|
Log-Analyse und Auswertung: Fehlermeldung RunDll : Problem beim Starten C Program files (x86) HomeTab TB Updater.dll.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
11.01.2014, 16:33 | #1 |
| Fehlermeldung RunDll : Problem beim Starten C Program files (x86) HomeTab TB Updater.dll. Hallo, vielleicht kann mir ja hier einer weiter helfen. Seit heut morgen taucht beim Starten des Computers immer das Feld : "Problem beim Starten von C Program Files (x86) HomeTab TB Updater.dll auf. Das angegebene Modul konnte nicht gefunden werden. Ich habe schon avast durchlaufen lassen. Nichts gefunden. Malwarebytes Anti-Malware hat auch nichts gefunden CCleaner hab ich auch durchlaufen lassen. Logfile hänge ich an. Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-01-2014 03 Ran by annabel (administrator) on ANNABEL-PC on 11-01-2014 16:14:20 Running from C:\Users\annabel\Desktop\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\WINDOWS\System32\atiesrxx.exe (IDT, Inc.) C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\stacsv64.exe (AMD) C:\WINDOWS\System32\atieclxx.exe (Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe () C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE (Microsoft Corporation) C:\WINDOWS\System32\wlanext.exe (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (Andrea Electronics Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (O2Micro International) C:\WINDOWS\System32\drivers\o2flash.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe (SoftThinks) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe (Microsoft Corporation) C:\WINDOWS\System32\StikyNot.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Spotify Ltd) C:\Users\annabel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe () C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (SupportSoft, Inc.) C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Dropbox, Inc.) C:\Users\annabel\AppData\Roaming\Dropbox\bin\Dropbox.exe (SupportSoft, Inc.) C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation) C:\WINDOWS\splwow64.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1909032 2010-01-14] (Synaptics Incorporated) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-01-20] (IDT, Inc.) HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE [4968960 2009-07-17] (Dell Inc.) HKLM\...\Run: [QuickSet] - C:\Program Files\Dell\QuickSet\quickset.exe [3168336 2009-11-03] (Dell Inc.) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-12-17] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [409744 2009-06-24] (Creative Technology Ltd) HKLM-x32\...\Run: [Desktop Disc Tool] - C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe [498160 2009-10-15] () HKLM-x32\...\Run: [DellSupportCenter] - C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe [206064 2009-05-21] (SupportSoft, Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2014-01-11] (AVAST Software) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-19] (Apple Inc.) HKLM-x32\...\RunOnce: [Launcher] - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe [165184 2010-05-21] (Softthinks) HKLM-x32\...\RunOnce: [DSUpdateLauncher] - "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe" [161088 2010-05-21] () HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\WINDOWS\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKCU\...\Run: [Spotify Web Helper] - C:\Users\annabel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-12-20] (Spotify Ltd) HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6563096 2013-12-20] (SUPERAntiSpyware) Startup: C:\Users\annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\annabel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {F03A0117-1316-4913-A722-80201D170B9F} URL = SearchScopes: HKCU - {CA0E73B9-1157-403C-9956-3F169981D941} URL = SearchScopes: HKCU - {F03A0117-1316-4913-A722-80201D170B9F} URL = BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\c46nvgnm.default FF NewTab: about:home FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\delta-homes.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: vis - C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\c46nvgnm.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM [2013-10-20] FF Extension: Zotero Word for Windows Integration - C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\c46nvgnm.default\Extensions\zoteroWinWordIntegration@zotero.org [2013-12-10] FF Extension: HomeTab - C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\c46nvgnm.default\Extensions\{ad7ef860-f366-4be1-8d12-4363b9356947} [2013-10-20] FF Extension: Zotero - C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\c46nvgnm.default\Extensions\zotero@chnm.gmu.edu.xpi [2013-11-25] FF Extension: Adblock Edge - C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\c46nvgnm.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2013-09-11] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-03-16] FF HKCU\...\Firefox\Extensions: [{4340308e-3e37-4dd7-9192-8cf05ce9c9f2}] - C:\Program Files (x86)\LyriXeeker\130.xpi ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-11] (AVAST Software) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia) R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\STacSV64.exe [244736 2010-01-20] (IDT, Inc.) R2 wltrysvc; C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE [33280 2009-07-17] () ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-01-11] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2014-01-11] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-01-11] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1034464 2014-01-11] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [422216 2014-01-11] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [79672 2014-01-11] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-12-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-11] () R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] () S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-11 16:13 - 2014-01-11 16:13 - 00000000 ____D C:\FRST 2014-01-11 16:11 - 2014-01-11 16:11 - 00009890 _____ C:\Users\annabel\Desktop\install.txt 2014-01-11 15:33 - 2014-01-11 15:33 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-11 15:33 - 2014-01-11 15:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-11 15:05 - 2014-01-11 15:06 - 00001329 _____ C:\DelFix.txt 2014-01-11 13:03 - 2014-01-11 15:05 - 00000000 ____D C:\Windows\ERUNT 2014-01-11 12:49 - 2014-01-11 12:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-11 12:44 - 2014-01-11 12:45 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-11 12:44 - 2014-01-11 12:45 - 00000000 ____D C:\Program Files\iTunes 2014-01-11 12:44 - 2014-01-11 12:45 - 00000000 ____D C:\Program Files (x86)\iTunes 2014-01-11 12:44 - 2014-01-11 12:44 - 00000000 ____D C:\Program Files\iPod 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default\AppData\Roaming\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default\AppData\Local\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default User\AppData\Local\Apple Computer 2014-01-11 12:38 - 2014-01-11 12:38 - 00000000 ____D C:\Users\annabel\AppData\Local\Secunia PSI 2014-01-11 12:38 - 2014-01-11 12:38 - 00000000 ____D C:\Program Files (x86)\Secunia 2014-01-11 11:00 - 2014-01-11 15:11 - 00001242 _____ C:\Windows\PFRO.log 2014-01-11 11:00 - 2014-01-11 15:11 - 00000168 _____ C:\Windows\setupact.log 2014-01-11 11:00 - 2014-01-11 11:00 - 00305296 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-11 11:00 - 2014-01-11 11:00 - 00000000 _____ C:\Windows\setuperr.log 2014-01-11 10:25 - 2014-01-11 10:25 - 00064416 _____ C:\Users\annabel\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-11 09:43 - 2014-01-11 09:43 - 00001810 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\Users\annabel\AppData\Roaming\SUPERAntiSpyware.com 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2014-01-11 09:28 - 2014-01-11 09:28 - 00000000 ____D C:\Users\annabel\AppData\Roaming\AVAST