 2013-12-29 17:48 - 2013-12-29 17:48 - 00004264 _____ C:\windows\System32\Tasks\Plus-HD-4.8-codedownloader 2013-12-29 17:48 - 2013-12-29 17:48 - 00004164 _____ C:\windows\System32\Tasks\Plus-HD-4.8-enabler 2013-12-29 17:48 - 2013-12-29 17:48 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop 2013-12-29 17:47 - 2014-01-05 16:41 - 00000000 ____D C:\Users\Nimmíra\AppData\Local\Lollipop 2013-12-29 17:47 - 2014-01-05 16:34 - 00002108 _____ C:\windows\Tasks\Plus-HD-4.8-firefoxinstaller.job 2013-12-29 17:47 - 2014-01-05 16:34 - 00001978 _____ C:\windows\Tasks\Plus-HD-4.8-chromeinstaller.job 2013-12-29 17:47 - 2013-12-29 17:48 - 00000000 ____D C:\Program Files (x86)\Plus-HD-4.8 2013-12-17 20:17 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-12-17 20:17 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-12-17 20:17 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2013-12-17 20:17 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2013-12-17 20:17 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-12-17 20:17 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2013-12-17 20:17 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-12-17 20:17 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-12-17 20:17 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-12-17 20:17 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2013-12-17 20:17 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-12-17 20:17 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2013-12-17 20:17 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2013-12-17 20:17 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2013-12-17 20:17 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-12-17 20:17 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2013-12-17 20:17 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2013-12-17 20:17 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-12-17 20:17 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2013-12-17 20:17 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2013-12-17 20:17 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2013-12-17 20:17 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2013-12-17 20:17 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-12-17 20:17 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2013-12-17 20:17 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2013-12-17 20:17 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-12-17 20:17 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-12-17 20:17 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2013-12-17 20:17 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2013-12-17 20:17 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2013-12-17 20:17 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2013-12-16 13:20 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll 2013-12-16 13:20 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL 2013-12-16 13:20 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL 2013-12-16 13:20 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll 2013-12-16 13:19 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\windows\system32\IEUDINIT.EXE 2013-12-16 13:13 - 2013-12-16 13:13 - 01228800 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00626176 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat 2013-12-16 13:13 - 2013-12-16 13:13 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat 2013-12-16 13:13 - 2013-12-16 13:13 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00523776 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00453120 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2013-12-16 13:13 - 2013-12-16 13:13 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec 2013-12-16 13:13 - 2013-12-16 13:13 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00263376 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00244736 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00238288 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx 2013-12-16 13:13 - 2013-12-16 13:13 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx 2013-12-16 13:13 - 2013-12-16 13:13 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00040448 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe 2013-12-16 12:22 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll 2013-12-16 12:22 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll 2013-12-16 12:22 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll 2013-12-16 12:22 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll 2013-12-16 12:22 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll 2013-12-16 12:22 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll 2013-12-16 12:22 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2013-12-16 12:22 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll 2013-12-16 12:22 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll 2013-12-16 12:22 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx 2013-12-16 12:22 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll 2013-12-16 12:22 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshom.ocx 2013-12-16 12:22 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll 2013-12-16 12:22 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe 2013-12-16 12:22 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe 2013-12-16 12:22 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscript.exe 2013-12-16 12:22 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe 2013-12-16 12:22 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys 2013-12-16 12:22 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys 2013-12-08 13:45 - 2013-12-24 13:12 - 00000000 ____D C:\Users\Nimmíra\Desktop\Weihnachten ==================== One Month Modified Files and Folders ======= 2014-01-05 16:44 - 2014-01-05 16:43 - 00016240 _____ C:\Users\Nimmíra\Desktop\FRST.txt 2014-01-05 16:42 - 2014-01-05 16:42 - 01931368 _____ (Farbar) C:\Users\Nimmíra\Desktop\FRST64.exe 2014-01-05 16:42 - 2014-01-05 16:42 - 00000000 ____D C:\FRST 2014-01-05 16:41 - 2013-12-29 17:47 - 00000000 ____D C:\Users\Nimmíra\AppData\Local\Lollipop 2014-01-05 16:37 - 2010-12-23 21:44 - 01525112 _____ C:\windows\WindowsUpdate.log 2014-01-05 16:35 - 2011-08-25 20:46 - 00003922 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{0E626F3C-8A24-4FFB-84FD-07195C3D7244} 2014-01-05 16:34 - 2013-12-30 14:33 - 00000336 _____ C:\windows\setupact.log 2014-01-05 16:34 - 2013-12-29 17:48 - 00001332 _____ C:\windows\Tasks\Plus-HD-4.8-updater.job 2014-01-05 16:34 - 2013-12-29 17:48 - 00001234 _____ C:\windows\Tasks\Plus-HD-4.8-codedownloader.job 2014-01-05 16:34 - 2013-12-29 17:48 - 00001134 _____ C:\windows\Tasks\Plus-HD-4.8-enabler.job 2014-01-05 16:34 - 2013-12-29 17:47 - 00002108 _____ C:\windows\Tasks\Plus-HD-4.8-firefoxinstaller.job 2014-01-05 16:34 - 2013-12-29 17:47 - 00001978 _____ C:\windows\Tasks\Plus-HD-4.8-chromeinstaller.job 2014-01-05 16:34 - 2011-11-29 21:55 - 00001108 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-05 16:34 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT 2014-01-05 16:33 - 2012-04-12 18:33 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job 2014-01-05 16:15 - 2013-12-01 16:59 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Opera Software 2014-01-05 16:15 - 2013-12-01 16:59 - 00000000 ____D C:\Users\Nimmíra\AppData\Local\Opera Software 2014-01-05 16:15 - 2010-12-26 17:16 - 00000000 ____D C:\Program Files (x86)\Opera 2014-01-05 16:15 - 2010-12-23 21:50 - 00001435 _____ C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-05 15:58 - 2011-11-29 21:55 - 00001112 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-05 15:53 - 2009-07-14 05:45 - 00017600 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-05 15:53 - 2009-07-14 05:45 - 00017600 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-05 13:44 - 2010-12-25 18:15 - 00000000 ____D C:\Users\Nimmíra\AppData\Local\Adobe 2014-01-05 13:39 - 2011-12-01 18:54 - 00000000 ____D C:\ProgramData\MFAData 2014-01-01 13:34 - 2009-08-14 08:59 - 00654150 _____ C:\windows\system32\perfh007.dat 2014-01-01 13:34 - 2009-08-14 08:59 - 00130022 _____ C:\windows\system32\perfc007.dat 2014-01-01 13:34 - 2009-07-14 06:13 - 01498742 _____ C:\windows\system32\PerfStringBackup.INI 2014-01-01 13:09 - 2012-10-13 19:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-30 16:32 - 2011-01-11 15:29 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Winamp 2013-12-30 15:06 - 2013-12-29 17:48 - 00000000 ____D C:\Program Files (x86)\Bizzybolt 2013-12-30 14:34 - 2013-12-29 21:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-12-30 14:33 - 2013-12-30 14:33 - 00000614 _____ C:\windows\PFRO.log 2013-12-30 14:33 - 2013-12-30 14:33 - 00000000 _____ C:\windows\setuperr.log 2013-12-29 17:48 - 2013-12-29 17:48 - 00004362 _____ C:\windows\System32\Tasks\Plus-HD-4.8-updater 2013-12-29 17:48 - 2013-12-29 17:48 - 00004264 _____ C:\windows\System32\Tasks\Plus-HD-4.8-codedownloader 2013-12-29 17:48 - 2013-12-29 17:48 - 00004164 _____ C:\windows\System32\Tasks\Plus-HD-4.8-enabler 2013-12-29 17:48 - 2013-12-29 17:48 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop 2013-12-29 17:48 - 2013-12-29 17:47 - 00000000 ____D