Plagegeister aller Art und deren Bekämpfung: nach Säuberung: System "hängt" CPU-Auslastung sehr hoch wegen Browser,Flash, HostprozessWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
| ![]() nach Säuberung: System "hängt" CPU-Auslastung sehr hoch wegen Browser,Flash, Hostprozess Hallo Ihr Lieben, ich habe hier schon einiges gelesen und möchte Euch für Eure Unterstützung herzlich danken. Mein Problem ist, ich hatte meinen Laptop letzte Woche von Malware etc. erfolgreich gesäubert gehabt mit Malwarebytes, ADWCleaner und dem Eset Smartinstaller. Ich hatte NextLive.A drauf und in der Registry hatte ich einen PUP.Optional.DynConIE.A - Trojan.Agent und PUP.Optional.PlusHD.A und so weiter. Ich habe Log-Files davon, die kann ich hier rein kopieren. Nachdem dann keine Meldungen mehr kamen dachte ich, jetzt wäre alles in Ordnung. Ich habe den Norton InternetSecurity V drauf und wähnte mich eigentlich sicher. Nun muss ich jeden Tag mit dem Laptop übers Internet arbeiten. Dabei gehen sehr viele Daten übers Internet, was bisher kein Problem war. Jedoch gestern und heute kann ich fast nicht mehr arbeiten. Mein System wird total gebremst, es stoppt sogar kurzzeitig, dass ich nicht mal mehr die Maus bewegen kann und ich weiß nicht mehr weiter, weil ich nichts finde. Ich habe heute noch mal Malwarebytes komplett laufen lassen, aber der findet nichts, alles clean. Ich bin ziemlich verzweifelt, weil ich nur übers Internet arbeiten kann. Ich wäre wirklich sehr froh, wenn mir helfen würde. Lieben Dank im Voraus. Bethesda |
![]() | #2 |
nach Säuberung: System "hängt" CPU-Auslastung sehr hoch wegen Browser,Flash, Hostprozess hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________
![]() | #3 |
| ![]() nach Säuberung: System "hängt" CPU-Auslastung sehr hoch wegen Browser,Flash, Hostprozess Hallo,
__________________vielen Dank für Deine Unterstützung, das ging aber sehr schnell. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-01-2014 Ran by Dolmi (administrator) on ID_NETZ on 23-01-2014 20:03:02 Running from C:\Users\Dolmi\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\eEBAPI\eEBSvc.exe (Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Agere Systems) C:\Windows\System32\agrsmsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (Seagate Technology LLC) D:\Program Files\Sync\FreeAgentService.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe ( ) C:\Windows\System32\lxcfcoms.exe (Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\\NIS.exe (pdfforge GbR) C:\Program Files\PDF Architect\HelperService.exe (pdfforge GbR) C:\Program Files\PDF Architect\ConversionService.exe (StarWind Software) D:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe (TeamViewer GmbH) D:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\\NIS.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe (InstallShield Software Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Acronis) C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Microsoft Corporation) C:\Windows\System32\wpcumi.exe (Research In Motion Limited) C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Apple Inc.) D:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Research In Motion Limited) C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynToshiba.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\igfxext.exe () C:\Windows\System32\dmwu.exe () C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Iminent) C:\Program Files\Common Files\Umbrella\Umbrella.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) D:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation) HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [411768 2006-12-19] (TOSHIBA Corporation) HKLM\...\Run: [HSON] - C:\Program Files\TOSHIBA\TBS\HSON.exe [55416 2006-12-07] (TOSHIBA Corporation) HKLM\...\Run: [SmoothView] - C:\Program Files\Toshiba\SmoothView\SmoothView.exe [509496 2007-04-03] (TOSHIBA Corporation) HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [538744 2007-03-23] (TOSHIBA Corporation) HKLM\...\Run: [HWSetup] - C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [413696 2006-11-01] (TOSHIBA Electronics, Inc.) HKLM\...\Run: [SVPWUTIL] - C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe [438272 2006-03-22] (TOSHIBA) HKLM\...\Run: [topi] - C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe [577536 2007-04-02] (TOSHIBA) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1451304 2009-03-20] (Synaptics Incorporated) HKLM\...\Run: [Toshiba Registration] - C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe [571024 2007-02-19] (Toshiba) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [174872 2007-02-12] (Intel Corporation) HKLM\...\Run: [SynTPStart] - C:\Program Files\Synaptics\SynTP\SynTPStart.exe [204800 2007-07-27] (Synaptics, Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4702208 2007-09-03] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Windows\Skytel.exe [1826816 2007-08-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [FreePDF Assistant] - C:\Program Files\FreePDF_XP\fpassist.exe [312320 2007-06-26] (shbox.de) HKLM\...\Run: [ISUSScheduler] - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-16] (InstallShield Software Corporation) HKLM\...\Run: [TrueImageMonitor.exe] - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [1194728 2007-02-17] (Acronis) HKLM\...\Run: [AcronisTimounterMonitor] - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [1966928 2007-02-17] (Acronis) HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [149024 2007-02-16] (Acronis) HKLM\...\Run: [WPCUMI] - C:\Windows\system32\WpcUmi.exe [176128 2006-11-02] (Microsoft Corporation) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [RIMBBLaunchAgent.exe] - C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [267792 2013-01-17] (Research In Motion Limited) HKLM\...\Run: [QuickTime Task] - D:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - D:\Program Files\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKLM\...\Run: [WinampAgent] - d:\Program Files\Winamp\winampa.exe [74752 2010-07-12] (Nullsoft, Inc.) HKLM\...\Run: [Iminent] - C:\Program Files\Iminent\Iminent.exe [1074736 2014-01-07] (Iminent) HKLM\...\Run: [IminentMessenger] - C:\Program Files\Iminent\Iminent.Messengers.exe [884784 2014-01-07] (Iminent) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [AlcoholAutomount] - d:\Program Files\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe [33120 2010-08-20] (Alcohol Soft Development Team) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation) HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil32_11_9_900_170_Plugin.exe -update plugin [839560 2013-12-11] (Adobe Systems Incorporated) HKCU\...\Policies\system: [LogonHoursAction] 2 HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 MountPoints2: {3acc327a-db62-11de-8f30-8b74867ae91f} - G:\LaunchU3.exe -a MountPoints2: {91288b47-8680-11dd-aa7d-0013e8b8cdd1} - E:\starter.exe HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Default\...\Run: [TOSCDSPD] - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2006-11-13] (TOSHIBA) HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Default User\...\Run: [TOSCDSPD] - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2006-11-13] (TOSHIBA) Lsa: [Authentication Packages] msv1_0 relog_ap ==================== Internet (Whitelisted) ==================== ProxyServer: localhost:8080 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.msn.com/?ocid=OIE9MSE&PC=UP09 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://de.msn.com/?ocid=OIE9MSE&PC=UP09 SearchScopes: HKLM - DefaultScope value is missing. BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll (IObit) BHO: jollywallet - {11111111-1111-1111-1111-110111251155} - C:\Program Files\jollywallet\jollywallet-bho.dll (jollywallet) BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GbR) BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\\coIEPlg.dll (Symantec Corporation) BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\\IPS\IPSBHO.DLL (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\IE\jre7\bin\ssv.dll (Oracle Corporation) BHO: No Name - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Updater By SweetPacks - {C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD} - C:\Program Files\Updater By SweetPacks\Extension32.dll () BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\IE\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - d:\Program Files\SUPERAntiSpyware\SASSEH.DLL No File [ ] Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 02 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 03 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 04 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 05 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 06 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 07 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 08 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 20 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] Tcpip\..\Interfaces\{1E15786F-368E-4303-9BE7-439A0D0888EC}: [NameServer] FireFox: ======== FF ProfilePath: C:\Users\Dolmi\AppData\Roaming\Mozilla\Firefox\Profiles\k22mrdjm.default-1389800339087 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1205146.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - D:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Windows\system32\npdeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin - D:\Program Files\Java\IE\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - D:\Program Files\Java\IE\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - D:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @RIM.com/WebSLLauncher,version=1.0 - C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll () FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: jollywallet - C:\Users\Dolmi\AppData\Roaming\Mozilla\Firefox\Profiles\k22mrdjm.default-1389800339087\Extensions\crossriderapp12555@crossrider.com [2014-01-23] FF Extension: Iminent - C:\Users\Dolmi\AppData\Roaming\Mozilla\Firefox\Profiles\k22mrdjm.default-1389800339087\Extensions\webbooster@iminent.com.xpi [2014-01-23] FF Extension: SweetPacks Toolbar for Firefox - C:\Users\Dolmi\AppData\Roaming\Mozilla\Firefox\Profiles\k22mrdjm.default-1389800339087\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi [2014-01-23] FF Extension: Skype extension for Firefox - C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED} [2013-12-12] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2013-12-12] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2013-12-12] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt [2013-03-01] FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn\ [] FF HKLM\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF [2013-11-25] FF HKLM\...