Software 2014-01-11 09:23 - 2014-01-11 09:57 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys ==================== One Month Modified Files and Folders ======= 2014-01-11 16:13 - 2014-01-11 16:13 - 00000000 ____D C:\FRST 2014-01-11 16:11 - 2014-01-11 16:11 - 00009890 _____ C:\Users\annabel\Desktop\install.txt 2014-01-11 16:03 - 2009-07-14 05:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-11 16:03 - 2009-07-14 05:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-11 15:50 - 2013-03-16 16:53 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-11 15:33 - 2014-01-11 15:33 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-11 15:33 - 2014-01-11 15:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-11 15:33 - 2013-11-05 21:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-01-11 15:14 - 2013-03-29 20:02 - 00000000 ___RD C:\Users\annabel\Dropbox 2014-01-11 15:14 - 2013-03-29 20:00 - 00000000 ____D C:\Users\annabel\AppData\Roaming\Dropbox 2014-01-11 15:13 - 2013-03-16 15:22 - 00000000 ____D C:\Users\annabel\AppData\Local\SoftThinks 2014-01-11 15:13 - 2009-07-14 06:10 - 01822754 _____ C:\Windows\WindowsUpdate.log 2014-01-11 15:11 - 2014-01-11 11:00 - 00001242 _____ C:\Windows\PFRO.log 2014-01-11 15:11 - 2014-01-11 11:00 - 00000168 _____ C:\Windows\setupact.log 2014-01-11 15:11 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-11 15:06 - 2014-01-11 15:05 - 00001329 _____ C:\DelFix.txt 2014-01-11 15:05 - 2014-01-11 13:03 - 00000000 ____D C:\Windows\ERUNT 2014-01-11 12:49 - 2014-01-11 12:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-11 12:49 - 2010-08-30 00:16 - 00000000 ____D C:\Program Files\Java 2014-01-11 12:45 - 2014-01-11 12:44 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-11 12:45 - 2014-01-11 12:44 - 00000000 ____D C:\Program Files\iTunes 2014-01-11 12:45 - 2014-01-11 12:44 - 00000000 ____D C:\Program Files (x86)\iTunes 2014-01-11 12:44 - 2014-01-11 12:44 - 00000000 ____D C:\Program Files\iPod 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default\AppData\Roaming\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default\AppData\Local\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default User\AppData\Local\Apple Computer 2014-01-11 12:38 - 2014-01-11 12:38 - 00000000 ____D C:\Users\annabel\AppData\Local\Secunia PSI 2014-01-11 12:38 - 2014-01-11 12:38 - 00000000 ____D C:\Program Files (x86)\Secunia 2014-01-11 11:00 - 2014-01-11 11:00 - 00305296 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-11 11:00 - 2014-01-11 11:00 - 00000000 _____ C:\Windows\setuperr.log 2014-01-11 10:25 - 2014-01-11 10:25 - 00064416 _____ C:\Users\annabel\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-11 09:57 - 2014-01-11 09:23 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-01-11 09:43 - 2014-01-11 09:43 - 00001810 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\Users\annabel\AppData\Roaming\SUPERAntiSpyware.com 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2014-01-11 09:28 - 2014-01-11 09:28 - 00000000 ____D C:\Users\annabel\AppData\Roaming\AVAST Software 2014-01-11 09:23 - 2013-03-16 15:43 - 01034464 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00422216 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-01-11 09:23 - 2013-03-16 15:43 - 00207904 _____ C:\Windows\system32\Drivers\aswVmm.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2014-01-11 09:23 - 2013-03-16 15:43 - 00001968 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-01-11 09:23 - 2013-03-16 15:41 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-01-11 09:23 - 2009-07-14 18:58 - 00654400 _____ C:\Windows\system32\perfh007.dat 2014-01-11 09:23 - 2009-07-14 18:58 - 00130240 _____ C:\Windows\system32\perfc007.dat 2014-01-11 09:23 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-11 09:20 - 2013-03-16 15:43 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2014-01-11 09:20 - 2013-03-16 15:40 - 00000000 ____D C:\ProgramData\AVAST Software 2014-01-10 17:10 - 2013-03-16 15:22 - 00000000 ___RD C:\Users\annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-10 17:09 - 2013-03-29 20:02 - 00001029 _____ C:\Users\annabel\Desktop\Dropbox.lnk 2014-01-10 17:09 - 2013-03-29 20:01 - 00000000 ____D C:\Users\annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-10 17:02 - 2013-10-20 14:46 - 00000000 ____D C:\Users\annabel\AppData\Roaming\HomeTab 2014-01-10 16:33 - 2013-03-18 17:17 - 00000000 ____D C:\Users\annabel\AppData\Roaming\Skype 2014-01-09 11:24 - 2013-10-20 14:48 - 00000000 ____D C:\Users\annabel\Documents\Bewerbung 2014-01-08 16:45 - 2010-08-30 02:43 - 00000000 ____D C:\Windows\Panther 2014-01-06 08:31 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2014-01-05 12:05 - 2013-12-09 12:24 - 00000000 ____D C:\Users\annabel\Desktop\Bachelorarbeit 2014-01-05 11:14 - 2010-08-30 00:23 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup 2013-12-21 09:53 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-20 19:46 - 2013-11-20 14:58 - 00000000 ____D C:\Users\annabel\AppData\Roaming\Spotify 2013-12-20 16:34 - 2013-11-20 14:58 - 00000000 ____D C:\Users\annabel\AppData\Local\Spotify 2013-12-19 14:11 - 2013-03-16 15:43 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-12-15 13:31 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache Some content of TEMP: ==================== C:\Users\annabel\AppData\Local\Temp\sdanircmdc.exe C:\Users\annabel\AppData\Local\Temp\sdapskill.exe C:\Users\annabel\AppData\Local\Temp\SecurityCheck.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-09 12:55 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-01-2014 03 Ran by annabel at 2014-01-11 16:14:45 Running from C:\Users\annabel\Desktop\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader XI (11.0.04) - Deutsch (x32 Version: 11.0.04 - Adobe Systems Incorporated) Advanced Audio FX Engine (x32 Version: 1.12.05 - Creative Technology Ltd) Apple Application Support (x32 Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (x32 Version: 2.1.3.127 - Apple Inc.) ATI Catalyst Control Center (x32 Version: 2.009.1217.1709 - ) Avant Browser (remove only) (x32 Version: 12.5.0.0 - Avant Force) avast! Free Antivirus (x32 Version: 9.0.2011 - Avast Software) Bonjour (Version: 3.0.0.10 - Apple Inc.) Canon MP550 series MP Drivers (Version: - ) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Core Implementation (x32 Version: 2009.1217.1710.30775 - ATI) Hidden Catalyst Control Center Graphics Full Existing (x32 Version: 2009.1217.1710.30775 - ATI) Hidden Catalyst Control Center Graphics Full New (x32 Version: 2009.1217.1710.30775 - ATI) Hidden Catalyst Control Center Graphics Light (x32 Version: 2009.1217.1710.30775 - ATI) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2009.1217.1710.30775 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (x32 Version: 2009.1217.1710.30775 - ATI) Hidden Catalyst Control Center InstallProxy (x32 Version: 2009.1217.1710.30775 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2009.1217.1710.30775 - ATI) Hidden CCC Help Chinese Standard (x32 Version: 2009.1217.1709.30775 - ATI) Hidden CCC Help Chinese Traditional (x32 Version: 2009.1217.1709.30775 - ATI) Hidden CCC Help Danish (x32 Version: 2009.1217.1709.30775 - ATI) Hidden CCC Help Dutch (x32 Version: 2009.1217.1709.30775 - ATI) Hidden CCC Help English (x32 Version: 2009.1217.1709.30775 - ATI) Hidden CCC Help Finnish (x32 Version: 2009.1217.1709.30775 - ATI) Hidden CCC Help French (x32 Version: 2009.1217.1709.30775 - ATI) Hidden CCC Help German (x32 Version: 2009.1217.1709.30775 - ATI) Hidden CCC Help Italian (x32 Version: 2009.1217.1709.30775 - ATI) Hidden CCC Help Japanese (x32 Version: 2009.1217.1709.30775 - ATI) Hidden CCC Help Korean (x32 Version: 2009.1217.1709.30775 - ATI) Hidden CCC Help Norwegian (x32 Version: 2009.1217.1709.30775 - ATI) Hidden CCC Help Portuguese (x32 Version: 2009.1217.1709.30775 - ATI) Hidden CCC Help Russian (x32 Version: 2009.1217.1709.30775 - ATI) Hidden CCC Help Spanish (x32 Version: 2009.1217.1709.30775 - ATI) Hidden CCC Help Swedish (x32 Version: 2009.1217.1709.30775 - ATI) Hidden ccc-core-static (x32 Version: 2009.1217.1710.30775 - ATI) Hidden ccc-utility64 (Version: 2009.1217.1710.30775 - ATI) Hidden CCleaner (Version: 3.28 - Piriform) CintaNotes 2.4 (x32 Version: - Cinta Software) Cisco EAP-FAST Module (x32 Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (x32 Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (x32 Version: 1.1.6 - Cisco Systems, Inc.) Dell DataSafe Local Backup - Support Software (x32 Version: - Dell) Dell DataSafe Local Backup (x32 Version: 9.4.40 - Dell) Dell Dock (Version: 2.0 - Stardock Corporation) Hidden Dell Dock (x32 Version: - Stardock Corporation) Dell Edoc Viewer (Version: 1.0.0 - Dell Inc) Dell Getting Started Guide (x32 Version: 1.00.0000 - Dell Inc.) Dell Support Center (Support Software) (x32 Version: 2.5.09100 - Dell) Dell Webcam Central (x32 Version: 1.40.05 - Creative Technology Ltd) Dell Wireless WLAN Card Utility (Version: 5.30.21.0 - Dell Inc.) Dropbox (HKCU Version: 2.4.11 - Dropbox, Inc.) Free YouTube to MP3 Converter version 3.12.17.1125 (x32 Version: 3.12.17.1125 - DVDVideoSoft Ltd.) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179 - Intel Corporation) Intel(R) Turbo Boost Technology Driver (x32 Version: 01.02.00.1002 - Intel Corporation) iTunes (Version: 11.1.2.31 - Apple Inc.) Java 3D 1.3.1 (OpenGL) SDK (x32 Version: - ) Java 7 Update 45 (64-bit) (Version: 7.0.450 - Oracle) Java 7 Update 45 (x32 Version: 7.0.450 - Oracle) Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden Live! Cam Avatar Creator (x32 Version: 4.6.3009.1 - Creative Technology Ltd) LoJack Factory Installer (x32 Version: 1.0.0 - Absolute Software) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Excel 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Excel 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office PowerPoint 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Word 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (x32 Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (x32 Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla) MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden MyFreeCodec (HKCU Version: - ) Quickset64 (Version: 10.3.2 - Dell Inc.) Roxio Burn (x32 Version: 1.01 - Roxio) Hidden SAMSUNG USB Driver for Mobile Phones (Version: 1.5.22.0 - SAMSUNG Electronics Co., Ltd.) Secunia PSI (3.0.0.9016) (x32 Version: 3.0.0.9016 - Secunia) Shared C Run-time for x64 (Version: 10.0.0 - McAfee) Skins (x32 Version: 2009.1217.1710.30775 - ATI) Hidden Skype Toolbars (x32 Version: 1.0.4036 - Skype Technologies S.A.) Skype™ 5.10 (x32 Version: 5.10.116 - Skype Technologies S.A.) Spotify (HKCU Version: 0.9.6.81.gd359a796 - Spotify AB) SUPERAntiSpyware (Version: 5.7.1016 - SUPERAntiSpyware.com) Synaptics Pointing Device Driver (Version: 15.0.3.0 - Synaptics Incorporated) Überwachungstool für die Intel® Turbo-Boost-Technik (Version: 1.0.186.6 - Intel) Update for 2007 Microsoft Office System (KB967642) (x32 Version: - Microsoft) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft Office 2007 Help for Common Features (KB963673) (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office Excel 2007 Help (KB963678) (x32 Version: - Microsoft) Update for Microsoft Office Powerpoint 2007 Help (KB963669) (x32 Version: - Microsoft) Update for Microsoft Office Script Editor Help (KB963671) (x32 Version: - Microsoft) Update for Microsoft Office Word 2007 Help (KB963665) (x32 Version: - Microsoft) VIS (x32 Version: - ) VLC media player 2.1.1 (Version: 2.1.1 - VideoLAN) Windows Live Anmelde-Assistent (x32 Version: 5.000.818.5 - Microsoft Corporation) Windows Live Call (x32 Version: 14.0.8064.0206 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 14.0.8064.206 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Windows Live Essentials (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 14.0.8081.709 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 14.0.8091.0730 - Microsoft Corporation) Hidden Windows Live Sync (x32 Version: 14.0.8089.726 - Microsoft Corporation) Windows Live Writer (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Windows Live-Uploadtool (x32 Version: 14.0.8014.1029 - Microsoft Corporation) ==================== Restore Points ========================= 11-01-2014 14:05:37 Ende der Bereinigung ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {02EEDEC3-C885-42C0-B5C4-6F2224CE4575} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-02-19] (Piriform Ltd) Task: {480841DA-7556-49C6-8DEF-AA33D9944A56} - System32\Tasks\LoJack for Laptops Install => C:\Program Files (x86)\Absolute Software\LoJack Install\FactoryInstaller.exe [2009-11-26] (Absolute Software) Task: {4DDE8B80-88C3-4550-813D-E804050ECE78} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe Task: {57090E23-BA28-4A65-BE54-0726FA24147D} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-01-11] (AVAST Software) Task: {669D853B-27C2-4B1D-ABFD-439FD2275A87} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated) Task: {6DBDB446-3A6A-4477-A669-38F81F781EA7} - System32\Tasks\{73DCFDE4-4CE9-4B3F-85FA-FFD670664A70} => Firefox.exe hxxp://ui.skype.com/ui/0/6.3.0.107/de/abandoninstall?page=tsProgressBar Task: {7B8AB13D-DC32-4E0F-86A4-7107CFBD2141} - System32\Tasks\ProtectedSearch\Protected Search => C:\Program Files (x86)\HomeTab\ProtectedSearch.exe <==== ATTENTION Task: {9BA5F2EB-BD41-44C3-B18E-39BF71B8D2E8} - System32\Tasks\Browser Updater\Browser Updater => Rundll32.exe "C:\Program Files (x86)\HomeTab\TBUpdater.dll",TBCheckForUpdate Task: {9C0F123C-E299-4555-874C-29FD62C97CAE} - \Scheduled Update for Ask Toolbar No Task File Task: {C42FA99B-0CE1-444F-8BFE-545CBCE515EA} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: {EF987B95-EED8-46AF-A7D2-D5AA3FCB8E3F} - System32\Tasks\DD57FVM1\Administrator - Start WLAN Tray Applet => C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE [2009-07-17] (Dell Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2010-08-30 00:17 - 2009-07-17 02:06 - 00058368 _____ () C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlrmt.dll 2013-08-15 08:51 - 2013-08-15 08:51 - 00472576 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_64\VistaBridgeLibrary\eb84d003744ea2a3a4e0c0babb5d5874\VistaBridgeLibrary.ni.dll 2009-05-05 18:56 - 2009-05-05 18:56 - 00016384 ____R () c:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2010-08-30 00:21 - 2010-08-30 00:21 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2014-01-11 09:23 - 2014-01-10 17:04 - 02153984 _____ () C:\Program Files\AVAST Software\Avast\defs\14011000\algo.dll 2014-01-11 15:12 - 2014-01-11 10:06 - 02153984 _____ () C:\Program Files\AVAST Software\Avast\defs\14011100\algo.dll 2013-01-28 12:08 - 2013-01-28 12:08 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-01-28 12:08 - 2013-01-28 12:08 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2010-08-30 00:23 - 2010-05-21 17:58 - 00116032 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\PSTVdsDisk.dll 2010-08-30 00:23 - 2010-05-21 17:58 - 00128320 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll 2010-08-30 00:23 - 2010-05-21 17:58 - 01123648 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\LibXml2.dll 2010-08-30 00:23 - 2010-05-21 17:59 - 00079168 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll 2010-08-30 00:23 - 2010-05-21 17:58 - 00234816 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll 2010-08-30 00:23 - 2010-05-21 17:58 - 00075072 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll 2010-08-30 00:23 - 2010-05-21 17:58 - 00111936 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll 2010-08-30 00:23 - 2010-05-21 17:58 - 00121152 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll 2014-01-11 09:23 - 2014-01-11 09:23 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\annabel\AppData\Roaming\Dropbox\bin\libcef.dll 2013-07-10 17:07 - 2013-07-10 17:07 - 00756888 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/11/2014 03:14:28 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Adobe Reader XI (11.0.05) - Deutsch - Update "Adobe Reader XI (11.0.04)" konnte nicht installiert werden. Fehlercode 1638. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/11/2014 03:14:28 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Adobe Reader XI (11.0.05) - Deutsch - Update "Adobe Reader XI (11.0.01)" konnte nicht installiert werden. Fehlercode 1638. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/11/2014 03:14:28 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Adobe Reader XI (11.0.05) - Deutsch - Update "Adobe Reader XI (11.0.02)" konnte nicht installiert werden. Fehlercode 1638. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/11/2014 03:14:28 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Adobe Reader XI (11.0.05) - Deutsch - Update "Adobe Reader XI (11.0.03)" konnte nicht installiert werden. Fehlercode 1638. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/11/2014 03:14:28 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Adobe Reader XI (11.0.05) - Deutsch - Update "Adobe Reader XI (11.0.05)" konnte nicht installiert werden. Fehlercode 1638. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/11/2014 03:02:33 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (01/11/2014 02:56:10 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Adobe Reader XI (11.0.05) - Deutsch - Update "Adobe Reader XI (11.0.04)" konnte nicht installiert werden. Fehlercode 1638. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/11/2014 02:56:10 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Adobe Reader XI (11.0.05) - Deutsch - Update "Adobe Reader XI (11.0.01)" konnte nicht installiert werden. Fehlercode 1638. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/11/2014 02:56:10 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Adobe Reader XI (11.0.05) - Deutsch - Update "Adobe Reader XI (11.0.02)" konnte nicht installiert werden. Fehlercode 1638. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/11/2014 02:56:10 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Adobe Reader XI (11.0.05) - Deutsch - Update "Adobe Reader XI (11.0.03)" konnte nicht installiert werden. Fehlercode 1638. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 System errors: ============= Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 46% Total physical RAM: 3956.55 MB Available physical RAM: 2118.39 MB Total Pagefile: 7911.27 MB Available Pagefile: 5554.92 MB Total Virtual: 8192 MB Available Virtual: 8191.79 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:283.4 GB) (Free:177.91 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298 GB) (Disk ID: 7A730FFA) Partition 1: (Not Active) - (Size=39 MB) - (Type=DE) Partition 2: (Active) - (Size=15 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=283 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter Adobe Flash Player 11 ActiveX Adobe Systems Incorporated 11.12.2013 6,00MB 11.9.900.170 Adobe Flash Player 11 Plugin Adobe Systems Incorporated 11.12.2013 6,00MB 11.9.900.170 Adobe Reader XI (11.0.04) - Deutsch Adobe Systems Incorporated 28.09.2013 134MB 11.0.04 Advanced Audio FX Engine Creative Technology Ltd 30.08.2010 1.12.05 Apple Application Support Apple Inc. 03.10.2013 64,0MB 2.3.6 Apple Mobile Device Support Apple Inc. 03.10.2013 25,0MB 7.0.0.117 Apple Software Update Apple Inc. 31.03.2013 2,38MB 2.1.3.127 ATI Catalyst Control Center 30.08.2010 2.009.1217.1709 Avant Browser (remove only) Avant Force 23.08.2013 12.5.0.0 avast! Free Antivirus Avast Software 11.01.2014 9.0.2011 Bonjour Apple Inc. 03.10.2013 2,04MB 3.0.0.10 Canon MP550 series MP Drivers 07.04.2013 CCleaner Piriform 19.02.2013 3.28 CintaNotes 2.4 Cinta Software 20.10.2013 5,43MB Cisco EAP-FAST Module Cisco Systems, Inc. 29.08.2010 1,55MB 2.2.14 Cisco LEAP Module Cisco Systems, Inc. 29.08.2010 644KB 1.0.19 Cisco PEAP Module Cisco Systems, Inc. 29.08.2010 1,23MB 1.1.6 Dell DataSafe Local Backup Dell 29.08.2010 9.4.40 Dell DataSafe Local Backup - Support Software Dell 29.08.2010 Dell Dock 30.08.2010 Dell Dock Stardock Corporation 29.08.2010 Dell Getting Started Guide Dell Inc. 29.08.2010 1.00.0000 Dell Support Center (Support Software) Dell 29.08.2010 2.5.09100 Dell Webcam Central Creative Technology Ltd 30.08.2010 1.40.05 Dell Wireless WLAN Card Utility Dell Inc. 30.08.2010 5.30.21.0 Dropbox Dropbox, Inc. 10.01.2014 2.4.11 Free YouTube to MP3 Converter version 3.12.17.1125 DVDVideoSoft Ltd. 07.12.2013 116MB 3.12.17.1125 Intel(R) Management Engine Components Intel Corporation 01.04.2013 6.0.0.1179 Intel(R) Turbo Boost Technology Driver Intel Corporation 01.04.2013 01.02.00.1002 iTunes Apple Inc. 11.01.2014 215MB 11.1.2.31 Java 3D 1.3.1 (OpenGL) SDK 22.05.2013 Java 7 Update 45 Oracle 11.01.2014 120MB 7.0.450 Java 7 Update 45 (64-bit) Oracle 11.01.2014 118MB 7.0.450 Live! Cam Avatar Creator Creative Technology Ltd 29.08.2010 4.6.3009.1 LoJack Factory Installer Absolute Software 29.08.2010 0,99MB 1.0.0 Malwarebytes Anti-Malware Version 1.75.0.1300 Malwarebytes Corporation 25.10.2013 19,2MB 1.75.0.1300 Microsoft .NET Framework 4 Client Profile Microsoft Corporation 31.03.2013 38,8MB 4.0.30320 Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Corporation 31.03.2013 2,93MB 4.0.30320 Microsoft Office 2010 Microsoft Corporation 11.09.2013 8,27MB 14.0.4763.1000 Microsoft Office Excel 2007 Microsoft Corporation 22.03.2013 12.0.6612.1000 Microsoft Office PowerPoint 2007 Microsoft Corporation 22.03.2013 12.0.6612.1000 Microsoft Office Word 2007 Microsoft Corporation 22.03.2013 12.0.6612.1000 Microsoft Silverlight Microsoft Corporation 10.10.2013 149MB 5.1.20913.0 Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 29.08.2010 1,72MB 3.1.0000 Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Corporation 29.08.2010 625KB 1.0.1215.0 Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Corporation 29.08.2010 1,44MB 1.0.1215.0 Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 17.03.2013 300KB 8.0.61001 Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Corporation 29.08.2010 708KB 8.0.61000 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 29.08.2010 788KB 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 18.03.2013 788KB 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 16.03.2013 600KB 9.0.30729.6161 Mozilla Firefox 26.0 (x86 de) Mozilla 11.01.2014 49,5MB 26.0 Mozilla Maintenance Service Mozilla 11.01.2014 221KB 26.0 MyFreeCodec 31.03.2013 Quickset64 Dell Inc. 29.08.2010 10.3.2 Roxio Burn Roxio 30.08.2010 36,1MB 1.01 SAMSUNG USB Driver for Mobile Phones SAMSUNG Electronics Co., Ltd. 31.03.2013 34,9MB 1.5.22.0 Secunia PSI (3.0.0.9016) Secunia 11.01.2014 8,50MB 3.0.0.9016 Shared C Run-time for x64 McAfee 16.03.2013 2,78MB 10.0.0 Skype Toolbars Skype Technologies S.A. 29.08.2010 5,25MB 1.0.4036 Skype™ 5.10 Skype Technologies S.A. 18.03.2013 19,4MB 5.10.116 Spotify Spotify AB 20.12.2013 0.9.6.81.gd359a796 SUPERAntiSpyware SUPERAntiSpyware.com 11.01.2014 68,3MB 5.7.1016 Synaptics Pointing Device Driver Synaptics Incorporated 30.08.2010 15.0.3.0 VIS 20.10.2013 VLC media player 2.1.1 VideoLAN 11.01.2014 2.1.1 Windows Live Anmelde-Assistent Microsoft Corporation 29.08.2010 1,93MB 5.000.818.5 Windows Live Essentials Microsoft Corporation 30.08.2010 14.0.8089.0726 Windows Live Sync Microsoft Corporation 29.08.2010 2,79MB 14.0.8089.726 Windows Live-Uploadtool Microsoft Corporation 29.08.2010 224KB 14.0.8014.1029 Überwachungstool für die Intel® Turbo-Boost-Technik Intel 29.08.2010 1,12MB 1.0.186.6 |
11.01.2014, 18:32 | #2 |
/// the machine /// TB-Ausbilder | Fehlermeldung RunDll : Problem beim Starten C Program files (x86) HomeTab TB Updater.dll. hi,
__________________Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
12.01.2014, 14:54 | #3 |
| Fehlermeldung RunDll : Problem beim Starten C Program files (x86) HomeTab TB Updater.dll. Hi und Danke für die schnelle Antwort.