C:\Program Files (x86)\Plus-HD-4.8 2013-12-29 17:48 - 2010-12-23 21:50 - 00000000 ___RD C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-12-29 17:48 - 2009-11-13 15:59 - 00000000 ____D C:\windows\Panther 2013-12-26 12:14 - 2009-07-14 06:09 - 00000000 ____D C:\windows\System32\Tasks\WPD 2013-12-24 14:30 - 2010-12-23 21:50 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Adobe 2013-12-24 13:12 - 2013-12-08 13:45 - 00000000 ____D C:\Users\Nimmíra\Desktop\Weihnachten 2013-12-24 12:36 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache 2013-12-24 11:59 - 2011-11-29 21:55 - 00000000 ____D C:\Program Files (x86)\Google 2013-12-17 19:33 - 2012-04-12 18:33 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2013-12-17 19:33 - 2012-04-12 18:33 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater 2013-12-17 19:33 - 2011-05-15 19:52 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-17 19:32 - 2009-07-14 05:45 - 02045744 _____ C:\windows\system32\FNTCACHE.DAT 2013-12-17 19:30 - 2009-07-14 04:20 - 00000000 ____D C:\windows\PolicyDefinitions 2013-12-16 13:13 - 2013-12-16 13:13 - 01228800 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00626176 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat 2013-12-16 13:13 - 2013-12-16 13:13 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat 2013-12-16 13:13 - 2013-12-16 13:13 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00523776 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00453120 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2013-12-16 13:13 - 2013-12-16 13:13 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec 2013-12-16 13:13 - 2013-12-16 13:13 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00263376 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00244736 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00238288 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx 2013-12-16 13:13 - 2013-12-16 13:13 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx 2013-12-16 13:13 - 2013-12-16 13:13 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00040448 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe 2013-12-16 13:11 - 2009-08-14 10:21 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-16 13:08 - 2013-08-15 19:49 - 00000000 ____D C:\windows\system32\MRT 2013-12-16 13:07 - 2010-12-28 20:31 - 90708896 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2013-12-16 12:53 - 2011-11-29 21:55 - 00004108 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-16 12:53 - 2011-11-29 21:55 - 00003856 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-30 15:59 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-01-2014 Ran by Nimmíra at 2014-01-05 16:44:35 Running from C:\Users\Nimmíra\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664} ==================== Installed Programs ====================== Adobe Acrobat 6.0 Professional - English, Français, Deutsch (x32 Version: 006.000.000 - Adobe Systems) Adobe AIR (x32 Version: 3.5.0.1060 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.5.0.1060 - Adobe Systems Incorporated) Hidden Adobe Download Assistant (x32 Version: 1.0.6 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.0.6 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Photoshop Elements 11 (x32 Version: 11.0 - Adobe Systems Incorporated) Adobe Photoshop Elements 11 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden Adobe Reader 9.5.5 - Deutsch (x32 Version: 9.5.5 - Adobe Systems Incorporated) Amazon MP3-Downloader 1.0.9 (x32 Version: - ) Apple Application Support (x32 Version: 1.4.1 - Apple Inc.) Apple Software Update (x32 Version: 2.1.1.116 - Apple Inc.) ArcSoft Magic-i Visual Effects 2 (x32 Version: 2.0.10.102 - ArcSoft) ArcSoft WebCam Companion 3 (x32 Version: 3.0.32.262 - ArcSoft) Audacity 2.0.5 (x32 Version: 2.0.5 - Audacity Team) AudioBox USB driver (Version: - ) AVerMedia A336 MiniCard Hybrid DVB-T 10.0.64.25 (x32 Version: 10.0.64.25 - AVerMedia TECHNOLOGIES, Inc.) AVG 2014 (Version: 14.0.3658 - AVG Technologies) Hidden AVG 2014 (Version: 14.0.4259 - AVG Technologies) Hidden AVG 2014 (Version: 2014.0.4259 - AVG Technologies) Bizzybolt (Version: 2013.11.20.184610 - Bizzybolt) BurnRecovery (x32 Version: 3.0.909.901 - Micro-Star International Co., Ltd.) Canon MP560 series MP Drivers (Version: - ) CCleaner (Version: 4.06 - Piriform) CDBurnerXP (Version: 4.3.8.2631 - CDBurnerXP) CDex extraction audio (x32 Version: - ) Cisco EAP-FAST Module (x32 Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (x32 Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (x32 Version: 1.1.6 - Cisco Systems, Inc.) Compatibility Pack für 2007 Office System (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32 Version: - Microsoft) Elements 11 Organizer (x32 Version: 11.0 - Ihr Firmenname) Hidden ENE CIR Receiver Driver (Version: 2.7.4.0 - ENE) Free YouTube Download version 3.1.42.1212 (x32 Version: 3.1.42.1212 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.1.320 (x32 Version: 3.12.1.320 - DVDVideoSoft Ltd.) Giant Savings Extension (x32 Version: 1.24.151.151 - 215 Apps) Google Earth (x32 Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden HTC Driver Installer (x32 Version: 4.3.0.001 - HTC Corporation) IPTInstaller (x32 Version: 4.0.8 - HTC) Java 7 Update 45 (x32 Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden LAME v3.99.3 (for Windows) (x32 Version: - ) Lollipop (HKCU Version: - Lollipop Network, S.L.) <==== ATTENTION Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Hidden Microsoft Office 2010 Service Pack 1 (SP1) (x32 Version: - Microsoft) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Search Enhancement Pack (x32 Version: 1.2.123.0 - Microsoft Corporation) Hidden Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (x32 Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (x32 Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Touch Pack for Windows 7 (x32 Version: 1.0.40517.00 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.0 (x32 Version: 3.0.11010.0 - Microsoft Corporation) Mozilla Maintenance Service (x32 Version: 24.2.0 - Mozilla) Mozilla Thunderbird 24.2.0 (x86 de) (x32 Version: 24.2.0 - Mozilla) msi EasyViewer (x32 Version: 1.2 - msi) msi EasyViewer (x32 Version: 1.2 - msi) Hidden msi Software Install_x64 (Version: 3.0.909.3001 - msi) msi Wind Match (x32 Version: 0.0.7.0 - msi) msi Wind Match (x32 Version: 0.0.7.0 - msi) Hidden MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) MuseScore 1.2 MuseScore score typesetter (x32 Version: 1.2.0 - Werner Schweer and Others) NVIDIA Drivers (Version: 1.9 - NVIDIA Corporation) PDF24 Creator 5.7.0 (x32 Version: - PDF24.org) Pixum Fotobuch (x32 Version: 5.0.1 - CEWE COLOR AG u Co. OHG) Plus-HD-4.8 (x32 Version: 1.32.153.0 - Plus HD) <==== ATTENTION PrimoPDF -- brought to you by Nitro PDF Software (x32 Version: 5 - Nitro PDF Software) PSE11 STI Installer (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden QuickTime (x32 Version: 7.69.80.9 - Apple Inc.) Realtek Ethernet Controller Driver For Windows Vista and Later (x32 Version: 1.00.0009 - Realtek) Realtek High Definition Audio Driver (x32 Version: 6.0.1.5948 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30105 - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver (x32 Version: 1.00.0130 - REALTEK Semiconductor Corp.) Sibelius Scorch (Firefox, Opera, Netscape only) (x32 Version: 6.0.7 - Sibelius Software) Softonic toolbar on IE and Chrome (x32 Version: - Softonic) SoftStylus (x32 Version: 2.2.120.4 - Motorola) SRS Premium Sound Control Panel (Version: 1.8.1700 - SRS Labs, Inc.) Stellarium 0.10.6.1 (x32 Version: - ) SyncBack (x32 Version: - 2BrightSparks) tsWebEditor 20060920 (x32 Version: 20060920 - thaler software) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2494150) (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2553065) (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2566458) (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (x32 Version: - Microsoft) Visual C++ Runtime for Dragon NaturallySpeaking 64bit (x64) (Version: 10.00.800.228 - Nuance Communications Inc.) Visual Studio 2008 x64 Redistributables (x32 Version: 10.0.0.2 - AVG Technologies) Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1 - AVG Technologies) Visual Studio 2012 x64 Redistributables (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (x32 Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Winamp (x32 Version: 5.601 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1 - Nullsoft, Inc) Windows Live Anmelde-Assistent (x32 Version: 5.000.818.5 - Microsoft Corporation) Windows Live Call (x32 Version: 14.0.8064.0206 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 14.0.8064.206 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Windows Live Essentials (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 14.0.8081.709 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 14.0.8091.0730 - Microsoft Corporation) Hidden Windows Live Sync (x32 Version: 14.0.8089.726 - Microsoft Corporation) Windows Live Toolbar (x32 Version: 14.0.8064.206 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Windows Live-Uploadtool (x32 Version: 14.0.8014.1029 - Microsoft Corporation) WindTouch3D_x64 (Version: 0.0.2.6 - msi) Hidden WindTouch3D_x64 (x32 Version: - ) WinRAR archiver (x32 Version: - ) WMIHookBtnFn (Version: 0.0.6.19 - msi) Hidden WMIHookBtnFn (x32 Version: - ) ==================== Restore Points ========================= 05-01-2014 14:14:10 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {37DB35FC-983E-4F56-968E-AA126BBCE2C4} - System32\Tasks\AdobeAAMUpdater-1.0-Rock-Nimmíra => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2012-09-20] (Adobe Systems Incorporated) Task: {39D64A31-0D0A-4264-82CD-0C63B89F73B4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-29] (Google Inc.) Task: {57D4329D-6E95-4387-98CE-EA8C50BB9C07} - System32\Tasks\Plus-HD-4.8-firefoxinstaller => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-firefoxinstaller.exe [2013-12-29] (Plus HD) <==== ATTENTION Task: {6D9ED03A-4495-4B9F-92EE-7BF30BB44DCC} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-09-19] (Piriform Ltd) Task: {809DBC28-BED5-4A35-B7E3-A5B113152F8D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-29] (Google Inc.) Task: {8505584A-2994-405F-AD1B-C7E1FA04D294} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-17] (Adobe Systems Incorporated) Task: {8FB36E9C-6B4A-4580-812D-9D58C4F0D32D} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: {A2F4E412-6010-4141-ABCE-FD976B48B8A7} - System32\Tasks\Plus-HD-4.8-enabler => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-enabler.exe [2013-12-29] (Plus HD) <==== ATTENTION Task: {B0633EF7-829B-4AD5-AD44-2852234BB202} - System32\Tasks\Plus-HD-4.8-chromeinstaller => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-chromeinstaller.exe [2013-12-29] (Plus HD) <==== ATTENTION Task: {BE1193C6-E2A4-4308-8B54-559DA96B3FD0} - System32\Tasks\Plus-HD-4.8-updater => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-updater.exe [2013-12-29] (Plus HD) <==== ATTENTION Task: {DB09736B-3223-496E-8898-77AE9AD38563} - System32\Tasks\Plus-HD-4.8-codedownloader => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-codedownloader.exe [2013-12-29] (Plus HD) <==== ATTENTION Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\Plus-HD-4.8-chromeinstaller.job => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-chromeinstaller.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-4.8-codedownloader.job => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-codedownloader.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-4.8-enabler.job => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-enabler.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-4.8-firefoxinstaller.job => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-firefoxinstaller.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-4.8-updater.job => C:\Program Files (x86)\Plus-HD-4.8\Plus-HD-4.8-updater.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2005-06-07 19:26 - 2005-06-07 19:26 - 00043008 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll 2013-12-29 17:48 - 2013-12-29 17:48 - 00494952 _____ () C:\program files (x86)\plus-hd-4.8\Plus-HD-4.8-buttonutil64.dll 2009-12-11 15:00 - 2009-12-11 15:00 - 00099592 _____ () C:\Program Files (x86)\SoftStylus\sstlstsrv.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/05/2014 03:09:38 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3. Ungültige XML-Syntax. Error: (01/05/2014 03:09:16 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (01/01/2014 01:44:11 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (12/30/2013 04:01:28 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3. Ungültige XML-Syntax. Error: (12/30/2013 04:01:12 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (12/30/2013 02:33:46 PM) (Source: Windows Search Service) (User: ) Description: Der Index kann nicht initialisiert werden. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (12/30/2013 02:33:46 PM) (Source: Windows Search Service) (User: ) Description: Die Anwendung kann nicht initialisiert werden. Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (12/30/2013 02:33:46 PM) (Source: Windows Search Service) (User: ) Description: Das Gatherer-Objekt kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (12/30/2013 02:33:46 PM) (Source: Windows Search Service) (User: ) Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Error: (12/30/2013 02:33:45 PM) (Source: Windows Search Service) (User: ) Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) System errors: ============= Error: (01/05/2014 04:33:55 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen Status gemeldet: 32 Error: (01/05/2014 03:45:31 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen Status gemeldet: 32 Error: (01/04/2014 10:28:31 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen Status gemeldet: 32 Error: (01/01/2014 05:39:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen Status gemeldet: 32 Error: (12/30/2013 10:18:14 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen Status gemeldet: 32 Error: (12/30/2013 02:33:46 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (12/30/2013 02:33:46 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535. Error: (12/29/2013 09:37:06 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen Status gemeldet: 32 Error: (12/29/2013 07:06:25 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (12/29/2013 05:31:03 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Microsoft Office Sessions: ========================= Error: (01/05/2014 03:09:38 PM) (Source: SideBySide)(User: ) Description: c:\program files (x86)\microsoft\search enhancement pack\search helper\searchhelper.dllc:\program files (x86)\microsoft\search enhancement pack\search helper\searchhelper.dll2 Error: (01/05/2014 03:09:16 PM) (Source: SideBySide)(User: ) Description: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1"c:\program files (x86)\windows live\photo gallery\MovieMaker.Exec:\program files (x86)\windows live\photo gallery\WLMFDS.DLL8 Error: (01/01/2014 01:44:11 PM) (Source: Customer Experience Improvement Program)(User: ) Description: 80004005 Error: (12/30/2013 04:01:28 PM) (Source: SideBySide)(User: ) Description: c:\program files (x86)\microsoft\search enhancement pack\search helper\searchhelper.dllc:\program files (x86)\microsoft\search enhancement pack\search helper\searchhelper.dll2 Error: (12/30/2013 04:01:12 PM) (Source: SideBySide)(User: ) Description: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1"c:\program files (x86)\windows live\photo gallery\MovieMaker.Exec:\program files (x86)\windows live\photo gallery\WLMFDS.DLL8 Error: (12/30/2013 02:33:46 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (12/30/2013 02:33:46 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (12/30/2013 02:33:46 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (12/30/2013 02:33:46 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Search.TripoliIndexer Error: (12/30/2013 02:33:45 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Search.JetPropStore ==================== Memory info =========================== Percentage of memory in use: 46% Total physical RAM: 3839.24 MB Available physical RAM: 2068.62 MB Total Pagefile: 7676.66 MB Available Pagefile: 5722.59 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: (OS_Install) (Fixed) (Total:137.09 GB) (Free:86.97 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (Data) (Fixed) (Total:444.34 GB) (Free:418.44 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: 45132279) Partition 1: (Not Active) - (Size=993 KB) - (Type=42) Partition 2: (Not Active) - (Size=15 GB) - (Type=27) Partition 3: (Active) - (Size=100 MB) - (Type=27) Partition 4: (Not Active) - (Size=137 GB) - (Type=42) ==================== End Of Log ============================ Und ich wollt noch anfügen: wenn ich die Lollipop.exe im Task-Manager beende, ändert das leider gar nichts. Die Werbe-Popups kommen trotzdem ständig weiter. :-( Geändert von Nimmira (05.01.2014 um 18:44 Uhr) |
05.01.2014, 18:51 | #4 |
/// TB-Ausbilder | Probleme mit vmtl. lollipop.exe Ja da lebt eine Horde Adware. Schritt 1
Schritt 2 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 3 Starte noch einmal FRST.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
05.01.2014, 19:27 | #5 |