\Firefox\Extensions: [{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}] - C:\Program Files\Updater By SweetPacks\Firefox FF Extension: Updater By SweetPacks - C:\Program Files\Updater By SweetPacks\Firefox [2014-01-23] Chrome: ======= CHR Extension: (YouTube) - C:\Users\Dolmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-06-06] CHR Extension: (Google Search) - C:\Users\Dolmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-06-06] CHR Extension: (Updater By SweetPacks) - C:\Users\Dolmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd [2014-01-23] CHR Extension: (Iminent) - C:\Users\Dolmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl [2014-01-23] CHR Extension: (jollywallet) - C:\Users\Dolmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\jiekonljbeipfklhchhdjddejaennfnl [2014-01-23] CHR Extension: (Norton Identity Protection) - C:\Users\Dolmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2013-06-06] CHR Extension: (Google Wallet) - C:\Users\Dolmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-27] CHR Extension: (Gmail) - C:\Users\Dolmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-06-06] CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files\Norton Internet Security\Engine\\Exts\Chrome.crx [2013-11-21] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ========================== Services (Whitelisted) ================= R2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [411168 2007-02-16] (Acronis) R3 Blackberry Device Manager; C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [577536 2013-01-18] (Research In Motion Limited) R2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\eEBAPI\eEBSVC.exe [90112 2004-11-17] (SEIKO EPSON CORPORATION) S3 FirebirdServerMAGIXInstance; C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) R2 FreeAgentGoNext Service; D:\Program Files\Sync\FreeAgentService.exe [189736 2009-09-25] (Seagate Technology LLC) R2 IBUpdaterService; C:\Windows\system32\dmwu.exe [1171760 2013-05-21] () S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2151744 2014-01-14] (IObit) R2 lxcf_device; C:\Windows\system32\lxcfcoms.exe [537520 2007-02-23] ( ) R2 NIS; C:\Program Files\Norton Internet Security\Engine\\NIS.exe [275696 2013-10-08] (Symantec Corporation) R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR) R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR) R2 SProtection; C:\Program Files\Common Files\Umbrella\umbrella.exe [2916672 2014-01-07] (Iminent) R2 StarWindServiceAE; d:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) S2 SystemStoreService; C:\Program Files\SoftwareUpdater\SystemStore.exe [297984 2014-01-23] () R2 TeamViewer9; d:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe [5341536 2013-12-17] (TeamViewer GmbH) R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.) R2 Updater By SweetPacks; C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe [188760 2013-02-28] () S3 usnjsvc; C:\Program Files\Windows Live\Messenger\usnsvc.exe [98328 2007-10-18] (Microsoft Corporation) S3 WLSetupSvc; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [266240 2007-10-25] (Microsoft Corporation) S2 Automatisches LiveUpdate - Scheduler; "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [x] S2 SkypeUpdate; "D:\Program Files\Skype\Updater\Updater.exe" [x] S2 TempoMonitoringService; "E:\Program Files\Toshiba TEMPO\TempoSVC.exe" [x] S2 Update EnhanceTronic; "C:\Program Files\EnhanceTronic\updateEnhanceTronic.exe" [x] ==================== Drivers (Whitelisted) ==================== S2 ALIWEHCD; C:\Windows\System32\Drivers\mfpec.sys [53152 2006-07-24] (None) S3 AliWGP; C:\Windows\System32\DRIVERS\mfpcomp.sys [10063 2006-06-02] (None) R1 BHDrvx86; C:\Program Files\Norton Internet Security\NortonData\\Definitions\BASHDefs\20140121.001\BHDrvx86.sys [1098968 2013-12-18] (Symantec Corporation) S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [28048 2010-02-05] (CSR, plc) R1 ccSet_NIS; C:\Windows\system32\drivers\NIS\1501000.012\ccSetx86.sys [127064 2013-09-26] (Symantec Corporation) R0 CplIR; C:\Windows\System32\DRIVERS\CplIR.SYS [14848 2007-03-06] (COMPAL ELECTRONIC INC.) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376920 2013-12-07] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [108120 2013-11-20] (Symantec Corporation) S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [53184 2007-06-27] (FTDI Ltd.) R1 IDSVix86; C:\Program Files\Norton Internet Security\NortonData\\Definitions\IPSDefs\20140122.001\IDSvix86.sys [394456 2014-01-21] (Symantec Corporation) S3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [20992 2008-01-19] (Microsoft Corporation) R0 LPCFilter; C:\Windows\System32\DRIVERS\LPCFilter.sys [19456 2006-07-28] (COMPAL ELECTRONIC INC.) R3 MonitorFunction; C:\Windows\System32\DRIVERS\TVMonitor.sys [13304 2013-10-17] (TeamViewer GmbH) R3 NAVENG; C:\Program Files\Norton Internet Security\NortonData\\Definitions\VirusDefs\20140123.002\NAVENG.SYS [93272 2013-12-07] (Symantec Corporation) R3 NAVEX15; C:\Program Files\Norton Internet Security\NortonData\\Definitions\VirusDefs\20140123.002\NAVEX15.SYS [1612376 2013-12-07] (Symantec Corporation) S3 OVT511Plus; C:\Windows\System32\Drivers\omcamvid.sys [167816 2001-09-18] (OmniVision Technologies, Inc.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [436792 2011-12-22] () R3 SRTSP; C:\Windows\System32\Drivers\NIS\1501000.012\SRTSP.SYS [651352 2013-09-27] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NIS\1501000.012\SRTSPX.SYS [32344 2013-09-10] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NIS\1501000.012\SYMDS.SYS [367704 2013-09-10] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NIS\1501000.012\SYMEFA.SYS [935512 2013-09-27] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142936 2013-11-21] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NIS\1501000.012\Ironx86.SYS [206936 2013-09-27] (Symantec Corporation) R1 SYMTDIv; C:\Windows\System32\Drivers\NIS\1501000.012\SYMTDIV.SYS [383576 2013-09-26] (Symantec Corporation) R3 teamviewervpn; C:\Windows\System32\DRIVERS\teamviewervpn.sys [25088 2008-01-25] (TeamViewer GmbH) R2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [32768 2009-08-06] (Acronis) R2 uacFlt; C:\Windows\System32\DRIVERS\uacflt.sys [21276 2002-05-03] (Micronas GmbH) S3 vncmirror; C:\Windows\System32\DRIVERS\vncmirror.sys [4608 2013-01-22] (RealVNC Ltd.) R3 WUSBVBus; C:\Windows\System32\DRIVERS\mfpvbus.sys [9472 2006-08-03] (None) U3 a8az9vid; C:\Windows\System32\Drivers\a8az9vid.sys [0 ] (Microsoft Corporation) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 BlueletAudio; system32\DRIVERS\blueletaudio.sys [x] S3 BlueletSCOAudio; system32\DRIVERS\BlueletSCOAudio.sys [x] S3 BT; system32\DRIVERS\btnetdrv.sys [x] S3 Btcsrusb; System32\Drivers\btcusb.sys [x] S0 BTHidEnum; System32\Drivers\vbtenum.sys [x] S0 BTHidMgr; System32\Drivers\BTHidMgr.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP2\WNt500x86\Sandra.sys [x] U2 srservice; S3 tosporte; system32\DRIVERS\tosporte.sys [x] S3 tosrfbd; system32\DRIVERS\tosrfbd.sys [x] S3 tosrfbnp; System32\Drivers\tosrfbnp.sys [x] S3 Tosrfcom; System32\Drivers\tosrfcom.sys [x] S3 Tosrfhid; system32\DRIVERS\Tosrfhid.sys [x] S3 tosrfnds; system32\DRIVERS\tosrfnds.sys [x] S3 TosRfSnd; system32\drivers\tosrfsnd.sys [x] S3 Tosrfusb; system32\DRIVERS\tosrfusb.sys [x] S3 TpChoice; system32\DRIVERS\TpChoice.sys [x] S3 VComm; system32\DRIVERS\VComm.sys [x] S3 VcommMgr; System32\Drivers\VcommMgr.sys [x] S3 VHidMinidrv; system32\drivers\VHIDMini.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-23 20:01 - 2014-01-23 20:02 - 00030361 _____ C:\Users\Dolmi\Desktop\Addition.txt 2014-01-23 20:00 - 2014-01-23 20:03 - 00028305 _____ C:\Users\Dolmi\Desktop\FRST.txt 2014-01-23 19:59 - 2014-01-23 19:59 - 00000000 ____D C:\FRST 2014-01-23 19:58 - 2014-01-23 19:58 - 01222144 _____ (Farbar) C:\Users\Dolmi\Desktop\FRST.exe 2014-01-23 19:48 - 2014-01-23 19:48 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\Iminent 2014-01-23 19:47 - 2014-01-23 19:47 - 00000611 _____ C:\Windows\system32\InstallUtil.InstallLog 2014-01-23 19:47 - 2014-01-23 19:47 - 00000000 ____D C:\ProgramData\Iminent 2014-01-23 19:46 - 2014-01-23 19:47 - 00000000 ____D C:\Program Files\Iminent 2014-01-23 19:46 - 2014-01-23 19:46 - 00000000 ____D C:\Program Files\Common Files\Umbrella 2014-01-23 19:44 - 2014-01-23 19:45 - 00000000 ____D C:\Program Files\jollywallet 2014-01-23 19:44 - 2014-01-23 19:44 - 00000356 _____ C:\Windows\Tasks\AmiUpdXp.job 2014-01-23 19:44 - 2014-01-23 19:44 - 00000000 ____D C:\Users\Dolmi\AppData\Local\SwvUpdater 2014-01-23 19:43 - 2014-01-23 19:43 - 00000000 ____D C:\Program Files\Updater By SweetPacks 2014-01-23 19:43 - 2014-01-23 19:43 - 00000000 ____D C:\Program Files\SweetIM 2014-01-23 19:42 - 2014-01-23 19:42 - 00000000 ____D C:\Windows\system32\WNLT 2014-01-23 19:42 - 2014-01-23 19:42 - 00000000 ____D C:\Windows\system32\jmdp 2014-01-23 19:42 - 2014-01-23 19:42 - 00000000 ____D C:\Windows\system32\ARFC 2014-01-23 19:42 - 2013-05-21 13:53 - 01171760 _____ C:\Windows\system32\dmwu.exe 2014-01-23 19:42 - 2013-05-21 13:50 - 00027136 _____ C:\Windows\system32\ImHttpComm.dll 2014-01-23 19:42 - 2013-05-21 13:28 - 00632656 _____ (Microsoft Corporation) C:\Windows\system32\msvcr80.dll 2014-01-23 19:42 - 2013-05-21 13:28 - 00554832 _____ (Microsoft Corporation) C:\Windows\system32\msvcp80.dll 2014-01-23 19:42 - 2013-05-21 13:28 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\msvcm80.dll 2014-01-23 19:42 - 2013-05-21 13:28 - 00001870 _____ C:\Windows\system32\Microsoft.VC80.CRT.manifest 2014-01-23 19:40 - 2014-01-23 19:43 - 00000000 ____D C:\Program Files\SoftwareUpdater 2014-01-23 19:40 - 2014-01-23 19:40 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2014-01-23 19:40 - 2014-01-23 19:40 - 00000000 ____D C:\Program Files\Covus Freemium 2014-01-23 19:37 - 2014-01-23 19:37 - 00000000 ____D C:\ProgramData\Package Cache 2014-01-23 19:34 - 2014-01-23 19:35 - 00000000 ____D C:\Users\Dolmi\AppData\Local\DownloadGuide 2014-01-22 12:52 - 2014-01-23 19:57 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-22 12:52 - 2014-01-23 12:58 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-14 23:20 - 2014-01-14 23:20 - 00000000 ____D C:\Program Files\ESET 2014-01-14 23:05 - 2014-01-14 23:05 - 00000000 ____D C:\Windows\ERUNT 2014-01-14 19:39 - 2014-01-14 19:39 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\Malwarebytes 2014-01-14 19:39 - 2014-01-14 19:39 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-14 19:38 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-14 19:22 - 2014-01-14 19:22 - 00000079 _____ C:\Windows\wininit.ini 2014-01-14 19:11 - 2014-01-14 19:11 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\ProductData 2014-01-14 19:10 - 2014-01-21 20:41 - 00000000 ____D C:\ProgramData\ProductData 2014-01-14 19:10 - 2014-01-15 22:46 - 00000000 ____D C:\ProgramData\IObit 2014-01-14 19:10 - 2014-01-14 19:10 - 00001050 _____ C:\Users\Dolmi\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk 2014-01-14 19:10 - 2014-01-14 19:10 - 00001026 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk 2014-01-14 19:10 - 2014-01-14 19:10 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\IObit 2014-01-14 19:10 - 2014-01-14 19:10 - 00000000 ____D C:\Program Files\IObit 2014-01-14 18:32 - 2014-01-15 22:50 - 00000000 ____D C:\AdwCleaner 2014-01-14 18:27 - 2014-01-14 18:27 - 00000066 _____ C:\Users\Dolmi\Desktop\Link_Bereinigung.txt 2014-01-14 00:12 - 2014-01-13 07:57 - 00000743 _____ C:\Windows\system32\Drivers\etc\hosts.20140114-001258.backup 2014-01-13 23:46 - 2014-01-14 19:24 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2014-01-13 11:26 - 2014-01-13 22:50 - 00001912 _____ C:\Windows\epplauncher.mif 2014-01-13 11:20 - 2010-04-05 21:00 - 00221568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-13 08:45 - 2014-01-13 08:45 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\SUPERAntiSpyware.com 2014-01-13 07:55 - 2014-01-14 19:25 - 00000000 ____D C:\Program Files\Enigma Software Group 2014-01-13 00:55 - 2014-01-13 00:55 - 00000000 ____D C:\Program Files\iPod 2014-01-13 00:54 - 2014-01-13 00:56 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2014-01-13 00:16 - 2012-08-21 13:01 - 00026840 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys 2014-01-13 00:11 - 2014-01-13 00:11 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUSB_01009.Wdf 2014-01-13 00:02 - 2014-01-13 00:02 - 01461992 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2014-01-13 00:02 - 2014-01-13 00:02 - 00851176 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller2.dll 2014-01-13 00:02 - 2014-01-13 00:02 - 00053152 _____ C:\Windows\system32\USBCoInstaller.dll 2014-01-12 21:33 - 2014-01-13 22:58 - 00000000 ____D C:\Users\Dolmi\AppData\Local\cache 2014-01-12 21:33 - 2014-01-13 22:27 - 00001410 _____ C:\Users\Dolmi\daemonprocess.txt 2014-01-12 21:33 - 2014-01-12 21:33 - 00000000 ____D C:\Users\Dolmi\.android 2014-01-12 21:30 - 2014-01-13 12:36 - 00000000 ____D C:\Program Files\EnhanceTronic 2014-01-06 15:12 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-06 15:12 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-06 15:12 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-06 15:12 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-06 15:12 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-06 15:12 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-06 15:12 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-06 15:12 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-06 15:12 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-06 15:12 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-01-06 15:12 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-06 15:12 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-06 15:12 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-06 15:12 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-06 15:12 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-06 15:11 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-06 15:05 - 2013-10-30 03:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2014-01-06 15:05 - 2013-10-30 02:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2014-01-06 15:05 - 2013-10-30 01:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2014-01-06 15:05 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-06 15:05 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2014-01-06 15:05 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2014-01-06 15:05 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2014-01-06 15:05 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2014-01-06 15:05 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2014-01-06 15:05 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe ==================== One Month Modified Files and Folders ======= 2014-01-23 20:03 - 2014-01-23 20:00 - 00028305 _____ C:\Users\Dolmi\Desktop\FRST.txt 2014-01-23 20:02 - 2014-01-23 20:01 - 00030361 _____ C:\Users\Dolmi\Desktop\Addition.txt 2014-01-23 19:59 - 2014-01-23 19:59 - 00000000 ____D C:\FRST 2014-01-23 19:58 - 2014-01-23 19:58 - 01222144 _____ (Farbar) C:\Users\Dolmi\Desktop\FRST.exe 2014-01-23 19:57 - 2014-01-22 12:52 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-23 19:56 - 2007-12-04 15:59 - 01324370 _____ C:\Windows\WindowsUpdate.log 2014-01-23 19:48 - 2014-01-23 19:48 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\Iminent 2014-01-23 19:47 - 2014-01-23 19:47 - 00000611 _____ C:\Windows\system32\InstallUtil.InstallLog 2014-01-23 19:47 - 2014-01-23 19:47 - 00000000 ____D C:\ProgramData\Iminent 2014-01-23 19:47 - 2014-01-23 19:46 - 00000000 ____D C:\Program Files\Iminent 2014-01-23 19:46 - 2014-01-23 19:46 - 00000000 ____D C:\Program Files\Common Files\Umbrella 2014-01-23 19:45 - 2014-01-23 19:44 - 00000000 ____D C:\Program Files\jollywallet 2014-01-23 19:44 - 2014-01-23 19:44 - 00000356 _____ C:\Windows\Tasks\AmiUpdXp.job 2014-01-23 19:44 - 2014-01-23 19:44 - 00000000 ____D C:\Users\Dolmi\AppData\Local\SwvUpdater 2014-01-23 19:43 - 2014-01-23 19:43 - 00000000 ____D C:\Program Files\Updater By SweetPacks 2014-01-23 19:43 - 2014-01-23 19:43 - 00000000 ____D C:\Program Files\SweetIM 2014-01-23 19:43 - 2014-01-23 19:40 - 00000000 ____D C:\Program Files\SoftwareUpdater 2014-01-23 19:42 - 2014-01-23 19:42 - 00000000 ____D C:\Windows\system32\WNLT 2014-01-23 19:42 - 2014-01-23 19:42 - 00000000 ____D C:\Windows\system32\jmdp 2014-01-23 19:42 - 2014-01-23 19:42 - 00000000 ____D C:\Windows\system32\ARFC 2014-01-23 19:42 - 2013-12-12 14:14 - 00000000 ____D C:\Program Files\Mozilla Firefox 2014-01-23 19:40 - 2014-01-23 19:40 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2014-01-23 19:40 - 2014-01-23 19:40 - 00000000 ____D C:\Program Files\Covus Freemium 2014-01-23 19:37 - 2014-01-23 19:37 - 00000000 ____D C:\ProgramData\Package Cache 2014-01-23 19:35 - 2014-01-23 19:34 - 00000000 ____D C:\Users\Dolmi\AppData\Local\DownloadGuide 2014-01-23 18:35 - 2006-11-02 13:47 - 00003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-23 18:35 - 2006-11-02 13:47 - 00003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-23 12:58 - 2014-01-22 12:52 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-23 11:31 - 2006-11-02 11:33 - 01575894 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-22 11:12 - 2009-08-22 23:12 - 00000000 ____D C:\Users\Dolmi\AppData\Local\Apps\2.0 2014-01-22 11:09 - 2010-08-08 22:34 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\Winamp 2014-01-22 11:07 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-22 11:04 - 2013-07-07 19:04 - 00000012 _____ C:\Windows\bthservsdp.dat 2014-01-22 11:04 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-21 20:47 - 2007-12-04 22:56 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\Toshiba 2014-01-21 20:41 - 2014-01-14 19:10 - 00000000 ____D C:\ProgramData\ProductData 2014-01-21 20:39 - 2007-04-16 07:16 - 01673266 _____ C:\Windows\PFRO.log 2014-01-21 20:23 - 2010-03-23 20:43 - 00000000 ____D C:\Users\Dolmi\AppData\Local\CrashDumps 2014-01-20 02:53 - 2013-08-27 16:42 - 00000000 ____D C:\Windows\pss 2014-01-16 12:15 - 2013-11-06 14:33 - 00000000 ____D C:\Users\Dolmi\Desktop\VerbaVoice 2014-01-15 22:50 - 2014-01-14 18:32 - 00000000 ____D C:\AdwCleaner 2014-01-15 22:46 - 2014-01-14 19:10 - 00000000 ____D C:\ProgramData\IObit 2014-01-15 16:58 - 2013-08-22 12:15 - 00000000 ____D C:\Windows\system32\MRT 2014-01-15 16:51 - 2006-11-02 11:24 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-01-15 01:43 - 2013-10-10 12:42 - 00000000 ____D C:\Program Files\SIW 2014-01-14 23:20 - 2014-01-14 23:20 - 00000000 ____D C:\Program Files\ESET 2014-01-14 23:05 - 2014-01-14 23:05 - 00000000 ____D C:\Windows\ERUNT 2014-01-14 22:33 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\nap 2014-01-14 19:39 - 2014-01-14 19:39 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\Malwarebytes 2014-01-14 19:39 - 2014-01-14 19:39 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-14 19:25 - 2014-01-13 07:55 - 00000000 ____D C:\Program Files\Enigma Software Group 2014-01-14 19:24 - 2014-01-13 23:46 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2014-01-14 19:22 - 2014-01-14 19:22 - 00000079 _____ C:\Windows\wininit.ini 2014-01-14 19:11 - 2014-01-14 19:11 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\ProductData 2014-01-14 19:10 - 2014-01-14 19:10 - 00001050 _____ C:\Users\Dolmi\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk 2014-01-14 19:10 - 2014-01-14 19:10 - 00001026 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk 2014-01-14 19:10 - 2014-01-14 19:10 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\IObit 2014-01-14 19:10 - 2014-01-14 19:10 - 00000000 ____D C:\Program Files\IObit 2014-01-14 18:27 - 2014-01-14 18:27 - 00000066 _____ C:\Users\Dolmi\Desktop\Link_Bereinigung.txt 2014-01-14 00:12 - 2006-11-02 11:23 - 00450556 ____R C:\Windows\system32\Drivers\etc\hosts.20140114-001620.backup 2014-01-13 22:58 - 2014-01-12 21:33 - 00000000 ____D C:\Users\Dolmi\AppData\Local\cache 2014-01-13 22:50 - 2014-01-13 11:26 - 00001912 _____ C:\Windows\epplauncher.mif 2014-01-13 22:27 - 2014-01-12 21:33 - 00001410 _____ C:\Users\Dolmi\daemonprocess.txt 2014-01-13 16:57 - 2011-04-27 21:20 - 00012999 _____ C:\Windows\IE9_main.log 2014-01-13 16:57 - 2007-04-16 07:11 - 00000000 ___HD C:\Windows\msdownld.tmp 2014-01-13 12:36 - 2014-01-12 21:30 - 00000000 ____D C:\Program Files\EnhanceTronic 2014-01-13 11:02 - 2013-01-16 14:03 - 00000000 ____D C:\Users\Dolmi\AppData\Local\NPE 2014-01-13 10:23 - 2006-11-02 13:47 - 00343616 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-13 08:45 - 2014-01-13 08:45 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\SUPERAntiSpyware.com 2014-01-13 07:57 - 2014-01-14 00:12 - 00000743 _____ C:\Windows\system32\Drivers\etc\hosts.20140114-001258.backup 2014-01-13 00:56 - 2014-01-13 00:54 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2014-01-13 00:55 - 2014-01-13 00:55 - 00000000 ____D C:\Program Files\iPod 2014-01-13 00:55 - 2009-01-05 23:44 - 00000000 ____D C:\Program Files\Common Files\Apple 2014-01-13 00:11 - 2014-01-13 00:11 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUSB_01009.Wdf 2014-01-13 00:11 - 2006-11-02 13:52 - 00126005 _____ C:\Windows\setupact.log 2014-01-13 00:06 - 2007-12-04 17:13 - 00000000 ____D C:\Users\Dolmi 2014-01-13 00:02 - 2014-01-13 00:02 - 01461992 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2014-01-13 00:02 - 2014-01-13 00:02 - 00851176 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller2.dll 2014-01-13 00:02 - 2014-01-13 00:02 - 00053152 _____ C:\Windows\system32\USBCoInstaller.dll 2014-01-12 21:33 - 2014-01-12 21:33 - 00000000 ____D C:\Users\Dolmi\.android 2014-01-12 21:09 - 2007-12-04 17:13 - 00097912 _____ C:\Users\Dolmi\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-07 21:23 - 2007-12-04 18:29 - 00000400 _____ C:\Windows\ODBC.INI 2014-01-06 15:22 - 2007-04-16 06:18 - 00000000 ____D C:\Windows\system32\RTCOM 2014-01-06 15:19 - 2010-10-26 21:44 - 00000000 ____D C:\ProgramData\Microsoft Help Some content of TEMP: ==================== C:\Users\Dolmi\AppData\Local\Temp\GenericUninstall.exe C:\Users\Dolmi\AppData\Local\Temp\hsbing_717_active.exe C:\Users\Dolmi\AppData\Local\Temp\mgsqlite3.dll