__________________Hier erst mal Malwarebytes Anti-Malware: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.12.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 annabel :: ANNABEL-PC [Administrator] 12.01.2014 13:39:27 mbam-log-2014-01-12 (13-39-27).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 350333 Laufzeit: 44 Minute(n), 18 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) AdwCleaner: Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 12/01/2014 um 14:33:19 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : annabel - ANNABEL-PC # Gestartet von : C:\Users\annabel\Desktop\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HomeTab Ordner Gelöscht : C:\Users\annabel\AppData\LocalLow\SimplyTech Ordner Gelöscht : C:\Users\annabel\AppData\Roaming\HomeTab Ordner Gelöscht : C:\Users\annabel\AppData\Roaming\Windows Net Data Ordner Gelöscht : C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\5dyf075u.default\Extensions\{ad7ef860-f366-4be1-8d12-4363b9356947} Ordner Gelöscht : C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_927011\Extensions\{ad7ef860-f366-4be1-8d12-4363b9356947} Ordner Gelöscht : C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_927011\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\delta-homes.xml Datei Gelöscht : C:\Windows\System32\Tasks\Browser Updater Datei Gelöscht : C:\Windows\System32\Tasks\ProtectedSearch ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3FC27B34-0C19-49DA-875E-1875DDD4A6B2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A} Schlüssel Gelöscht : HKCU\Software\Myfree Codec Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKLM\Software\Myfree Codec Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\5dyf075u.default\prefs.js ] [ Datei : C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\5gh2cggt.default\prefs.js ] [ Datei : C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_927011\prefs.js ] ************************* AdwCleaner[R0].txt - [3951 octets] - [12/01/2014 14:29:17] AdwCleaner[S0].txt - [3747 octets] - [12/01/2014 14:33:19] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3807 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows 7 Home Premium x64 Ran by annabel on 12.01.2014 at 14:40:00,37 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\annabel\AppData\Roaming\mozilla\firefox\profiles\5gh2cggt.default\minidumps [1 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 12.01.2014 at 14:48:22,41 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-01-2014 Ran by annabel (administrator) on ANNABEL-PC on 12-01-2014 14:49:15 Running from C:\Users\annabel\Desktop\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\WINDOWS\System32\atiesrxx.exe (IDT, Inc.) C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\stacsv64.exe (Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe (AMD) C:\WINDOWS\System32\atieclxx.exe () C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE (Microsoft Corporation) C:\WINDOWS\System32\wlanext.exe (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (Andrea Electronics Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (O2Micro International) C:\WINDOWS\System32\drivers\o2flash.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe (SoftThinks) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe (Microsoft Corporation) C:\WINDOWS\System32\StikyNot.exe (Spotify Ltd) C:\Users\annabel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe () C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe (SupportSoft, Inc.) C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Dropbox, Inc.) C:\Users\annabel\AppData\Roaming\Dropbox\bin\Dropbox.exe (SupportSoft, Inc.) C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1909032 2010-01-14] (Synaptics Incorporated) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-01-20] (IDT, Inc.) HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-17] (Dell Inc.) HKLM\...\Run: [QuickSet] - C:\Program Files\Dell\QuickSet\QuickSet.exe [3168336 2009-11-03] (Dell Inc.) HKLM-x32\...\Run: [StartCCC] - c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-12-17] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [409744 2009-06-24] (Creative Technology Ltd) HKLM-x32\...\Run: [Desktop Disc Tool] - c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe [498160 2009-10-15] () HKLM-x32\...\Run: [DellSupportCenter] - C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe [206064 2009-05-21] (SupportSoft, Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2014-01-11] (AVAST Software) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-19] (Apple Inc.) HKLM-x32\...\RunOnce: [Launcher] - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe [165184 2010-05-21] (Softthinks) HKLM-x32\...\RunOnce: [DSUpdateLauncher] - "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe" [161088 2010-05-21] () HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\WINDOWS\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKCU\...\Run: [Spotify Web Helper] - C:\Users\annabel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-12-20] (Spotify Ltd) HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6563096 2013-12-20] (SUPERAntiSpyware) Startup: C:\Users\annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\annabel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {CA0E73B9-1157-403C-9956-3F169981D941} URL = SearchScopes: HKCU - {F03A0117-1316-4913-A722-80201D170B9F} URL = BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\5gh2cggt.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Zotero - C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\5gh2cggt.default\Extensions\zotero@chnm.gmu.edu.xpi [2014-01-11] FF Extension: Adblock Plus - C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\5gh2cggt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-11] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-03-16] FF HKCU\...\Firefox\Extensions: [{4340308e-3e37-4dd7-9192-8cf05ce9c9f2}] - C:\Program Files (x86)\LyriXeeker\130.xpi ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-11] (AVAST Software) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia) R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\STacSV64.exe [244736 2010-01-20] (IDT, Inc.) R2 wltrysvc; C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe [3417088 2009-07-17] (Dell Inc.) ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-01-11] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2014-01-11] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-01-11] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1034464 2014-01-11] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [422216 2014-01-11] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [79672 2014-01-11] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-12-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-11] () R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] () S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-12 14:48 - 2014-01-12 14:48 - 00000760 _____ C:\Users\annabel\Desktop\JRT.txt 2014-01-12 14:36 - 2014-01-12 14:36 - 00003919 _____ C:\Users\annabel\Desktop\AdwCleaner[S0].txt 2014-01-12 14:26 - 2014-01-12 14:26 - 00002180 _____ C:\Users\annabel\Desktop\Malware.txt 2014-01-12 13:41 - 2014-01-12 14:33 - 00000000 ____D C:\AdwCleaner 2014-01-11 16:57 - 2014-01-11 16:57 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-11 16:57 - 2014-01-11 16:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-11 16:13 - 2014-01-12 14:49 - 00000000 ____D C:\FRST 2014-01-11 15:05 - 2014-01-11 15:06 - 00001329 _____ C:\DelFix.txt 2014-01-11 13:03 - 2014-01-11 15:05 - 00000000 ____D C:\Windows\ERUNT 2014-01-11 12:49 - 2014-01-11 12:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-11 12:44 - 2014-01-11 12:45 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-11 12:44 - 2014-01-11 12:45 - 00000000 ____D C:\Program Files\iTunes 2014-01-11 12:44 - 2014-01-11 12:45 - 00000000 ____D C:\Program Files (x86)\iTunes 2014-01-11 12:44 - 2014-01-11 12:44 - 00000000 ____D C:\Program Files\iPod 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default\AppData\Roaming\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default\AppData\Local\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default User\AppData\Local\Apple Computer 2014-01-11 12:38 - 2014-01-11 12:38 - 00000000 ____D C:\Users\annabel\AppData\Local\Secunia PSI 2014-01-11 12:38 - 2014-01-11 12:38 - 00000000 ____D C:\Program Files (x86)\Secunia 2014-01-11 11:00 - 2014-01-12 14:34 - 00000280 _____ C:\Windows\setupact.log 2014-01-11 11:00 - 2014-01-12 13:28 - 00003006 _____ C:\Windows\PFRO.log 2014-01-11 11:00 - 2014-01-11 11:00 - 00305296 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-11 11:00 - 2014-01-11 11:00 - 00000000 _____ C:\Windows\setuperr.log 2014-01-11 10:25 - 2014-01-11 10:25 - 00064416 _____ C:\Users\annabel\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-11 09:43 - 2014-01-11 09:43 - 00001810 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\Users\annabel\AppData\Roaming\SUPERAntiSpyware.com 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2014-01-11 09:28 - 2014-01-11 09:28 - 00000000 ____D C:\Users\annabel\AppData\Roaming\AVAST Software 2014-01-11 09:23 - 2014-01-11 09:57 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys ==================== One Month Modified Files and Folders ======= 2014-01-12 14:49 - 2014-01-11 16:13 - 00000000 ____D C:\FRST 2014-01-12 14:48 - 2014-01-12 14:48 - 00000760 _____ C:\Users\annabel\Desktop\JRT.txt 2014-01-12 14:44 - 2009-07-14 05:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-12 14:44 - 2009-07-14 05:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-12 14:37 - 2013-03-29 20:00 - 00000000 ____D C:\Users\annabel\AppData\Roaming\Dropbox 2014-01-12 14:36 - 2014-01-12 14:36 - 00003919 _____ C:\Users\annabel\Desktop\AdwCleaner[S0].txt 2014-01-12 14:36 - 2013-03-29 20:02 - 00000000 ___RD C:\Users\annabel\Dropbox 2014-01-12 14:36 - 2013-03-16 15:43 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2014-01-12 14:35 - 2013-03-16 15:22 - 00000000 ____D C:\Users\annabel\AppData\Local\SoftThinks 2014-01-12 14:34 - 2014-01-11 11:00 - 00000280 _____ C:\Windows\setupact.log 2014-01-12 14:34 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-12 14:33 - 2014-01-12 13:41 - 00000000 ____D C:\AdwCleaner 2014-01-12 14:33 - 2013-10-20 14:46 - 00000000 ____D C:\Windows\System32\Tasks\ProtectedSearch 2014-01-12 14:33 - 2013-10-20 14:46 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater 2014-01-12 14:33 - 2009-07-14 06:10 - 01871728 _____ C:\Windows\WindowsUpdate.log 2014-01-12 14:26 - 2014-01-12 14:26 - 00002180 _____ C:\Users\annabel\Desktop\Malware.txt 2014-01-12 13:50 - 2013-03-16 16:53 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-12 13:28 - 2014-01-11 11:00 - 00003006 _____ C:\Windows\PFRO.log 2014-01-11 16:57 - 2014-01-11 16:57 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-11 16:57 - 2014-01-11 16:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-11 16:57 - 2013-11-05 21:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-01-11 15:06 - 2014-01-11 15:05 - 00001329 _____ C:\DelFix.txt 2014-01-11 15:05 - 2014-01-11 13:03 - 00000000 ____D C:\Windows\ERUNT 2014-01-11 12:49 - 2014-01-11 12:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-11 12:49 - 2010-08-30 00:16 - 00000000 ____D C:\Program Files\Java 2014-01-11 12:45 - 2014-01-11 12:44 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-11 12:45 - 2014-01-11 12:44 - 00000000 ____D C:\Program Files\iTunes 2014-01-11 12:45 - 2014-01-11 12:44 - 00000000 ____D C:\Program Files (x86)\iTunes 2014-01-11 12:44 - 2014-01-11 12:44 - 00000000 ____D C:\Program Files\iPod 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default\AppData\Roaming\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default\AppData\Local\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default User\AppData\Local\Apple Computer 2014-01-11 12:38 - 2014-01-11 12:38 - 00000000 ____D C:\Users\annabel\AppData\Local\Secunia PSI 2014-01-11 12:38 - 2014-01-11 12:38 - 00000000 ____D C:\Program Files (x86)\Secunia 2014-01-11 11:00 - 2014-01-11 11:00 - 00305296 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-11 11:00 - 2014-01-11 11:00 - 00000000 _____ C:\Windows\setuperr.log 2014-01-11 10:25 - 2014-01-11 10:25 - 00064416 _____ C:\Users\annabel\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-11 09:57 - 2014-01-11 09:23 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-01-11 09:43 - 2014-01-11 09:43 - 00001810 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\Users\annabel\AppData\Roaming\SUPERAntiSpyware.com 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2014-01-11 09:28 - 2014-01-11 09:28 - 00000000 ____D C:\Users\annabel\AppData\Roaming\AVAST Software 2014-01-11 09:23 - 2013-03-16 15:43 - 01034464 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00422216 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-01-11 09:23 - 2013-03-16 15:43 - 00207904 _____ C:\Windows\system32\Drivers\aswVmm.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00001968 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-01-11 09:23 - 2013-03-16 15:41 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-01-11 09:23 - 2009-07-14 18:58 - 00654400 _____ C:\Windows\system32\perfh007.dat 2014-01-11 09:23 - 2009-07-14 18:58 - 00130240 _____ C:\Windows\system32\perfc007.dat 2014-01-11 09:23 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-11 09:20 - 2013-03-16 15:43 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2014-01-11 09:20 - 2013-03-16 15:40 - 00000000 ____D C:\ProgramData\AVAST Software 2014-01-10 17:10 - 2013-03-16 15:22 - 00000000 ___RD C:\Users\annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-10 17:09 - 2013-03-29 20:02 - 00001029 _____ C:\Users\annabel\Desktop\Dropbox.lnk 2014-01-10 17:09 - 2013-03-29 20:01 - 00000000 ____D C:\Users\annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-10 16:33 - 2013-03-18 17:17 - 00000000 ____D C:\Users\annabel\AppData\Roaming\Skype 2014-01-09 11:24 - 2013-10-20 14:48 - 00000000 ____D C:\Users\annabel\Documents\Bewerbung 2014-01-08 16:45 - 2010-08-30 02:43 - 00000000 ____D C:\Windows\Panther 2014-01-06 08:31 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2014-01-05 12:05 - 2013-12-09 12:24 - 00000000 ____D C:\Users\annabel\Desktop\Bachelorarbeit 2014-01-05 11:14 - 2010-08-30 00:23 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup 2013-12-21 09:53 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-20 19:46 - 2013-11-20 14:58 - 00000000 ____D C:\Users\annabel\AppData\Roaming\Spotify 2013-12-20 16:34 - 2013-11-20 14:58 - 00000000 ____D C:\Users\annabel\AppData\Local\Spotify 2013-12-19 14:11 - 2013-03-16 15:43 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-12-15 13:31 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache Some content of TEMP: ==================== C:\Users\annabel\AppData\Local\Temp\Quarantine.exe C:\Users\annabel\AppData\Local\Temp\sdanircmdc.exe C:\Users\annabel\AppData\Local\Temp\sdapskill.exe C:\Users\annabel\AppData\Local\Temp\SecurityCheck.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-09 12:55 ==================== End Of Log ============================ --- --- --- --- --- --- |
13.01.2014, 10:15 | #4 |