| Probleme mit vmtl. lollipop.exe Danke!! Hier kommt gleich mal der erste Text... ich ergänze gleich den zweiten Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 05/01/2014 um 19:23:16 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Nimmíra - ROCK # Gestartet von : C:\Users\Nimmíra\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Uniblue\DriverScanner Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB Ordner Gelöscht : C:\Users\Nimmíra\AppData\Local\lollipop Ordner Gelöscht : C:\Users\Nimmíra\AppData\Local\OpenCandy Ordner Gelöscht : C:\Users\Nimmíra\AppData\LocalLow\Softonic Ordner Gelöscht : C:\Users\Nimmíra\AppData\Roaming\dvdvideosoftiehelpers Ordner Gelöscht : C:\Users\Nimmíra\AppData\Roaming\OpenCandy Ordner Gelöscht : C:\Users\Nimmíra\AppData\Roaming\Mozilla\Firefox\Profiles\hbv1q2wc.default\Extensions\ffxtlbra@softonic.com Datei Gelöscht : C:\Users\Nimmíra\AppData\Roaming\Mozilla\Firefox\Profiles\hbv1q2wc.default\user.js ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Classes\Applications\lollipop.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\driverscanner Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Giant Savings Extension_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Giant Savings Extension_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Giant Savings Extension-InternalInstaller_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Giant Savings Extension-InternalInstaller_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\softonic_ggl_1_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\softonic_ggl_1_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_essentialpim_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_essentialpim_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_stellarium_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_stellarium_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_streaming-video-recorder_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_streaming-video-recorder_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_vallen-zipper_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_vallen-zipper_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_wettercenter_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_wettercenter_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{50F7F0BE-31BA-4145-BD8B-6B0DECFED804} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKCU\Software\AVG Nation toolbar Schlüssel Gelöscht : HKCU\Software\Cr_Installer Schlüssel Gelöscht : HKCU\Software\InstallCore Schlüssel Gelöscht : HKCU\Software\lollipop Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider Schlüssel Gelöscht : HKLM\Software\AVG Nation toolbar Schlüssel Gelöscht : HKLM\Software\AVG Secure Search Schlüssel Gelöscht : HKLM\Software\AVG Security Toolbar Schlüssel Gelöscht : HKLM\Software\Uniblue ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v [ Datei : C:\Users\Nimmíra\AppData\Roaming\Mozilla\Firefox\Profiles\hbv1q2wc.default\prefs.js ] Zeile gelöscht : user_pref("extensions.crossriderapp21810.adsOldValue", -1); ************************* AdwCleaner[R0].txt - [5360 octets] - [05/01/2014 19:22:28] AdwCleaner[S0].txt - [5008 octets] - [05/01/2014 19:23:16] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5068 octets] ########## Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2014 Ran by Nimmíra (administrator) on ROCK on 05-01-2014 19:28:47 Running from C:\Users\Nimmíra\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (MICRO-STAR INT'L,.LTD.) C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (MICRO-STAR INT'L,.LTD.) C:\Program Files\msi\WMIHookBtnFn\HookKey.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_11_9_900_170_ActiveX.exe (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8123936 2009-09-30] (Realtek Semiconductor) HKLM\...\Run: [HookKey] - C:\Program Files\msi\WMIHookBtnFn\HookKey.exe [24576 2010-01-06] (MICRO-STAR INT'L,.LTD.) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [444904 2012-09-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [74752 2010-12-06] (Nullsoft, Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.) HKLM-x32\...\Run: [ISUSScheduler] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-16] (InstallShield Software Corporation) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKCU\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup HKCU\...\Run: [AVG-Secure-Search-Update_0913b] - C:\Users\Nimmíra\AppData\Roaming\AVG 0913b Campaign\AVG-Secure-Search-Update-0913b.exe /PROMPT --mid 9d541528125d47d187139128c07effa9-ad1491be2ce6c122f6b66faa90e70c2decf7d34c --CMPID 0913b Startup: C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wetter.lnk ShortcutTarget: wetter.lnk -> C:\Program Files (x86)\wetter.com Desktop\wetter.com Desktop.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKCU - DefaultScope {D815FEEE-5EAB-48B5-B77E-A2A52D60075B} URL = SearchScopes: HKCU - {4C499952-9C89-4F6F-ACA9-BBDE2A5C5776} URL = SearchScopes: HKCU - {565E11A4-BCC7-417D-BEB0-9AF611C96216} URL = SearchScopes: HKCU - {D815FEEE-5EAB-48B5-B77E-A2A52D60075B} URL = BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java Runtime - {279384DD-3D1B-4086-8679-AA5EC7268BE1} - C:\Users\Nimmíra\AppData\Roaming\JavaRun\IE\JavaRun.dll (Oracle Corporation) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll () BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) Toolbar: HKLM-x32 - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll () Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll No File Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Nimmíra\AppData\Roaming\Mozilla\Firefox\Profiles\hbv1q2wc.default FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ No File FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Extension: Giant Savings Extension - C:\Users\Nimmíra\AppData\Roaming\Mozilla\Firefox\Profiles\hbv1q2wc.default\Extensions\crossriderapp21810@crossrider.com FF HKLM-x32\...\Thunderbird\Extensions: [avgthb@avg.com] - C:\Program Files (x86)\AVG\AVG2012\Thunderbird\ Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION ==================== Services (Whitelisted) ================= R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171600 2012-09-17] (Adobe Systems Incorporated) R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () R2 WMI_Hook_Service; C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe [105472 2010-01-07] (MICRO-STAR INT'L,.LTD.) S3 Ipci1cewemvh; ==================== Drivers (Whitelisted) ==================== S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31968 2012-10-08] (Wondershare) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-05] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [240920 2013-11-04] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [194872 2013-10-24] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.) R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [28192 2009-07-17] (NVIDIA Corporation) S3 PRESONUS_AUDIOBOX_MIDI; C:\Windows\System32\drivers\psabusbm.sys [37496 2009-12-04] (Ploytec GmbH) S3 PRESONUS_AUDIOBOX_USB; C:\Windows\System32\Drivers\psabusbu.sys [462968 2009-12-04] (Ploytec GmbH) S3 PRESONUS_AUDIOBOX_WDM; C:\Windows\System32\drivers\psabusba.sys [50808 2009-12-04] (Ploytec GmbH) R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-08-10] (Corel Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-05 19:21 - 2014-01-05 19:23 - 00000000 ____D C:\AdwCleaner 2014-01-05 19:21 - 2014-01-05 19:21 - 01233962 _____ C:\Users\Nimmíra\Desktop\adwcleaner.exe 2014-01-05 16:44 - 2014-01-05 16:45 - 00027733 _____ C:\Users\Nimmíra\Desktop\Addition.txt 2014-01-05 16:43 - 2014-01-05 19:28 - 00013967 _____ C:\Users\Nimmíra\Desktop\FRST.txt 2014-01-05 16:42 - 2014-01-05 16:42 - 01931368 _____ (Farbar) C:\Users\Nimmíra\Desktop\FRST64.exe 2014-01-05 16:42 - 2014-01-05 16:42 - 00000000 ____D C:\FRST 2014-01-05 16:09 - 2013-08-22 18:22 - 00003323 _____ C:\Users\Nimmíra\Desktop\speeddial.ini 2013-12-30 14:33 - 2014-01-05 19:25 - 00000448 _____ C:\windows\setupact.log 2013-12-30 14:33 - 2014-01-05 19:19 - 00002146 _____ C:\windows\PFRO.log 2013-12-30 14:33 - 2013-12-30 14:33 - 00000000 _____ C:\windows\setuperr.log 2013-12-29 21:36 - 2013-12-30 14:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-12-29 17:48 - 2013-12-29 17:48 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop 2013-12-17 20:17 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-12-17 20:17 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-12-17 20:17 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2013-12-17 20:17 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2013-12-17 20:17 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-12-17 20:17 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2013-12-17 20:17 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-12-17 20:17 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-12-17 20:17 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-12-17 20:17 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2013-12-17 20:17 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-12-17 20:17 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2013-12-17 20:17 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2013-12-17 20:17 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2013-12-17 20:17 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-12-17 20:17 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2013-12-17 20:17 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2013-12-17 20:17 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-12-17 20:17 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2013-12-17 20:17 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2013-12-17 20:17 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2013-12-17 20:17 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2013-12-17 20:17 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-12-17 20:17 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2013-12-17 20:17 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2013-12-17 20:17 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-12-17 20:17 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-12-17 20:17 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2013-12-17 20:17 