C:\Users\Dolmi\AppData\Local\Temp\Quarantine.exe C:\Users\Dolmi\AppData\Local\Temp\Shortcut_sweetpacks.exe C:\Users\Dolmi\AppData\Local\Temp\uninstaller.exe C:\Users\Dolmi\AppData\Local\Temp\WSSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-22 11:13 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 23-01-2014 Ran by Dolmi at 2014-01-23 20:01:58 Running from C:\Users\Dolmi\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Norton Internet Security (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Internet Security (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} ==================== Installed Programs ====================== 10 Finger Test 5.5 (Version: - Giletech e.K.) 3D Pinball from Plus! for Windows 95 (Version: - ) 7-Zip 9.20 (Version: - ) Acronis*True*Image*Home (Version: 10.0.4942 - Acronis) Active@ ISO Burner (Version: 2.5.1 - LSoft Technologies) Adobe Acrobat Connect Add-in (HKCU Version: - ) Adobe AIR (Version: - Adobe Systems Incorporated) Adobe AIR (Version: - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader X (10.1.9) - Deutsch (Version: 10.1.9 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (Version: - Adobe Systems, Inc.) AIDA64 Extreme Edition v3.20 (Version: 3.20 - FinalWire Ltd.) Alien Intruders (Version: 1.7.0 - Novel Games Limited) Alien Intruders (Version: 1.7.0 - Novel Games Limited) Hidden Apple Application Support (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (Version: - Apple Inc.) Apple Software Update (Version: - Apple Inc.) Audacity 1.3.12 (Unicode) (Version: - Audacity Team) BlackBerry Desktop Software 7.1 (Version: - Research in Motion Ltd.) BlackBerry Desktop Software 7.1 (Version: - Research in Motion Ltd.) Hidden Bonjour (Version: - Apple Inc.) Bonjour-Druckdienste (Version: - Apple Inc.) Camera RAW Plug-In for EPSON Creativity Suite (Version: - SEIKO EPSON CORPORATION) CD/DVD Drive Acoustic Silencer (Version: 2.00.02 - TOSHIBA) Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000 - Microsoft Corporation) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (Version: - Microsoft) Digitus USB Webcam(DA-70815) (Version: AKKORD_3328_20080721 - Vimicro) Documents To Go Desktop for iPhone (Version: 2.0000.006 - DataViz, Inc.) DVD MovieFactory for TOSHIBA (Version: 5.3 - Ulead Systems, Inc.) Emdedded IR Driver (Version: - Compal Electronics, Inc.) Emdedded IR Driver (Version: - Compal Electronics, Inc.) Hidden EPSON Copy Utility 3 (Version: - ) EPSON Easy Photo Print (Version: - SEIKO EPSON CORPORATION) EPSON NET Benutzerhandbuch (Version: - ) EPSON Printer Software (Version: - SEIKO EPSON Corporation) EPSON Scan (Version: - ) EPSON Stylus CX9300F_DX9400F Handbuch (Version: - ) EpsonNet Config V1 (Version: - ) EpsonNet Config V3 (Version: 3.5c - SEIKO EPSON CORPORATION) EpsonNet Print (Version: 2.4j - SEIKO EPSON CORPORATION) ESET Online Scanner v3 (Version: - ) FileZilla Client (Version: - ) Firebird SQL Server - MAGIX Edition (D) (Version: - MAGIX AG) Free System Utilities (Version: - Covus Freemium GmbH) Free SystemUtilities (Version: - Covus Freemium GmbH) Hidden FreePDF XP (Remove only) (Version: - ) GIMP 2.4.5 (Version: - ) Google Chrome (Version: 32.0.1700.76 - Google Inc.) Google Earth (Version: - Google) Google Earth Plug-in (Version: - Google) Google Update Helper (Version: - Google Inc.) Hidden GPL Ghostscript 8.61 (Version: - ) GPL Ghostscript Fonts (Version: - ) iCloud (Version: - Apple Inc.) Iminent (Version: - Iminent) <==== ATTENTION Iminent (Version: - Iminent) Hidden <==== ATTENTION Inkscape 0.48.4 (Version: 0.48.4 - ) Intel Matrix Storage Manager (Version: - ) Intel(R) Graphics Media Accelerator Driver (Version: - ) Internet Explorer Toolbar 4.8 by SweetPacks (Version: 4.8.0000 - SweetIM Technologies Ltd.) <==== ATTENTION IObit Uninstaller (Version: - IObit) IrfanView (remove only) (Version: 4.35 - Irfan Skiljan) iTunes (Version: - Apple Inc.) Java 7 Update 45 (Version: 7.0.450 - Oracle) Java Auto Updater (Version: - Sun Microsystems, Inc.) Hidden jollywallet (Version: - jollywallet) LAME v3.99.3 (for Windows) (Version: - ) MAGIX Digital Foto Maker SE (D) (Version: - MAGIX AG) MAGIX Foto Suite (D) (Version: - MAGIX AG) MAGIX Online Druck Service (D) (Version: - MAGIX AG) Malwarebytes Anti-Malware Version (Version: - Malwarebytes Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Business 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office XP Professional mit FrontPage (Version: 10.0.6626.0 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft XML Parser (Version: 8.0.7820.0 - Microsoft Corporation) Hidden Microsoft XML Parser (Version: 8.20.8730.4 - Microsoft Corporation) Hidden Mozilla Firefox 26.0 (x86 de) (Version: 26.0 - Mozilla) Mozilla Maintenance Service (Version: 26.0 - Mozilla) MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation) muvee autoProducer 6.1 Seagate Edition (Version: 6.10.050 - Seagate) muvee Reveal Seagate Edition (Version: - muvee Technologies Pte Ltd) myphotobook 3.1 (Version: 3.1 - myphotobook) NAVIGON Fresh 3.3.2 (Version: 3.3.2 - NAVIGON) NETGEAR Router Recovery (Version: 3.01.008 - Avanquest Software) Norton Internet Security (Version: - Symantec Corporation) Nvu 1.0 (Version: 1.0 - Thorsten Fritz) OpenOffice.org 3.1 (Version: 3.1.9420 - OpenOffice.org) PDF Architect (Version: - pdfforge) PDFCreator (Version: 1.6.2 - pdfforge) PerSono (Version: - ) phase5 (Version: 09.09.2003 - Hans-Dieter Berretz) PhraseExpress v8.0.127 (Version: 8.0.127 - Bartels Media) QuickTime (Version: - Apple Inc.) Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista (Version: 1.00.0000 - Realtek) Realtek High Definition Audio Driver (Version: - Realtek Semiconductor Corp.) RedMon - Redirection Port Monitor (Version: - ) SA23xx Device Manager (Version: 1.0 - Philips) Safari (Version: - Apple Inc.) Seagate Manager Installer (Version: 2.01.0600 - Seagate) Seagate Manager Installer (Version: 2.01.0600 - Seagate) Hidden Secret Maryo Chronicles (Version: 1.6 - Florian Richter) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (Version: - Microsoft) Hidden SIW version 2011.10.29 (Version: 2011.10.29 - Topala Software Solutions) Skype web features (Version: 1.0.3810 - Skype Technologies S.A.) Skype™ 6.7 (Version: 6.7.102 - Skype Technologies S.A.) Software Version Updater (Version: - ) <==== ATTENTION SweetPacks Updater Service (Version: - ) <==== ATTENTION swMSM (Version: - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (Version: - Synaptics Incorporated) Tarot (Version: - ) TeamViewer 9 (Version: 9.0.24951 - TeamViewer) Texas Instruments PCIxx21/x515/xx12 drivers. (Version: 2.00.0001 - Ihr Firmenname) TIPCI (Version: 2.00.0001 - Ihr Firmenname) Hidden TIPP10 Version 2.1.0 (Version: - (c) 2006-2011, Tom Thielicke IT Solutions) TolkCorrect (Version: - ) TOSHIBA Assist (Version: 2.00.03 - ) TOSHIBA ConfigFree (Version: 7.00.27 - TOSHIBA) TOSHIBA Disc Creator (Version: - TOSHIBA Corporation) TOSHIBA DVD PLAYER (Version: 1.10.06 - TOSHIBA Corporation) TOSHIBA Extended Tiles for Windows Mobility Center (Version: 1.01.00 - Toshiba) TOSHIBA Extended Tiles for Windows Mobility Center (Version: 1.01.00 - Toshiba) Hidden TOSHIBA Hardware Setup (Version: - TOSHIBA) TOSHIBA Hardware Setup (Version: - TOSHIBA) Hidden Toshiba Online Product Information (Version: 1.00.0009 - TOSHIBA) TOSHIBA SD Memory Utilities (Version: - TOSHIBA) TOSHIBA Software Modem (Version: 2.1.77 (SM2177ALD03) - Agere Systems) TOSHIBA Supervisor Password (Version: - TOSHIBA) Hidden TOSHIBA Supervisorkennwort (Version: - TOSHIBA) Toshiba TEMPO (Version: 1.0 - Toshiba Europe GmbH) TOSHIBA Value Added Package (Version: 1.0.17 - TOSHIBA Corporation) TOSHIBA Value Added Package (Version: 1.0.17 - TOSHIBA Corporation) Hidden Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2494150) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (Version: - Microsoft) Updater By SweetPacks (Version: - SweetPacks) <==== ATTENTION Utility Common Driver (Version: - TOSHIBA) Hidden Visual C++ Runtime for Dragon NaturallySpeaking (Version: - Nuance Communications Inc.) Winamp (Version: 5.581 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKCU Version: - Nullsoft, Inc) Windows Live Anmelde-Assistent (Version: 5.000.818.6 - Microsoft Corporation) Windows Live installer (Version: 12.0.1471.1025 - Microsoft Corporation) Windows Live Messenger (Version: 8.5.1302.1018 - Microsoft Corporation) Windows Media Encoder 9-Reihe (Version: - ) Windows Media Encoder 9-Reihe (Version: 9.00.3374 - Microsoft Corporation) Hidden Windows Media Player Firefox Plugin (Version: - Microsoft Corp) WinZip (Version: 9.0 SR-1 (6224g) - WinZip Computing, Inc. und H.C. Top Systems B.V.) WinZip 11.1 (Version: 11.1.7466g - WinZip Computing, S.L. ) Xirrus Wi-Fi Inspector (Version: - Xirrus) XMind 2013 (v3.4.0) (Version: - XMind Ltd.) Yahoo! Detect (Version: - ) ==================== Restore Points ========================= 16-01-2014 06:11:46 Geplanter Prüfpunkt 16-01-2014 23:06:39 Geplanter Prüfpunkt 21-01-2014 09:38:53 Geplanter Prüfpunkt 23-01-2014 01:00:19 Geplanter Prüfpunkt 23-01-2014 18:36:09 Free System Utilities ==================== Hosts content: ========================== 2006-11-02 11:23 - 2014-01-14 00:16 - 00450556 ____N C:\Windows\system32\Drivers\etc\hosts localhost www.007guard.com 007guard.com 008i.com www.008k.com 008k.com www.00hq.com 00hq.com 010402.com www.032439.com 032439.com www.0scan.com 0scan.com 1000gratisproben.com www.1000gratisproben.com 1001namen.com www.1001namen.com 100888290cs.com www.100888290cs.com www.100sexlinks.com 100sexlinks.com 10sek.com www.10sek.com www.1-2005-search.com 1-2005-search.com 123fporn.info www.123fporn.info 123haustiereundmehr.com www.123haustiereundmehr.