/// the machine /// TB-Ausbilder | Fehlermeldung RunDll : Problem beim Starten C Program files (x86) HomeTab TB Updater.dll.ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.01.2014, 12:23 | #5 |
| Fehlermeldung RunDll : Problem beim Starten C Program files (x86) HomeTab TB Updater.dll.Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=b059626dc67d6c4eba64b77846e9cbe6 # engine=16628 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-13 11:01:28 # local_time=2014-01-13 12:01:28 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 77 180091 185897 0 0 # compatibility_mode=5893 16776573 100 94 55734 141240738 0 0 # scanned=194453 # found=0 # cleaned=0 # scan_time=5339 Code:
ATTFilter Results of screen317's Security Check version 0.99.78 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Secunia PSI (3.0.0.9016) Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 45 Java 3D 1.3.1 (OpenGL) SDK Adobe Flash Player 11.9.900.170 Adobe Reader XI Mozilla Firefox (26.0) ````````Process Check: objlist.exe by Laurent```````` AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-01-2014 01 Ran by annabel (administrator) on ANNABEL-PC on 13-01-2014 12:21:25 Running from C:\Users\annabel\Desktop\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\WINDOWS\System32\atiesrxx.exe (IDT, Inc.) C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\stacsv64.exe (Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe (AMD) C:\WINDOWS\System32\atieclxx.exe () C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE (Microsoft Corporation) C:\WINDOWS\System32\wlanext.exe (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (Andrea Electronics Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (O2Micro International) C:\WINDOWS\System32\drivers\o2flash.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe (SoftThinks) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe (Microsoft Corporation) C:\WINDOWS\System32\StikyNot.exe (Spotify Ltd) C:\Users\annabel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe () C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe (SupportSoft, Inc.) C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (Dropbox, Inc.) C:\Users\annabel\AppData\Roaming\Dropbox\bin\Dropbox.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (SupportSoft, Inc.) C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation) C:\WINDOWS\splwow64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1909032 2010-01-14] (Synaptics Incorporated) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-01-20] (IDT, Inc.) HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-17] (Dell Inc.) HKLM\...\Run: [QuickSet] - C:\Program Files\Dell\QuickSet\QuickSet.exe [3168336 2009-11-03] (Dell Inc.) HKLM-x32\...\Run: [StartCCC] - c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-12-17] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [409744 2009-06-24] (Creative Technology Ltd) HKLM-x32\...\Run: [Desktop Disc Tool] - c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe [498160 2009-10-15] () HKLM-x32\...\Run: [DellSupportCenter] - C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe [206064 2009-05-21] (SupportSoft, Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2014-01-11] (AVAST Software) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-19] (Apple Inc.) HKLM-x32\...\RunOnce: [Launcher] - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe [165184 2010-05-21] (Softthinks) HKLM-x32\...\RunOnce: [DSUpdateLauncher] - "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe" [161088 2010-05-21] () HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\WINDOWS\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKCU\...\Run: [Spotify Web Helper] - C:\Users\annabel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-12-20] (Spotify Ltd) HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6563096 2013-12-20] (SUPERAntiSpyware) Startup: C:\Users\annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\annabel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {CA0E73B9-1157-403C-9956-3F169981D941} URL = SearchScopes: HKCU - {F03A0117-1316-4913-A722-80201D170B9F} URL = BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\5gh2cggt.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Zotero - C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\5gh2cggt.default\Extensions\zotero@chnm.gmu.edu.xpi [2014-01-11] FF Extension: Adblock Plus - C:\Users\annabel\AppData\Roaming\Mozilla\Firefox\Profiles\5gh2cggt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-11] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-03-16] FF HKCU\...\Firefox\Extensions: [{4340308e-3e37-4dd7-9192-8cf05ce9c9f2}] - C:\Program Files (x86)\LyriXeeker\130.xpi ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-11] (AVAST Software) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia) R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\STacSV64.exe [244736 2010-01-20] (IDT, Inc.) R2 wltrysvc; C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe [3417088 2009-07-17] (Dell Inc.) ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-01-11] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2014-01-11] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-01-11] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1034464 2014-01-11] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [422216 2014-01-11] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [79672 2014-01-11] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-12-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-11] () R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] () S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-12 13:41 - 2014-01-12 14:33 - 00000000 ____D C:\AdwCleaner 2014-01-11 16:57 - 2014-01-11 16:57 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-11 16:57 - 2014-01-11 16:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-11 16:13 - 2014-01-13 12:21 - 00000000 ____D C:\FRST 2014-01-11 15:05 - 2014-01-11 15:06 - 00001329 _____ C:\DelFix.txt 2014-01-11 13:03 - 2014-01-11 15:05 - 00000000 ____D C:\Windows\ERUNT 2014-01-11 12:49 - 2014-01-11 12:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-11 12:44 - 2014-01-11 12:45 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-11 12:44 - 2014-01-11 12:45 - 00000000 ____D C:\Program Files\iTunes 2014-01-11 12:44 - 2014-01-11 12:45 - 00000000 ____D C:\Program Files (x86)\iTunes 2014-01-11 12:44 - 2014-01-11 12:44 - 00000000 ____D C:\Program Files\iPod 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default\AppData\Roaming\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default\AppData\Local\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default User\AppData\Local\Apple Computer 2014-01-11 12:38 - 2014-01-11 12:38 - 00000000 ____D C:\Users\annabel\AppData\Local\Secunia PSI 2014-01-11 12:38 - 2014-01-11 12:38 - 00000000 ____D C:\Program Files (x86)\Secunia 2014-01-11 11:00 - 2014-01-13 09:17 - 00000336 _____ C:\Windows\setupact.log 2014-01-11 11:00 - 2014-01-12 13:28 - 00003006 _____ C:\Windows\PFRO.log 2014-01-11 11:00 - 2014-01-11 11:00 - 00305296 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-11 11:00 - 2014-01-11 11:00 - 00000000 _____ C:\Windows\setuperr.log 2014-01-11 10:25 - 2014-01-11 10:25 - 00064416 _____ C:\Users\annabel\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-11 09:43 - 2014-01-11 09:43 - 00001810 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\Users\annabel\AppData\Roaming\SUPERAntiSpyware.com 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2014-01-11 09:28 - 2014-01-11 09:28 - 00000000 ____D C:\Users\annabel\AppData\Roaming\AVAST Software 2014-01-11 09:23 - 2014-01-11 09:57 