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2013-12-17 20:17 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2013-12-17 20:17 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2013-12-16 13:20 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll 2013-12-16 13:20 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL 2013-12-16 13:20 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL 2013-12-16 13:20 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll 2013-12-16 13:19 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\windows\system32\IEUDINIT.EXE 2013-12-16 13:13 - 2013-12-16 13:13 - 01228800 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00626176 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat 2013-12-16 13:13 - 2013-12-16 13:13 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat 2013-12-16 13:13 - 2013-12-16 13:13 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00523776 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00453120 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2013-12-16 13:13 - 2013-12-16 13:13 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec 2013-12-16 13:13 - 2013-12-16 13:13 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00263376 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00244736 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00238288 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx 2013-12-16 13:13 - 2013-12-16 13:13 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx 2013-12-16 13:13 - 2013-12-16 13:13 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00040448 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe 2013-12-16 12:22 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll 2013-12-16 12:22 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll 2013-12-16 12:22 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll 2013-12-16 12:22 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll 2013-12-16 12:22 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll 2013-12-16 12:22 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll 2013-12-16 12:22 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2013-12-16 12:22 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll 2013-12-16 12:22 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll 2013-12-16 12:22 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx 2013-12-16 12:22 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll 2013-12-16 12:22 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshom.ocx 2013-12-16 12:22 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll 2013-12-16 12:22 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe 2013-12-16 12:22 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe 2013-12-16 12:22 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscript.exe 2013-12-16 12:22 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe 2013-12-16 12:22 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys 2013-12-16 12:22 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys 2013-12-08 13:45 - 2013-12-24 13:12 - 00000000 ____D C:\Users\Nimmíra\Desktop\Weihnachten ==================== One Month Modified Files and Folders ======= 2014-01-05 19:29 - 2014-01-05 16:43 - 00013967 _____ C:\Users\Nimmíra\Desktop\FRST.txt 2014-01-05 19:25 - 2013-12-30 14:33 - 00000448 _____ C:\windows\setupact.log 2014-01-05 19:25 - 2011-11-29 21:55 - 00001108 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-05 19:25 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT 2014-01-05 19:24 - 2010-12-23 21:44 - 01581833 _____ C:\windows\WindowsUpdate.log 2014-01-05 19:24 - 2009-07-14 05:45 - 00017600 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-05 19:24 - 2009-07-14 05:45 - 00017600 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-05 19:23 - 2014-01-05 19:21 - 00000000 ____D C:\AdwCleaner 2014-01-05 19:23 - 2011-08-19 08:51 - 00000000 ____D C:\ProgramData\Uniblue 2014-01-05 19:21 - 2014-01-05 19:21 - 01233962 _____ C:\Users\Nimmíra\Desktop\adwcleaner.exe 2014-01-05 19:19 - 2013-12-30 14:33 - 00002146 _____ C:\windows\PFRO.log 2014-01-05 19:17 - 2010-12-23 21:50 - 00000000 ___RD C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-05 18:58 - 2011-11-29 21:55 - 00001112 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-05 18:37 - 2011-12-01 18:54 - 00000000 ____D C:\ProgramData\MFAData 2014-01-05 18:33 - 2012-04-12 18:33 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job 2014-01-05 16:45 - 2014-01-05 16:44 - 00027733 _____ C:\Users\Nimmíra\Desktop\Addition.txt 2014-01-05 16:42 - 2014-01-05 16:42 - 01931368 _____ (Farbar) C:\Users\Nimmíra\Desktop\FRST64.exe 2014-01-05 16:42 - 2014-01-05 16:42 - 00000000 ____D C:\FRST 2014-01-05 16:35 - 2011-08-25 20:46 - 00003922 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{0E626F3C-8A24-4FFB-84FD-07195C3D7244} 2014-01-05 16:15 - 2013-12-01 16:59 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Opera Software 2014-01-05 16:15 - 2013-12-01 16:59 - 00000000 ____D C:\Users\Nimmíra\AppData\Local\Opera Software 2014-01-05 16:15 - 2010-12-26 17:16 - 00000000 ____D C:\Program Files (x86)\Opera 2014-01-05 16:15 - 2010-12-23 21:50 - 00001435 _____ C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-05 13:44 - 2010-12-25 18:15 - 00000000 ____D C:\Users\Nimmíra\AppData\Local\Adobe 2014-01-01 13:34 - 2009-08-14 08:59 - 00654150 _____ C:\windows\system32\perfh007.dat 2014-01-01 13:34 - 2009-08-14 08:59 - 00130022 _____ C:\windows\system32\perfc007.dat 2014-01-01 13:34 - 2009-07-14 06:13 - 01498742 _____ C:\windows\system32\PerfStringBackup.INI 2014-01-01 13:09 - 2012-10-13 19:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-30 16:32 - 2011-01-11 15:29 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Winamp 2013-12-30 14:34 - 2013-12-29 21:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-12-30 14:33 - 2013-12-30 14:33 - 00000000 _____ C:\windows\setuperr.log 2013-12-29 17:48 - 2013-12-29 17:48 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop 2013-12-29 17:48 - 2009-11-13 15:59 - 00000000 ____D C:\windows\Panther 2013-12-26 12:14 - 2009-07-14 06:09 - 00000000 ____D C:\windows\System32\Tasks\WPD 2013-12-24 14:30 - 2010-12-23 21:50 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Adobe 2013-12-24 13:12 - 2013-12-08 13:45 - 00000000 ____D C:\Users\Nimmíra\Desktop\Weihnachten 2013-12-24 12:36 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache 2013-12-24 11:59 - 2011-11-29 21:55 - 00000000 ____D C:\Program Files (x86)\Google 2013-12-17 19:33 - 2012-04-12 18:33 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2013-12-17 19:33 - 2012-04-12 18:33 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater 2013-12-17 19:33 - 2011-05-15 19:52 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-17 19:32 - 2009-07-14 05:45 - 02045744 _____ C:\windows\system32\FNTCACHE.DAT 2013-12-17 19:30 - 2009-07-14 04:20 - 00000000 ____D C:\windows\PolicyDefinitions 2013-12-16 13:13 - 2013-12-16 13:13 - 01228800 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00626176 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat 2013-12-16 13:13 - 2013-12-16 13:13 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat 2013-12-16 13:13 - 2013-12-16 13:13 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00523776 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00453120 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2013-12-16 13:13 - 2013-12-16 13:13 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec 2013-12-16 13:13 - 2013-12-16 13:13 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00263376 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00244736 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00238288 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx 2013-12-16 13:13 - 2013-12-16 13:13 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx 2013-12-16 13:13 - 2013-12-16 13:13 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00040448 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe 2013-12-16 13:11 - 2009-08-14 10:21 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-16 13:08 - 2013-08-15 19:49 - 00000000 ____D C:\windows\system32\MRT 2013-12-16 13:07 - 2010-12-28 20:31 - 90708896 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2013-12-16 12:53 - 2011-11-29 21:55 - 00004108 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-16 12:53 - 2011-11-29 21:55 - 00003856 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore Some content of TEMP: ==================== C:\Users\Nimmíra\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-30 15:59 ==================== End Of Log ============================ |
05.01.2014, 20:17 | #6 |
/// TB-Ausbilder | Probleme mit vmtl. lollipop.exe Prima. Wie läuft der Rechner jetzt? Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter FF Extension: Giant Savings Extension - C:\Users\Nimmíra\AppData\Roaming\Mozilla\Firefox\Profiles\hbv1q2wc.default\Extensions\crossriderapp21810@crossrider.com S3 Ipci1cewemvh; 2014-01-05 16:09 - 2013-08-22 18:22 - 00003323 _____ C:\Users\Nimmíra\Desktop\speeddial.ini 2013-12-29 17:48 - 2013-12-29 17:48 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 3 ESET Online Scanner
Schritt 4 Starte noch einmal FRST.