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {07727611-E7D0-4273-928E-5CC279DC42D5} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton Internet Security\Engine\\WSCStub.exe [2013-10-08] (Symantec Corporation) Task: {0AA54F7C-1EBD-4F61-B9E4-1A7D7F964EE7} - System32\Tasks\{A8B9DB5B-BA98-4A9F-BF58-1F8EDE47B7AB} => d:\Program Files\Skype\Phone\Skype.exe [2013-07-25] (Skype Technologies S.A.) Task: {0EC4B00E-D5C1-4800-8D8C-7655A7FA04A8} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files\Norton Internet Security\Engine\\SymErr.exe [2013-08-01] (Symantec Corporation) Task: {1CA76EDA-3762-4160-848E-BD13839F5B8A} - System32\Tasks\Software Updater => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe [2014-01-23] () Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {25A15125-D0B7-456E-971F-D1639B7BF489} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {30CC3AB1-3FF8-4A19-9A36-29FCC35C0E0F} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-01-14] (IObit) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation) Task: {46F021E5-232B-411A-A946-FFA802982706} - System32\Tasks\Software Updater Ui => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Ui.exe [2014-01-23] () Task: {5F23CAC3-FC54-4A97-925F-2CD304413954} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files\Norton Internet Security\Engine\\SymErr.exe [2013-08-01] (Symantec Corporation) Task: {78C0B212-F723-417D-986E-B562CDC7A951} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-11-08] (Google Inc.) Task: {9A1FADAE-01B5-4034-86B3-C69B78FD3ED3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-11-08] (Google Inc.) Task: {B2704CCD-F4B3-487E-8F84-9137A103F433} - \SUPERAntiSpyware Scheduled Task 28bc9b0d-d5bd-4ba0-9cbc-ffa93577fe40 No Task File Task: {C2A8C252-B387-40B5-A32B-92723960DB93} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {C6B6B2A1-D8E0-4CB1-BDE4-BF44C6B1407B} - \SUPERAntiSpyware Scheduled Task 1ec90d68-9654-42f1-be85-d9b2ba7c8876 No Task File Task: {D2E5FE77-A81D-49D1-96EB-B27426975057} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] () Task: {F6BB6E53-6E8A-497D-BB33-2140888958BF} - System32\Tasks\AmiUpdXp => C:\Users\Dolmi\AppData\Local\SwvUpdater\Updater.exe [2014-01-23] (Amonetizé Ltd) <==== ATTENTION Task: C:\Windows\Tasks\AmiUpdXp.job => C:\Users\Dolmi\AppData\Local\SwvUpdater\Updater.exe <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2007-04-17 12:53 - 2007-03-06 10:34 - 00249856 _____ () C:\Windows\system32\igfxTMM.dll 2007-04-03 11:18 - 2007-04-03 11:18 - 00950272 _____ () C:\Program Files\TOSHIBA\FlashCards\de\TCrdMain.resources.dll 2006-11-09 17:27 - 2006-11-09 17:27 - 00090112 _____ () C:\Program Files\TOSHIBA\FlashCards\TWarnMsg\TWarnMsg.dll 2007-04-16 07:06 - 2006-10-10 10:44 - 00009728 _____ () C:\Program Files\TOSHIBA\TOSHIBA Assist\NotifyX.dll 2006-11-08 17:08 - 2006-11-08 17:08 - 00009216 _____ () C:\Program Files\Toshiba\PCDiag\NotifyPCD.dll 2007-04-16 07:01 - 2006-10-20 12:49 - 00009216 _____ () C:\Program Files\Toshiba\ConfigFree\NotifyCFF.dll 2006-10-07 11:57 - 2006-10-07 11:57 - 00053248 _____ () C:\Program Files\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll 2006-12-01 17:55 - 2006-12-01 17:55 - 00009216 _____ () C:\Program Files\Toshiba\TBS\NotifyTBS.dll 2007-02-14 18:21 - 2007-02-14 18:21 - 00050720 _____ () C:\Program Files\Common Files\Acronis\Common\gc.dll 2011-11-01 23:26 - 2011-11-01 23:26 - 00087912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2011-11-01 23:26 - 2011-11-01 23:26 - 01242472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-12-12 14:14 - 2013-12-12 14:15 - 03559024 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\office14\Cultures\office.odf 2013-02-14 14:46 - 2013-02-14 14:46 - 01044048 _____ () D:\Program Files\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll 2013-12-11 15:49 - 2013-12-11 15:54 - 16242056 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:F35A93AD ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: PC Camera Description: Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: Camera Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (01/23/2014 08:37:14 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\CONFIG.MSI\49A5C4C.RBS> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (01/23/2014 08:37:12 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\CONFIG.MSI\49A5C4B.RBF> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (01/22/2014 06:54:37 AM) (Source: System Restore) (User: ) Description: Der geplante Wiederherstellungspunkt konnte nicht erstellt werden. Zusätzliche Informationen: (0x81000101). Error: (01/22/2014 06:54:37 AM) (Source: System Restore) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts auf dem Volume (Prozess = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Beschreibung = Geplanter Prüfpunkt; Hr = 0x81000101). Error: (01/22/2014 06:54:20 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 27858783 Error: (01/22/2014 06:54:20 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 27858783 Error: (01/22/2014 06:54:20 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (01/22/2014 02:01:28 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 10286472 Error: (01/22/2014 02:01:28 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 10286472 Error: (01/22/2014 02:01:28 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second System errors: ============= Error: (01/23/2014 07:46:37 PM) (Source: Service Control Manager) (User: ) Description: SProtection Error: (01/23/2014 08:30:41 AM) (Source: Dhcp) (User: ) Description: Die IP-Adresslease für die Netzwerkkarte mit der Netzwerkadresse 0013E8B8CDD1 wurde durch den DHCP-Server abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet). Error: (01/22/2014 00:51:33 PM) (Source: Service Control Manager) (User: ) Description: Google Update Service (gupdate)%%1053 Error: (01/22/2014 00:51:33 PM) (Source: Service Control Manager) (User: ) Description: 30000Google Update Service (gupdate) Error: (01/22/2014 00:51:25 PM) (Source: Service Control Manager) (User: ) Description: Google Update-Dienst (gupdatem)%%1053 Error: (01/22/2014 00:51:25 PM) (Source: Service Control Manager) (User: ) Description: 30000Google Update-Dienst (gupdatem) Error: (01/22/2014 11:08:36 AM) (Source: Service Control Manager) (User: ) Description: LiveUpdate1 Error: (01/22/2014 11:07:53 AM) (Source: Service Control Manager) (User: ) Description: BTHidMgr Error: (01/22/2014 11:07:53 AM) (Source: Service Control Manager) (User: ) Description: Update EnhanceTronic%%2 Error: (01/22/2014 11:07:53 AM) (Source: Service Control Manager) (User: ) Description: Automatisches LiveUpdate - Scheduler%%3 Microsoft Office Sessions: ========================= Error: (01/23/2014 08:37:14 AM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\CONFIG.MSI\49A5C4C.RBS Error: (01/23/2014 08:37:12 AM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\CONFIG.MSI\49A5C4B.RBF Error: (01/22/2014 06:54:37 AM) (Source: System Restore)(User: ) Description: 0x81000101 Error: (01/22/2014 06:54:37 AM) (Source: System Restore)(User: ) Description: C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreationGeplanter Prüfpunkt0x81000101 Error: (01/22/2014 06:54:20 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 27858783 Error: (01/22/2014 06:54:20 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 27858783 Error: (01/22/2014 06:54:20 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (01/22/2014 02:01:28 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 10286472 Error: (01/22/2014 02:01:28 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 10286472 Error: (01/22/2014 02:01:28 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second CodeIntegrity Errors: =================================== Date: 2014-01-23 20:01:10.145 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-23 20:01:09.642 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-23 20:01:09.204 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-23 20:01:08.833 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-23 20:00:59.191 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Norton Internet Security\NortonData\\Definitions\BASHDefs\20140121.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-23 20:00:58.873 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Norton Internet Security\NortonData\\Definitions\BASHDefs\20140121.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-23 20:00:58.538 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Norton Internet Security\NortonData\\Definitions\BASHDefs\20140121.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-23 20:00:58.120 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Norton Internet Security\NortonData\\Definitions\BASHDefs\20140121.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-23 18:32:52.580 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-23 18:32:52.205 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 77% Total physical RAM: 2037.69 MB Available physical RAM: 467.2 MB Total Pagefile: 4312.61 MB Available Pagefile: 2229.97 MB Total Virtual: 2047.88 MB Available Virtual: 1891.32 MB ==================== Drives ================================ Drive c: (Vista) (Fixed) (Total:74.52 GB) (Free:12.85 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Data) (Fixed) (Total:40.77 GB) (Free:10.54 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 149 GB) (Disk ID: 3011A9DF) Partition 1: (Not Active) - (Size=1 GB) - (Type=27) Partition 2: (Active) - (Size=75 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=41 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=32 GB) - (Type=05) ==================== End Of Log ============================ Vielen Dank! P.S. Norton hatte vorhin Supicios-Cloud erkannt und berabeitet. LG |
![]() | #4 |
nach Säuberung: System "hängt" CPU-Auslastung sehr hoch wegen Browser,Flash, Hostprozess Downloade Dir bitte ![]()

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #5 |
| ![]() nach Säuberung: System "hängt" CPU-Auslastung sehr hoch wegen Browser,Flash, Hostprozess Hallo, alles erledigt. ich habe 2 Dateien vom ADWCleaner. Die Logs waren zu lang für den Beitrag hier, deshalb habe ich sie Dir hier angehängt: ADWCleander: Log 1 und 2 JRT: 1 Log FRST: 1 Log So, jetzt Du aber einiges zu tun, das alles auszuwerten ... ![]() Ich danke Dir vielmals! ![]() Viele liebe Grüße |
![]() | #6 |
nach Säuberung: System "hängt" CPU-Auslastung sehr hoch wegen Browser,Flash, Hostprozess Hi,

Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. ![]()

Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? ![]()
__________________ --> nach Säuberung: System "hängt" CPU-Auslastung sehr hoch wegen Browser,Flash, Hostprozess |
![]() | #7 |
| ![]() nach Säuberung: System "hängt" CPU-Auslastung sehr hoch wegen Browser,Flash, Hostprozess Hallo, so, nun endlich fertig. Ja, entschuldige bitte mit dem Log posten, das mache ich das nächste Mal so. Ich habe den Eset-Scan gemacht und ihn danach deinstalliert. Jetzt - und das ist mir wirklich oberpeinlich und ich ärgere mich sehr darüber - habe ich das Log-File davon nicht mehr. Ich habe in dem Ordner das Logfile geholt, auf dem Desktop gespeichert und als ich reingeschaut habe, war es das Logfile vom 15.01. als ich schon mal einen Scan gemacht hatte. D. h., das Logfile von jetzt weg. Der Scan lief von Samstag Mittag bis Sonntag früh, also ca. 16 Stunden. Das stinkt mir jetzt total. Bitte sei nicht sauer. Wenigstens habe ich gesehen, dass er keine Infektionen mehr gefunden hatte ... Jetzt das Logfile vom SecurityCheck: Code:
ATTFilter Results of screen317's Security Check version 0.99.79 Windows Vista Service Pack 2 x86 (UAC is enabled) Internet Explorer 9 Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` Norton Internet Security WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` MVPS Hosts File Malwarebytes Anti-Malware Version Java 7 Update 45 Java version out of Date! Adobe Flash Player 11.9.900.170 Adobe Reader 10.1.9 Adobe Reader out of Date! Mozilla Firefox (26.0) Google Chrome 31.0.1650.63 Google Chrome 32.0.1700.76 ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-01-2014 Ran by Dolmi (administrator) on ID_NETZ on 26-01-2014 07:43:19 Running from C:\Users\Dolmi\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\eEBAPI\eEBSvc.exe (Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Agere Systems) C:\Windows\System32\agrsmsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (Seagate Technology LLC) D:\Program Files\Sync\FreeAgentService.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe ( ) C:\Windows\System32\lxcfcoms.exe (Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\\NIS.exe (pdfforge GbR) C:\Program Files\PDF Architect\HelperService.exe (pdfforge GbR) C:\Program Files\PDF Architect\ConversionService.exe (StarWind Software) D:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe (TeamViewer GmbH) D:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\\NIS.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe (InstallShield Software Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynToshiba.exe (Acronis) C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Microsoft Corporation) C:\Windows\System32\wpcumi.exe (Research In Motion Limited) C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Apple Inc.) D:\Program Files\iTunes\iTunesHelper.exe (TOSHIBA CORPORATION) D:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Plantronics) D:\Program Files\PerSono\PersTray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (TOSHIBA CORPORATION.) C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (Research In Motion Limited) C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (TOSHIBA CORPORATION) D:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION.) C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.) C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.) C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHSP.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\WerFault.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation) HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [411768 2006-12-19] (TOSHIBA Corporation) HKLM\...\Run: [HSON] - C:\Program Files\TOSHIBA\TBS\HSON.exe [55416 2006-12-07] (TOSHIBA Corporation) HKLM\...\Run: [SmoothView] - C:\Program Files\Toshiba\SmoothView\SmoothView.exe [509496 2007-04-03] (TOSHIBA Corporation) HKLM\...\Run: [SVPWUTIL] - C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe [438272 2006-03-22] (TOSHIBA) HKLM\...\Run: [topi] - C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe [577536 2007-04-02] (TOSHIBA) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1451304 2009-03-20] (Synaptics Incorporated) HKLM\...\Run: [Toshiba Registration] - C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe [571024 2007-02-19] (Toshiba) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [174872 2007-02-12] (Intel Corporation) HKLM\...\Run: [SynTPStart] - C:\Program Files\Synaptics\SynTP\SynTPStart.exe [204800 2007-07-27] (Synaptics, Inc.) HKLM\...\Run: [FreePDF Assistant] - C:\Program Files\FreePDF_XP\fpassist.exe [312320 2007-06-26] (shbox.de) HKLM\...\Run: [ISUSScheduler] - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-16] (InstallShield Software Corporation) HKLM\...\Run: [TrueImageMonitor.exe] - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [1194728 2007-02-17] (Acronis) HKLM\...\Run: [AcronisTimounterMonitor] - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [1966928 2007-02-17] (Acronis) HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [149024 2007-02-16] (Acronis) HKLM\...\Run: [WPCUMI] - C:\Windows\system32\WpcUmi.exe [176128 2006-11-02] (Microsoft Corporation) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-01-20] (Apple Inc.) HKLM\...\Run: [RIMBBLaunchAgent.exe] - C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [267792 2013-01-17] (Research In Motion Limited) HKLM\...\Run: [QuickTime Task] - D:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [WinampAgent] - d:\Program Files\Winamp\winampa.exe [74752 2010-07-12] (Nullsoft, Inc.) HKLM\...\Run: [iTunesHelper] - D:\Program Files\iTunes\iTunesHelper.exe [152392 2014-01-20] (Apple Inc.) HKLM\...\Run: [ITSecMng] - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [80840 2011-04-01] (TOSHIBA CORPORATION) HKLM\...\Run: [NDSTray.exe] - NDSTray.exe HKLM\...\Run: [HWSetup] - C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [413696 2006-11-01] (TOSHIBA Electronics, Inc.) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [AlcoholAutomount] - d:\Program Files\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe [33120 2010-08-20] (Alcohol Soft Development Team) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation) HKCU\...\Policies\system: [LogonHoursAction] 2 HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 MountPoints2: {3acc327a-db62-11de-8f30-8b74867ae91f} - G:\LaunchU3.exe -a MountPoints2: {91288b47-8680-11dd-aa7d-0013e8b8cdd1} - E:\starter.exe HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Default\...\Run: [TOSCDSPD] - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2006-11-13] (TOSHIBA) HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Default User\...\Run: [TOSCDSPD] - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2006-11-13] (TOSHIBA) Lsa: [Authentication Packages] msv1_0 relog_ap ==================== Internet (Whitelisted) ==================== ProxyServer: localhost:8080 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://de.msn.com/?ocid=OIE9MSE&PC=UP09 SearchScopes: HKLM - DefaultScope value is missing. BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll (IObit) BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GbR) BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\\coIEPlg.dll (Symantec Corporation) BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\\IPS\IPSBHO.DLL (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\IE\jre7\bin\ssv.dll (Oracle Corporation) BHO: No Name - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\IE\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\\coIEPlg.dll (Symantec Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - d:\Program Files\SUPERAntiSpyware\SASSEH.DLL No File [ ] Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 02 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 03 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 04 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 05 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 06 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 07 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 08 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 20 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] Tcpip\..\Interfaces\{1E15786F-368E-4303-9BE7-439A0D0888EC}: [NameServer] FireFox: ======== FF ProfilePath: C:\Users\Dolmi\AppData\Roaming\Mozilla\Firefox\Profiles\k22mrdjm.default-1389800339087 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1205146.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - D:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Windows\system32\npdeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin - D:\Program Files\Java\IE\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - D:\Program Files\Java\IE\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - D:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @RIM.com/WebSLLauncher,version=1.0 - C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll () FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Skype extension for Firefox - C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED} [2013-12-12] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2013-12-12] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2013-12-12] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt [2013-03-01] FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn\ [] FF HKLM\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF [2013-11-25] Chrome: ======= CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Dolmi\AppData\Local\Google\Chrome\User Data\WidevineCDM\\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\32.0.1700.76\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\32.0.1700.76\pdf.dll () CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation) CHR Plugin: (Winamp Application Detector) - C:\Program Files\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - D:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - D:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - D:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - D:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - D:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll () CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw_1205146.dll (Adobe Systems, Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () CHR Plugin: (Java Deployment Toolkit 7.0.450.18) - C:\Windows\system32\npdeployJava1.dll (Oracle Corporation) CHR Plugin: (Microsoft Office 2010) - D:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Java(TM) Platform SE 7 U45) - D:\Program Files\Java\IE\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (iTunes Application Detector) - D:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (YouTube) - C:\Users\Dolmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-06-06] CHR Extension: (Google Search) - C:\Users\Dolmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-06-06] CHR Extension: (No Name) - C:\Users\Dolmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl [2014-01-23] CHR Extension: (Norton Identity Protection) - C:\Users\Dolmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2013-06-06] CHR Extension: (Google Wallet) - C:\Users\Dolmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-27] CHR Extension: (Gmail) - C:\Users\Dolmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-06-06] CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files\Norton Internet Security\Engine\\Exts\Chrome.crx [2013-11-21] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ========================== Services (Whitelisted) ================= R2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [411168 2007-02-16] (Acronis) R3 Blackberry Device Manager; C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [577536 2013-01-18] (Research In Motion Limited) R2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\eEBAPI\eEBSVC.exe [90112 2004-11-17] (SEIKO EPSON CORPORATION) S3 FirebirdServerMAGIXInstance; C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) R2 FreeAgentGoNext Service; D:\Program Files\Sync\FreeAgentService.exe [189736 2009-09-25] (Seagate Technology LLC) S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2151744 2014-01-14] (IObit) R2 lxcf_device; C:\Windows\system32\lxcfcoms.exe [537520 2007-02-23] ( ) R2 NIS; C:\Program Files\Norton Internet Security\Engine\\NIS.exe [275696 2013-10-08] (Symantec Corporation) R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR) R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR) S3 SandraAgentSrv; d:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.RTM\RpcAgentSrv.exe [72344 2008-11-25] (SiSoftware) R2 StarWindServiceAE; d:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) R2 TeamViewer9; d:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe [5341536 2013-12-17] (TeamViewer GmbH) R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.) S3 usnjsvc; C:\Program Files\Windows Live\Messenger\usnsvc.exe [98328 2007-10-18] (Microsoft Corporation) S3 WLSetupSvc; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [266240 2007-10-25] (Microsoft Corporation) S2 Automatisches LiveUpdate - Scheduler; "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [x] S2 SkypeUpdate; "D:\Program Files\Skype\Updater\Updater.exe" [x] S2 TempoMonitoringService; "E:\Program Files\Toshiba TEMPO\TempoSVC.exe" [x] S2 Update EnhanceTronic; "C:\Program Files\EnhanceTronic\updateEnhanceTronic.exe" [x] ==================== Drivers (Whitelisted) ==================== S2 ALIWEHCD; C:\Windows\System32\Drivers\mfpec.sys [53152 2006-07-24] (None) S3 AliWGP; C:\Windows\System32\DRIVERS\mfpcomp.sys [10063 2006-06-02] (None) R1 BHDrvx86; C:\Program Files\Norton Internet Security\NortonData\\Definitions\BASHDefs\20140121.001\BHDrvx86.sys [1098968 2013-12-18] (Symantec Corporation) S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [28048 2010-02-05] (CSR, plc) R1 ccSet_NIS; C:\Windows\system32\drivers\NIS\1501000.012\ccSetx86.sys [127064 2013-09-26] (Symantec Corporation) R0 CplIR; C:\Windows\System32\DRIVERS\CplIR.SYS [14848 2007-03-06] (COMPAL ELECTRONIC INC.) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376920 2013-12-07] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [108120 2013-11-20] (Symantec Corporation) S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [53184 2007-06-27] (FTDI Ltd.) R1 IDSVix86; C:\Program Files\Norton Internet Security\NortonData\\Definitions\IPSDefs\20140124.001\IDSvix86.sys [394456 2014-01-21] (Symantec Corporation) S3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [20992 2008-01-19] (Microsoft Corporation) R0 LPCFilter; C:\Windows\System32\DRIVERS\LPCFilter.sys [19456 2006-07-28] (COMPAL ELECTRONIC INC.) R3 MonitorFunction; C:\Windows\System32\DRIVERS\TVMonitor.sys [13304 2013-10-17] (TeamViewer GmbH) R3 NAVENG; C:\Program Files\Norton Internet Security\NortonData\\Definitions\VirusDefs\20140125.005\NAVENG.SYS [93272 2013-12-07] (Symantec Corporation) R3 NAVEX15; C:\Program Files\Norton Internet Security\NortonData\\Definitions\VirusDefs\20140125.005\NAVEX15.SYS [1612376 2013-12-07] (Symantec Corporation) S3 OVT511Plus; C:\Windows\System32\Drivers\omcamvid.sys [167816 2001-09-18] (OmniVision Technologies, Inc.) S3 SANDRA; d:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.RTM\WNt500x86\Sandra.sys [23112 2009-08-07] (SiSoftware) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [436792 2011-12-22] () R3 SRTSP; C:\Windows\System32\Drivers\NIS\1501000.012\SRTSP.SYS [651352 2013-09-27] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NIS\1501000.012\SRTSPX.SYS [32344 2013-09-10] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NIS\1501000.012\SYMDS.SYS [367704 2013-09-10] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NIS\1501000.012\SYMEFA.SYS [935512 2013-09-27] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142936 2013-11-21] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NIS\1501000.012\Ironx86.SYS [206936 2013-09-27] (Symantec Corporation) R1 SYMTDIv; C:\Windows\System32\Drivers\NIS\1501000.012\SYMTDIV.SYS [383576 2013-09-26] (Symantec Corporation) R3 teamviewervpn; C:\Windows\System32\DRIVERS\teamviewervpn.sys [25088 2008-01-25] (TeamViewer GmbH) R2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [32768 2009-08-06] (Acronis) R2 uacFlt; C:\Windows\System32\DRIVERS\uacflt.sys [21276 2002-05-03] (Micronas GmbH) S3 vncmirror; C:\Windows\System32\DRIVERS\vncmirror.sys [4608 2013-01-22] (RealVNC Ltd.) R3 WUSBVBus; C:\Windows\System32\DRIVERS\mfpvbus.sys [9472 2006-08-03] (None) U3 axqyelbv; C:\Windows\System32\Drivers\axqyelbv.sys [0 ] (Microsoft Corporation) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 BlueletAudio; system32\DRIVERS\blueletaudio.sys [x] S3 BlueletSCOAudio; system32\DRIVERS\BlueletSCOAudio.sys [x] S3 BT; system32\DRIVERS\btnetdrv.sys [x] S3 Btcsrusb; System32\Drivers\btcusb.sys [x] S0 BTHidEnum; System32\Drivers\vbtenum.sys [x] S0 BTHidMgr; System32\Drivers\BTHidMgr.sys [x] S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] U2 srservice; S3 TpChoice; system32\DRIVERS\TpChoice.sys [x] S3 VComm; system32\DRIVERS\VComm.sys [x] S3 VcommMgr; System32\Drivers\VcommMgr.sys [x] S3 VHidMinidrv; system32\drivers\VHIDMini.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-26 07:43 - 2014-01-26 07:43 - 00028713 _____ C:\Users\Dolmi\Desktop\FRST.txt 2014-01-26 07:42 - 2014-01-26 07:42 - 00001010 _____ C:\Users\Dolmi\Desktop\checkup.txt 2014-01-26 07:19 - 2014-01-26 07:19 - 00987425 _____ C:\Users\Dolmi\Desktop\SecurityCheck.exe 2014-01-25 00:34 - 2007-11-14 15:18 - 00000553 _____ C:\Windows\USetup.iss 2014-01-24 23:36 - 2014-01-24 23:36 - 00000000 __SHD C:\Windows\system32\%APPDATA% 2014-01-24 20:03 - 2014-01-24 22:47 - 14098432 _____ C:\Users\Dolmi\AppData\Roaming\Sandra.mdb 2014-01-24 20:00 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-01-24 20:00 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2014-01-24 20:00 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-01-24 20:00 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-01-24 20:00 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2014-01-24 20:00 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2014-01-24 20:00 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2014-01-24 20:00 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2014-01-24 20:00 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2014-01-24 20:00 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2014-01-24 20:00 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2014-01-24 20:00 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2014-01-24 20:00 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2014-01-24 20:00 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2014-01-24 20:00 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2014-01-24 20:00 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2014-01-24 20:00 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2014-01-24 20:00 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-01-24 20:00 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2014-01-24 20:00 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2014-01-24 20:00 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2014-01-24 20:00 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2014-01-24 20:00 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2014-01-24 20:00 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2014-01-24 20:00 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2014-01-24 20:00 - 2008-10-10 04:52 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2014-01-24 20:00 - 2008-10-10 04:52 - 00452440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2014-01-24 19:59 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-01-24 19:59 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-01-24 19:59 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-01-24 19:59 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-01-24 19:59 - 2008-10-10 04:52 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2014-01-24 19:59 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2014-01-24 19:59 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2014-01-24 19:59 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2014-01-24 19:59 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-01-24 19:59 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-01-24 19:59 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-01-24 19:59 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-01-24 19:59 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-01-24 19:59 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-01-24 19:59 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-01-24 19:59 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-01-24 19:59 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-01-24 19:59 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-01-24 19:59 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-01-24 19:59 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-01-24 19:59 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-01-24 19:59 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-01-24 19:59 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-01-24 19:59 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-01-24 19:59 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-01-24 19:59 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-01-24 19:59 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-01-24 19:59 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-01-24 19:59 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-01-24 19:59 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-01-24 19:59 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-01-24 19:59 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-01-24 19:59 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-01-24 19:59 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-01-24 19:59 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-01-24 19:59 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-01-24 19:59 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-01-24 19:59 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-01-24 19:59 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2014-01-24 19:59 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-01-24 19:59 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-01-24 19:59 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-01-24 19:59 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-01-24 19:59 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-01-24 19:59 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-01-24 19:59 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-01-24 19:59 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-01-24 19:59 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-01-24 19:59 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-01-24 19:59 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-01-24 19:59 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2014-01-24 19:59 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2014-01-24 19:58 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2014-01-24 19:58 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2014-01-24 19:58 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2014-01-24 19:58 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2014-01-24 19:58 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2014-01-24 19:58 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2014-01-24 19:58 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2014-01-24 19:58 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2014-01-24 19:58 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2014-01-24 19:58 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2014-01-24 