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys ==================== One Month Modified Files and Folders ======= 2014-01-13 12:21 - 2014-01-11 16:13 - 00000000 ____D C:\FRST 2014-01-13 11:50 - 2013-03-16 16:53 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-13 10:25 - 2009-07-14 18:58 - 00654400 _____ C:\Windows\system32\perfh007.dat 2014-01-13 10:25 - 2009-07-14 18:58 - 00130240 _____ C:\Windows\system32\perfc007.dat 2014-01-13 10:25 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-13 10:24 - 2010-08-30 00:23 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup 2014-01-13 09:27 - 2009-07-14 05:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-13 09:27 - 2009-07-14 05:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-13 09:22 - 2009-07-14 06:10 - 01909138 _____ C:\Windows\WindowsUpdate.log 2014-01-13 09:19 - 2013-03-29 20:02 - 00000000 ___RD C:\Users\annabel\Dropbox 2014-01-13 09:19 - 2013-03-29 20:00 - 00000000 ____D C:\Users\annabel\AppData\Roaming\Dropbox 2014-01-13 09:18 - 2013-03-16 15:22 - 00000000 ____D C:\Users\annabel\AppData\Local\SoftThinks 2014-01-13 09:17 - 2014-01-11 11:00 - 00000336 _____ C:\Windows\setupact.log 2014-01-13 09:17 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-12 14:36 - 2013-03-16 15:43 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2014-01-12 14:33 - 2014-01-12 13:41 - 00000000 ____D C:\AdwCleaner 2014-01-12 14:33 - 2013-10-20 14:46 - 00000000 ____D C:\Windows\System32\Tasks\ProtectedSearch 2014-01-12 14:33 - 2013-10-20 14:46 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater 2014-01-12 13:28 - 2014-01-11 11:00 - 00003006 _____ C:\Windows\PFRO.log 2014-01-11 16:57 - 2014-01-11 16:57 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-11 16:57 - 2014-01-11 16:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-11 16:57 - 2013-11-05 21:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-01-11 15:06 - 2014-01-11 15:05 - 00001329 _____ C:\DelFix.txt 2014-01-11 15:05 - 2014-01-11 13:03 - 00000000 ____D C:\Windows\ERUNT 2014-01-11 12:49 - 2014-01-11 12:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-11 12:49 - 2014-01-11 12:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-11 12:49 - 2010-08-30 00:16 - 00000000 ____D C:\Program Files\Java 2014-01-11 12:45 - 2014-01-11 12:44 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-11 12:45 - 2014-01-11 12:44 - 00000000 ____D C:\Program Files\iTunes 2014-01-11 12:45 - 2014-01-11 12:44 - 00000000 ____D C:\Program Files (x86)\iTunes 2014-01-11 12:44 - 2014-01-11 12:44 - 00000000 ____D C:\Program Files\iPod 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default\AppData\Roaming\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default\AppData\Local\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Apple Computer 2014-01-11 12:43 - 2014-01-11 12:43 - 00000000 ____D C:\Users\Default User\AppData\Local\Apple Computer 2014-01-11 12:38 - 2014-01-11 12:38 - 00000000 ____D C:\Users\annabel\AppData\Local\Secunia PSI 2014-01-11 12:38 - 2014-01-11 12:38 - 00000000 ____D C:\Program Files (x86)\Secunia 2014-01-11 11:00 - 2014-01-11 11:00 - 00305296 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-11 11:00 - 2014-01-11 11:00 - 00000000 _____ C:\Windows\setuperr.log 2014-01-11 10:25 - 2014-01-11 10:25 - 00064416 _____ C:\Users\annabel\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-11 09:57 - 2014-01-11 09:23 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-01-11 09:43 - 2014-01-11 09:43 - 00001810 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\Users\annabel\AppData\Roaming\SUPERAntiSpyware.com 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2014-01-11 09:43 - 2014-01-11 09:43 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2014-01-11 09:28 - 2014-01-11 09:28 - 00000000 ____D C:\Users\annabel\AppData\Roaming\AVAST Software 2014-01-11 09:23 - 2013-03-16 15:43 - 01034464 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00422216 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-01-11 09:23 - 2013-03-16 15:43 - 00207904 _____ C:\Windows\system32\Drivers\aswVmm.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2014-01-11 09:23 - 2013-03-16 15:43 - 00001968 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-01-11 09:23 - 2013-03-16 15:41 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-01-11 09:20 - 2013-03-16 15:43 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2014-01-11 09:20 - 2013-03-16 15:40 - 00000000 ____D C:\ProgramData\AVAST Software 2014-01-10 17:10 - 2013-03-16 15:22 - 00000000 ___RD C:\Users\annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-10 17:09 - 2013-03-29 20:02 - 00001029 _____ C:\Users\annabel\Desktop\Dropbox.lnk 2014-01-10 17:09 - 2013-03-29 20:01 - 00000000 ____D C:\Users\annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-10 16:33 - 2013-03-18 17:17 - 00000000 ____D C:\Users\annabel\AppData\Roaming\Skype 2014-01-09 11:24 - 2013-10-20 14:48 - 00000000 ____D C:\Users\annabel\Documents\Bewerbung 2014-01-08 16:45 - 2010-08-30 02:43 - 00000000 ____D C:\Windows\Panther 2014-01-06 08:31 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2014-01-05 12:05 - 2013-12-09 12:24 - 00000000 ____D C:\Users\annabel\Desktop\Bachelorarbeit 2013-12-21 09:53 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-20 19:46 - 2013-11-20 14:58 - 00000000 ____D C:\Users\annabel\AppData\Roaming\Spotify 2013-12-20 16:34 - 2013-11-20 14:58 - 00000000 ____D C:\Users\annabel\AppData\Local\Spotify 2013-12-19 14:11 - 2013-03-16 15:43 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-12-15 13:31 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache Some content of TEMP: ==================== C:\Users\annabel\AppData\Local\Temp\Quarantine.exe C:\Users\annabel\AppData\Local\Temp\sdanircmdc.exe C:\Users\annabel\AppData\Local\Temp\sdapskill.exe C:\Users\annabel\AppData\Local\Temp\SecurityCheck.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-09 12:55 ==================== End Of Log ============================ --- --- --- Vielen herzlichen Dank ! Fehlermeldung wird beim Starten des Computers nicht mehr angezeigt |
14.01.2014, 09:37 | #6 |
/// the machine /// TB-Ausbilder | Fehlermeldung RunDll : Problem beim Starten C Program files (x86) HomeTab TB Updater.dll. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] C:\Program Files\Enigma Software Group Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ --> Fehlermeldung RunDll : Problem beim Starten C Program files (x86) HomeTab TB Updater.dll. |
14.01.2014, 14:19 | #7 |
| Fehlermeldung RunDll : Problem beim Starten C Program files (x86) HomeTab TB Updater.dll.Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-01-2014 01 Ran by annabel at 2014-01-14 14:09:30 Run:1 Running from C:\Users\annabel\Desktop\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] C:\Program Files\Enigma Software Group ***************** esgiguard => Service deleted successfully. C:\Program Files\Enigma Software Group => Moved successfully. ==== End of Fixlog ==== |
15.01.2014, 09:33 | #8 |
/// the machine /// TB-Ausbilder | Fehlermeldung RunDll : Problem beim Starten C Program files (x86) HomeTab TB Updater.dll. Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Fehlermeldung RunDll : Problem beim Starten C Program files (x86) HomeTab TB Updater.dll. |
adblock, antivirus, bonjour, branding, browser, converter, desktop, device driver, dvdvideosoft ltd., error, excel, fehlercode 1, flash player, home, homepage, installation, logfile, mozilla, mp3, msiinstaller, nicht installiert, plug-in, problem, registry, richtlinie, rundll, scan, secunia psi, security, software, spotify web helper, starten, svchost.exe, system, usb, vista |