Bitte poste in deiner nächsten Antwort:
__________________ --> Probleme mit vmtl. lollipop.exe |
05.01.2014, 22:10 | #7 |
| Probleme mit vmtl. lollipop.exe Der Rechner läuft schon wieder ganz fit , schon seit ich die unerwünschten Programme am Anfang deinstalliert habe (keine einzige Werbung mehr - juhuu!). Hier kommen wieder die Log-Dateien, ich ergänz sie eine nach der anderen... 1. Fixlog Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-01-2014 Ran by Nimmíra at 2014-01-05 20:26:38 Run:1 Running from D:\Eigene Dateien\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** FF Extension: Giant Savings Extension - C:\Users\Nimmíra\AppData\Roaming\Mozilla\Firefox\Profiles\hbv1q2wc.default\Extensions\crossriderapp21810@crossrider.com S3 Ipci1cewemvh; 2014-01-05 16:09 - 2013-08-22 18:22 - 00003323 _____ C:\Users\Nimmíra\Desktop\speeddial.ini 2013-12-29 17:48 - 2013-12-29 17:48 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop ***************** C:\Users\Nimmíra\AppData\Roaming\Mozilla\Firefox\Profiles\hbv1q2wc.default\Extensions\crossriderapp21810@crossrider.com => Moved successfully. Ipci1cewemvh => Service deleted successfully. "C:\Users\Nimmíra\Desktop\speeddial.ini" => File/Directory not found. C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop => Moved successfully. ==== End of Fixlog ==== Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.05.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 Nimmíra :: ROCK [Administrator] 05.01.2014 20:34:12 mbam-log-2014-01-05 (20-34-12).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 212057 Laufzeit: 4 Minute(n), 4 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Nimmíra\AppData\Local\Temp\n5076\Bizzybolt_2511-5ea0573c.exe (PUP.Optional.Bizzybolt.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Ohoh... der ESET-Scan läuft seit über 1 Std. und hat bis jetzt gerade 24% geschafft. Das wird heute nix mehr... ich werd ihn morgen Vormittag nochmal starten und die letzten beiden Log-Files dann morgen Nachmittag posten. Vielen, vielen Dank für die Hilfe bis jetzt!!! Morgen dann noch: ESET Log file FRST Log file Geändert von Nimmira (05.01.2014 um 21:06 Uhr) |
05.01.2014, 22:20 | #8 |
/// TB-Ausbilder | Probleme mit vmtl. lollipop.exe Ja der ESET-Scan kann sehr lange dauern, das ist normal.
__________________ cheers, Leo |
06.01.2014, 11:27 | #9 |
| Probleme mit vmtl. lollipop.exe So, hier nach langem Warten die ESET Log-Datei Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=527adfb04b614f40a85621b7160d3d48 # engine=16532 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-05 09:53:29 # local_time=2014-01-05 10:53:29 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 3295285 140588659 0 0 # scanned=257425 # found=0 # cleaned=0 # scan_time=7214 ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=527adfb04b614f40a85621b7160d3d48 # engine=16532 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-06 10:22:22 # local_time=2014-01-06 11:22:22 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 3343818 140633592 0 0 # scanned=293292 # found=0 # cleaned=0 # scan_time=7407 Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014 Ran by Nimmíra (administrator) on ROCK on 06-01-2014 11:29:13 Running from D:\Eigene Dateien\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (MICRO-STAR INT'L,.LTD.) C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (MICRO-STAR INT'L,.LTD.) C:\Program Files\msi\WMIHookBtnFn\HookKey.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Opera Software) C:\Program Files (x86)\Opera\18.0.1284.68_0\opera.exe () C:\Program Files (x86)\Opera\18.0.1284.68_0\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\18.0.1284.68_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\18.0.1284.68_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\18.0.1284.68_0\opera.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8123936 2009-09-30] (Realtek Semiconductor) HKLM\...\Run: [HookKey] - C:\Program Files\msi\WMIHookBtnFn\HookKey.exe [24576 2010-01-06] (MICRO-STAR INT'L,.LTD.) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [444904 2012-09-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [74752 2010-12-06] (Nullsoft, Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.) HKLM-x32\...\Run: [ISUSScheduler] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-16] (InstallShield Software Corporation) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [HOSTS Anti-Adware_PUPs] - C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe HKCU\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup HKCU\...\Run: [AVG-Secure-Search-Update_0913b] - C:\Users\Nimmíra\AppData\Roaming\AVG 0913b Campaign\AVG-Secure-Search-Update-0913b.exe /PROMPT --mid 9d541528125d47d187139128c07effa9-ad1491be2ce6c122f6b66faa90e70c2decf7d34c --CMPID 0913b MountPoints2: {efd7e1cd-76a9-11e3-ba06-40618640b831} - G:\HTC_Sync_Manager_PC.exe Startup: C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wetter.lnk ShortcutTarget: wetter.lnk -> C:\Program Files (x86)\wetter.com Desktop\wetter.com Desktop.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKCU - DefaultScope {D815FEEE-5EAB-48B5-B77E-A2A52D60075B} URL = SearchScopes: HKCU - {4C499952-9C89-4F6F-ACA9-BBDE2A5C5776} URL = SearchScopes: HKCU - {565E11A4-BCC7-417D-BEB0-9AF611C96216} URL = SearchScopes: HKCU - {D815FEEE-5EAB-48B5-B77E-A2A52D60075B} URL = BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java Runtime - {279384DD-3D1B-4086-8679-AA5EC7268BE1} - C:\Users\Nimmíra\AppData\Roaming\JavaRun\IE\JavaRun.dll (Oracle Corporation) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll () BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) Toolbar: HKLM-x32 - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll () Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll No File Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Nimmíra\AppData\Roaming\Mozilla\Firefox\Profiles\hbv1q2wc.default FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ No File FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF HKLM-x32\...\Thunderbird\Extensions: [avgthb@avg.com] - C:\Program Files (x86)\AVG\AVG2012\Thunderbird\ Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION ==================== Services (Whitelisted) ================= R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171600 2012-09-17] (Adobe Systems Incorporated) S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () R2 WMI_Hook_Service; C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe [105472 2010-01-07] (MICRO-STAR INT'L,.LTD.) S2 HOSTS Anti-PUPs; C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe -update [x] ==================== Drivers (Whitelisted) ==================== S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31968 2012-10-08] (Wondershare) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-05] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [240920 2013-11-04] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [194872 2013-10-24] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.) R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [28192 2009-07-17] (NVIDIA Corporation) S3 PRESONUS_AUDIOBOX_MIDI; C:\Windows\System32\drivers\psabusbm.sys [37496 2009-12-04] (Ploytec GmbH) S3 PRESONUS_AUDIOBOX_USB; C:\Windows\System32\Drivers\psabusbu.sys [462968 2009-12-04] (Ploytec GmbH) S3 PRESONUS_AUDIOBOX_WDM; C:\Windows\System32\drivers\psabusba.sys [50808 2009-12-04] (Ploytec GmbH) R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-08-10] (Corel Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-06 09:10 - 2014-01-06 09:17 - 00001071 _____ C:\windows\setupact.log 2014-01-06 09:10 - 2014-01-06 09:10 - 00000000 _____ C:\windows\setuperr.log 2014-01-05 20:51 - 2014-01-05 20:51 - 00000000 ____D C:\Program Files (x86)\ESET 2014-01-05 20:32 - 2014-01-05 20:32 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Malwarebytes 2014-01-05 20:32 - 2014-01-05 20:32 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-05 20:32 - 2014-01-05 20:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-05 20:32 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-01-05 19:42 - 2014-01-05 19:42 - 00000000 ____D C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs 2014-01-05 19:21 - 2014-01-05 19:23 - 00000000 ____D C:\AdwCleaner 2014-01-05 16:42 - 2014-01-06 11:29 - 00000000 ____D C:\FRST 2013-12-29 21:36 - 2013-12-30 14:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-12-17 20:17 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-12-17 20:17 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-12-17 20:17 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2013-12-17 20:17 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2013-12-17 20:17 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-12-17 20:17 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2013-12-17 20:17 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-12-17 20:17 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-12-17 20:17 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-12-17 20:17 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2013-12-17 20:17 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-12-17 20:17 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2013-12-17 20:17 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2013-12-17 20:17 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2013-12-17 20:17 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-12-17 20:17 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2013-12-17 20:17 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2013-12-17 20:17 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-12-17 20:17 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2013-12-17 20:17 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2013-12-17 20:17 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2013-12-17 20:17 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2013-12-17 20:17 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-12-17 20:17 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2013-12-17 20:17 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2013-12-17 20:17 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-12-17 20:17 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-12-17 20:17 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2013-12-17 20:17 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2013-12-17 20:17 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2013-12-17 20:17 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2013-12-16 13:20 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll 2013-12-16 13:20 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL 2013-12-16 13:20 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL 2013-12-16 13:20 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll 2013-12-16 13:19 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\windows\system32\IEUDINIT.EXE 2013-12-16 13:13 - 2013-12-16 13:13 - 01228800 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00626176 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat 2013-12-16 13:13 - 2013-12-16 13:13 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat 2013-12-16 13:13 - 2013-12-16 13:13 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00523776 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00453120 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2013-12-16 13:13 - 2013-12-16 13:13 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec 2013-12-16 13:13 - 2013-12-16 13:13 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00263376 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00244736 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00238288 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx 2013-12-16 13:13 - 2013-12-16 13:13 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx 2013-12-16 13:13 - 2013-12-16 13:13 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00040448 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe 2013-12-16 12:22 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll 2013-12-16 12:22 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll 2013-12-16 12:22 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll 2013-12-16 12:22 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll 2013-12-16 12:22 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll 2013-12-16 12:22 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll 2013-12-16 12:22 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2013-12-16 12:22 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll 2013-12-16 12:22 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll 2013-12-16 12:22 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx 2013-12-16 12:22 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll 2013-12-16 12:22 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshom.ocx 2013-12-16 12:22 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll 2013-12-16 12:22 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe 2013-12-16 12:22 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe 2013-12-16 12:22 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscript.exe 2013-12-16 12:22 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe 2013-12-16 12:22 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys 2013-12-16 12:22 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys 2013-12-08 13:45 - 2013-12-24 13:12 - 00000000 ____D C:\Users\Nimmíra\Desktop\Weihnachten ==================== One Month Modified Files and Folders ======= 2014-01-06 11:29 - 2014-01-05 16:42 - 00000000 ____D C:\FRST 2014-01-06 10:58 - 2011-11-29 21:55 - 00001112 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-06 10:33 - 2012-04-12 18:33 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job 2014-01-06 09:32 - 2010-12-23 21:44 - 01662746 _____ C:\windows\WindowsUpdate.log 2014-01-06 09:23 - 2009-07-14 05:45 - 00017600 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-06 09:23 - 2009-07-14 05:45 - 00017600 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-06 09:20 - 2010-12-25 18:15 - 00000000 ____D C:\Users\Nimmíra\AppData\Local\Adobe 2014-01-06 09:17 - 2014-01-06 09:10 - 00001071 _____ C:\windows\setupact.log 2014-01-06 09:10 - 2014-01-06 09:10 - 00000000 _____ C:\windows\setuperr.log 2014-01-06 09:10 - 2011-11-29 21:55 - 00001108 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-06 09:10 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT 2014-01-05 22:55 - 2011-01-11 15:29 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Winamp 2014-01-05 22:35 - 2011-08-25 20:46 - 00003922 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{0E626F3C-8A24-4FFB-84FD-07195C3D7244} 2014-01-05 20:51 - 2014-01-05 20:51 - 00000000 ____D C:\Program Files (x86)\ESET 2014-01-05 20:45 - 2009-08-14 08:59 - 00654150 _____ C:\windows\system32\perfh007.dat 2014-01-05 20:45 - 2009-08-14 08:59 - 00130022 _____ C:\windows\system32\perfc007.dat 2014-01-05 20:45 - 2009-07-14 06:13 - 01498742 _____ C:\windows\system32\PerfStringBackup.INI 2014-01-05 20:32 - 2014-01-05 20:32 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Malwarebytes 2014-01-05 20:32 - 2014-01-05 20:32 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-05 20:32 - 2014-01-05 20:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-05 19:55 - 2013-12-01 16:59 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Opera Software 2014-01-05 19:55 - 2013-12-01 16:59 - 00000000 ____D C:\Users\Nimmíra\AppData\Local\Opera Software 2014-01-05 19:55 - 2010-12-26 17:16 - 00000000 ____D C:\Program Files (x86)\Opera 2014-01-05 19:42 - 2014-01-05 19:42 - 00000000 ____D C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs 2014-01-05 19:23 - 2014-01-05 19:21 - 00000000 ____D C:\AdwCleaner 2014-01-05 19:23 - 2011-08-19 08:51 - 00000000 ____D C:\ProgramData\Uniblue 2014-01-05 19:17 - 2010-12-23 21:50 - 00000000 ___RD C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-05 18:37 - 2011-12-01 18:54 - 00000000 ____D C:\ProgramData\MFAData 2014-01-05 16:15 - 2010-12-23 21:50 - 00001435 _____ C:\Users\Nimmíra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-01 13:09 - 2012-10-13 19:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-30 14:34 - 2013-12-29 21:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-12-29 17:48 - 2009-11-13 15:59 - 00000000 ____D C:\windows\Panther 2013-12-26 12:14 - 2009-07-14 06:09 - 00000000 ____D C:\windows\System32\Tasks\WPD 2013-12-24 14:30 - 2010-12-23 21:50 - 00000000 ____D C:\Users\Nimmíra\AppData\Roaming\Adobe 2013-12-24 13:12 - 2013-12-08 13:45 - 00000000 ____D C:\Users\Nimmíra\Desktop\Weihnachten 2013-12-24 12:36 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache 2013-12-24 11:59 - 2011-11-29 21:55 - 00000000 ____D C:\Program Files (x86)\Google 2013-12-17 19:33 - 2012-04-12 18:33 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2013-12-17 19:33 - 2012-04-12 18:33 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater 2013-12-17 19:33 - 2011-05-15 19:52 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-17 19:32 - 2009-07-14 05:45 - 02045744 _____ C:\windows\system32\FNTCACHE.DAT 2013-12-17 19:30 - 2009-07-14 04:20 - 00000000 ____D C:\windows\PolicyDefinitions 2013-12-16 13:13 - 2013-12-16 13:13 - 01228800 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00626176 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat 2013-12-16 13:13 - 2013-12-16 13:13 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat 2013-12-16 13:13 - 2013-12-16 13:13 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00523776 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00453120 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2013-12-16 13:13 - 2013-12-16 13:13 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec 2013-12-16 13:13 - 2013-12-16 13:13 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00263376 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00244736 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00238288 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx 2013-12-16 13:13 - 2013-12-16 13:13 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx 2013-12-16 13:13 - 2013-12-16 13:13 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00040448 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll 2013-12-16 13:13 - 2013-12-16 13:13 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe 2013-12-16 13:13 - 2013-12-16 13:13 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe 2013-12-16 13:11 - 2009-08-14 10:21 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-16 13:08 - 2013-08-15 19:49 - 00000000 ____D C:\windows\system32\MRT 2013-12-16 13:07 - 2010-12-28 20:31 - 90708896 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2013-12-16 12:53 - 2011-11-29 21:55 - 00004108 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-16 12:53 - 2011-11-29 21:55 - 00003856 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore Some content of TEMP: ==================== C:\Users\Nimmíra\AppData\Local\Temp\Install_HOSTS_Anti-Adware.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-30 15:59 ==================== End Of Log ============================ |
06.01.2014, 11:51 | #10 |
/// TB-Ausbilder | Probleme mit vmtl. lollipop.exe Sieht gut aus. Schritt 1 Die Version deines Adobe PDF Readers ist veraltet, wir müssen ihn updaten:
Cleanup Zum Schluss werden wir jetzt noch unsere Tools (inklusive der Quarantäne-Ordner) wegräumen, die verseuchten Systemwiederherstellungspunkte löschen und alle Einstellungen wieder herrichten. Auch diese Schritte sind noch wichtig und sollten in der angegebenen Reihenfolge ausgeführt werden.
>> OK << Wir sind durch, deine Logs sehen für mich im Moment sauber aus. Ich habe dir nachfolgend ein paar Hinweise und Tipps zusammengestellt, die dazu beitragen sollen, dass du in Zukunft unsere Hilfe nicht mehr brauchen wirst. Bitte gib mir danach noch eine kurze Rückmeldung, wenn auch von deiner Seite keine Probleme oder Fragen mehr offen sind, damit ich dieses Thema als erledigt betrachten kann. Epilog: Tipps, Dos & Don'ts Aktualität von System und Software Das Betriebsystem Windows muss zwingend immer auf dem neusten Stand sein. Stelle sicher, dass die automatischen Updates aktiviert sind:
Auch die installierte Software sollte immer in der aktuellsten Version vorliegen. Speziell gilt das für den Browser, Java, Flash-Player und PDF-Reader, denn bekannte Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim blossen Besuch einer präparierten Website per Drive-by Download Malware zu installieren. Das kann sogar auf normalerweise legitimen Websites geschehen, wenn es einem Angreifer gelungen ist, seinen Code in die Seite einzuschleusen, und ist deshalb relativ unberechenbar.
Sicherheits-Software Eine Bemerkung vorneweg: Jede Softwarelösung hat ihre Schwächen. Die gesamte Verantwortung für die Sicherheit auf Software zu übertragen und einen Rundum-Schutz zu erwarten, wäre eine gefährliche Illusion. Bei unbedachtem oder bewusst risikoreichem Verhalten wird auch das beste Programm früher oder später seinen Dienst versagen (z.B. ein Virenscanner, der eine verseuchte Datei nicht erkennt). Trotzdem ist entsprechende Software natürlich wichtig und hilft dir in Kombination mit einem gut gewarteten (up-to-date) System und durchdachtem Verhalten, deinen Rechner sauber zu halten.
Es liegt in der Natur der Sache, dass die am weitesten verbreitete Anwendungs-Software auch am häufigsten von Malware-Autoren attackiert wird. Es kann daher bereits einen kleinen Sicherheitsgewinn darstellen, wenn man alternative Software (z.B. einen alternativen PDF Reader) benutzt. Anstelle des Internet Explorers kann man beispielsweise den Mozilla Firefox einsetzen, für welchen es zwei nützliche Addons zur Empfehlung gibt:
(Un-)Sicheres Verhalten im Internet Nebst unbemerkten Drive-by Installationen wird Malware aber auch oft mehr oder weniger aktiv vom Benutzer selbst installiert. Der Besuch zwielichtiger Websites kann bereits Risiken bergen. Und Downloads aus dubiosen Quellen sind immer russisches Roulette. Auch wenn der Virenscanner im Moment darin keine Bedrohung erkennt, muss das nichts bedeuten.
Oft wird auch versucht, den Benutzer mit mehr oder weniger trickreichen Methoden dazu zu bringen, eine für ihn verhängnisvolle Handlung selbst auszuführen (Überbegriff Social Engineering).
Nervige Adware (Werbung) und unnötige Toolbars werden auch meist durch den Benutzer selbst mitinstalliert.
Allgemeine Hinweise Abschliessend noch ein paar grundsätzliche Bemerkungen:
Wenn du möchtest, kannst du das Forum mit einer kleinen Spende unterstützen. Es bleibt mir nur noch, dir unbeschwertes und sicheres Surfen zu wünschen und dass wir uns hier so bald nicht wiedersehen.
__________________ cheers, Leo |
06.01.2014, 17:14 | #11 |
| Probleme mit vmtl. lollipop.exe Hab ich alles gemacht *stolz*, sollte jetzt wieder eine Weile gut gehen. Die Hinweise hab ich mir sogar ausgedruckt, werde sie beherzigen! Vielen lieben Dank für die kompetente und schnelle Hilfe!!! LG, Nimmira |
06.01.2014, 19:51 | #12 |
/// TB-Ausbilder | Probleme mit vmtl. lollipop.exe Freut mich, dass wir helfen konnten. Falls du dem Forum noch Verbesserungsvorschläge, Kritik oder ein Lob mitgeben möchtest, kannst du das hier tun. Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Ich bekomme somit keine Benachrichtigung mehr über neue Antworten. Solltest du das Thema erneut brauchen, schicke mir bitte eine PM und wir machen hier weiter. Jeder andere bitte diese Anleitung lesen und einen eigenen Thread erstellen.
__________________ cheers, Leo |
Themen zu Probleme mit vmtl. lollipop.exe |
andere, anderen, arbeitet, browser, browsern, dateien, falsch, hintergrund, hoffe, lollipop.exe, manager, nichts, opera, problem, probleme, programm, prozesse, schonmal, stelle, surfe, surfen, task manager, werbeseite, woche, wochen, überhaupt |