19:54 - 2014-01-24 20:00 - 00000000 ____D C:\Windows\system32\directx 2014-01-24 19:45 - 2014-01-24 19:45 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2014-01-24 13:38 - 2014-01-24 13:38 - 00000000 ____D C:\Program Files\iPod 2014-01-24 12:38 - 2014-01-24 12:42 - 00043424 _____ C:\Users\Dolmi\Desktop\FRST_140124.txt 2014-01-24 12:24 - 2014-01-24 12:24 - 00001468 _____ C:\Users\Dolmi\Desktop\JRT_140124.txt 2014-01-24 11:06 - 2014-01-24 11:06 - 01037068 _____ (Thisisu) C:\Users\Dolmi\Desktop\JRT.exe 2014-01-24 10:56 - 2014-01-24 10:56 - 01236282 _____ C:\Users\Dolmi\Desktop\adwcleaner.exe 2014-01-23 20:01 - 2014-01-23 20:04 - 00030544 _____ C:\Users\Dolmi\Desktop\Addition_140123.txt 2014-01-23 20:00 - 2014-01-23 20:04 - 00045605 _____ C:\Users\Dolmi\Desktop\FRST_140123.txt 2014-01-23 19:59 - 2014-01-23 19:59 - 00000000 ____D C:\FRST 2014-01-23 19:58 - 2014-01-23 19:58 - 01222144 _____ (Farbar) C:\Users\Dolmi\Desktop\FRST.exe 2014-01-23 19:47 - 2014-01-23 19:47 - 00000611 _____ C:\Windows\system32\InstallUtil.InstallLog 2014-01-23 19:42 - 2013-05-21 13:28 - 00632656 _____ (Microsoft Corporation) C:\Windows\system32\msvcr80.dll 2014-01-23 19:42 - 2013-05-21 13:28 - 00554832 _____ (Microsoft Corporation) C:\Windows\system32\msvcp80.dll 2014-01-23 19:42 - 2013-05-21 13:28 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\msvcm80.dll 2014-01-23 19:42 - 2013-05-21 13:28 - 00001870 _____ C:\Windows\system32\Microsoft.VC80.CRT.manifest 2014-01-23 19:40 - 2014-01-23 19:40 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2014-01-23 19:40 - 2014-01-23 19:40 - 00000000 ____D C:\Program Files\Covus Freemium 2014-01-23 19:37 - 2014-01-23 19:37 - 00000000 ____D C:\ProgramData\Package Cache 2014-01-22 12:52 - 2014-01-26 00:57 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-22 12:52 - 2014-01-25 12:59 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-14 23:05 - 2014-01-14 23:05 - 00000000 ____D C:\Windows\ERUNT 2014-01-14 19:39 - 2014-01-14 19:39 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\Malwarebytes 2014-01-14 19:39 - 2014-01-14 19:39 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-14 19:38 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-14 19:22 - 2014-01-14 19:22 - 00000079 _____ C:\Windows\wininit.ini 2014-01-14 19:11 - 2014-01-14 19:11 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\ProductData 2014-01-14 19:10 - 2014-01-24 12:09 - 00000000 ____D C:\ProgramData\IObit 2014-01-14 19:10 - 2014-01-21 20:41 - 00000000 ____D C:\ProgramData\ProductData 2014-01-14 19:10 - 2014-01-14 19:10 - 00001050 _____ C:\Users\Dolmi\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk 2014-01-14 19:10 - 2014-01-14 19:10 - 00001026 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk 2014-01-14 19:10 - 2014-01-14 19:10 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\IObit 2014-01-14 19:10 - 2014-01-14 19:10 - 00000000 ____D C:\Program Files\IObit 2014-01-14 18:39 - 2014-01-14 18:39 - 02347384 _____ (ESET) C:\Users\Dolmi\Desktop\esetsmartinstaller_deu.exe 2014-01-14 18:32 - 2014-01-24 12:56 - 00000000 ____D C:\AdwCleaner 2014-01-14 18:27 - 2014-01-14 18:27 - 00000066 _____ C:\Users\Dolmi\Desktop\Link_Bereinigung.txt 2014-01-14 00:12 - 2014-01-13 07:57 - 00000743 _____ C:\Windows\system32\Drivers\etc\hosts.20140114-001258.backup 2014-01-13 23:46 - 2014-01-14 19:24 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2014-01-13 11:26 - 2014-01-13 22:50 - 00001912 _____ C:\Windows\epplauncher.mif 2014-01-13 11:20 - 2010-04-05 21:00 - 00221568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-13 08:45 - 2014-01-13 08:45 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\SUPERAntiSpyware.com 2014-01-13 07:55 - 2014-01-14 19:25 - 00000000 ____D C:\Program Files\Enigma Software Group 2014-01-13 00:16 - 2012-08-21 13:01 - 00026840 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys 2014-01-13 00:11 - 2014-01-13 00:11 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUSB_01009.Wdf 2014-01-13 00:02 - 2014-01-13 00:02 - 01461992 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2014-01-13 00:02 - 2014-01-13 00:02 - 00851176 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller2.dll 2014-01-13 00:02 - 2014-01-13 00:02 - 00053152 _____ C:\Windows\system32\USBCoInstaller.dll 2014-01-12 21:33 - 2014-01-13 22:58 - 00000000 ____D C:\Users\Dolmi\AppData\Local\cache 2014-01-12 21:33 - 2014-01-13 22:27 - 00001410 _____ C:\Users\Dolmi\daemonprocess.txt 2014-01-12 21:33 - 2014-01-12 21:33 - 00000000 ____D C:\Users\Dolmi\.android 2014-01-12 21:30 - 2014-01-13 12:36 - 00000000 ____D C:\Program Files\EnhanceTronic 2014-01-06 15:12 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-06 15:12 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-06 15:12 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-06 15:12 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-06 15:12 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-06 15:12 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-06 15:12 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-06 15:12 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-06 15:12 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-06 15:12 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-01-06 15:12 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-06 15:12 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-06 15:12 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-06 15:12 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-06 15:12 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-06 15:11 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-06 15:05 - 2013-10-30 03:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2014-01-06 15:05 - 2013-10-30 02:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2014-01-06 15:05 - 2013-10-30 01:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2014-01-06 15:05 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-06 15:05 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2014-01-06 15:05 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2014-01-06 15:05 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2014-01-06 15:05 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2014-01-06 15:05 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2014-01-06 15:05 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe ==================== One Month Modified Files and Folders ======= 2014-01-26 07:44 - 2014-01-26 07:43 - 00028713 _____ C:\Users\Dolmi\Desktop\FRST.txt 2014-01-26 07:42 - 2014-01-26 07:42 - 00001010 _____ C:\Users\Dolmi\Desktop\checkup.txt 2014-01-26 07:19 - 2014-01-26 07:19 - 00987425 _____ C:\Users\Dolmi\Desktop\SecurityCheck.exe 2014-01-26 07:11 - 2007-12-04 15:59 - 01347615 _____ C:\Windows\WindowsUpdate.log 2014-01-26 06:31 - 2006-11-02 13:47 - 00003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-26 06:31 - 2006-11-02 13:47 - 00003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-26 00:57 - 2014-01-22 12:52 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-25 12:59 - 2014-01-22 12:52 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-25 12:32 - 2006-11-02 11:33 - 01575894 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-25 01:28 - 2010-06-11 20:49 - 00290816 ____N (Microsoft Corporation) C:\Windows\Setup1.exe 2014-01-25 01:28 - 2010-06-11 20:49 - 00074752 _____ (Microsoft Corporation) C:\Windows\ST6UNST.EXE 2014-01-25 00:56 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-25 00:49 - 2013-07-07 19:04 - 00000012 _____ C:\Windows\bthservsdp.dat 2014-01-25 00:49 - 2006-11-02 14:01 - 00032628 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-25 00:47 - 2007-04-16 06:18 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2014-01-25 00:34 - 2007-04-16 06:18 - 00000000 ____D C:\Windows\system32\RTCOM 2014-01-25 00:34 - 2007-04-16 06:18 - 00000000 ____D C:\Program Files\Realtek 2014-01-25 00:33 - 2007-04-16 06:18 - 00319456 _____ (Microsoft Corporation) C:\Windows\DIFxAPI.dll 2014-01-25 00:20 - 2007-04-16 07:01 - 00000000 ____D C:\ProgramData\Toshiba 2014-01-25 00:17 - 2007-04-16 07:16 - 01673978 _____ C:\Windows\PFRO.log 2014-01-24 23:54 - 2007-12-04 17:13 - 00000000 ____D C:\Users\Dolmi 2014-01-24 23:36 - 2014-01-24 23:36 - 00000000 __SHD C:\Windows\system32\%APPDATA% 2014-01-24 23:34 - 2007-04-13 11:11 - 00000000 ____D C:\Program Files\TOSHIBA 2014-01-24 23:25 - 2007-12-04 16:02 - 00072732 _____ C:\Windows\DPINST.LOG 2014-01-24 22:47 - 2014-01-24 20:03 - 14098432 _____ C:\Users\Dolmi\AppData\Roaming\Sandra.mdb 2014-01-24 20:00 - 2014-01-24 19:54 - 00000000 ____D C:\Windows\system32\directx 2014-01-24 19:58 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET 2014-01-24 19:56 - 2007-04-16 07:11 - 00000000 ___HD C:\Windows\msdownld.tmp 2014-01-24 19:45 - 2014-01-24 19:45 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2014-01-24 13:38 - 2014-01-24 13:38 - 00000000 ____D C:\Program Files\iPod 2014-01-24 13:37 - 2009-01-05 23:44 - 00000000 ____D C:\Program Files\Common Files\Apple 2014-01-24 13:30 - 2009-01-05 23:44 - 00000000 ____D C:\ProgramData\Apple 2014-01-24 12:56 - 2014-01-14 18:32 - 00000000 ____D C:\AdwCleaner 2014-01-24 12:42 - 2014-01-24 12:38 - 00043424 _____ C:\Users\Dolmi\Desktop\FRST_140124.txt 2014-01-24 12:24 - 2014-01-24 12:24 - 00001468 _____ C:\Users\Dolmi\Desktop\JRT_140124.txt 2014-01-24 12:09 - 2014-01-14 19:10 - 00000000 ____D C:\ProgramData\IObit 2014-01-24 11:06 - 2014-01-24 11:06 - 01037068 _____ (Thisisu) C:\Users\Dolmi\Desktop\JRT.exe 2014-01-24 10:56 - 2014-01-24 10:56 - 01236282 _____ C:\Users\Dolmi\Desktop\adwcleaner.exe 2014-01-23 20:53 - 2010-08-08 22:34 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\Winamp 2014-01-23 20:04 - 2014-01-23 20:01 - 00030544 _____ C:\Users\Dolmi\Desktop\Addition_140123.txt 2014-01-23 20:04 - 2014-01-23 20:00 - 00045605 _____ C:\Users\Dolmi\Desktop\FRST_140123.txt 2014-01-23 19:59 - 2014-01-23 19:59 - 00000000 ____D C:\FRST 2014-01-23 19:58 - 2014-01-23 19:58 - 01222144 _____ (Farbar) C:\Users\Dolmi\Desktop\FRST.exe 2014-01-23 19:47 - 2014-01-23 19:47 - 00000611 _____ C:\Windows\system32\InstallUtil.InstallLog 2014-01-23 19:42 - 2013-12-12 14:14 - 00000000 ____D C:\Program Files\Mozilla Firefox 2014-01-23 19:40 - 2014-01-23 19:40 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2014-01-23 19:40 - 2014-01-23 19:40 - 00000000 ____D C:\Program Files\Covus Freemium 2014-01-23 19:37 - 2014-01-23 19:37 - 00000000 ____D C:\ProgramData\Package Cache 2014-01-22 11:12 - 2009-08-22 23:12 - 00000000 ____D C:\Users\Dolmi\AppData\Local\Apps\2.0 2014-01-21 20:47 - 2007-12-04 22:56 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\Toshiba 2014-01-21 20:41 - 2014-01-14 19:10 - 00000000 ____D C:\ProgramData\ProductData 2014-01-21 20:23 - 2010-03-23 20:43 - 00000000 ____D C:\Users\Dolmi\AppData\Local\CrashDumps 2014-01-20 02:53 - 2013-08-27 16:42 - 00000000 ____D C:\Windows\pss 2014-01-16 12:15 - 2013-11-06 14:33 - 00000000 ____D C:\Users\Dolmi\Desktop\VerbaVoice 2014-01-15 16:58 - 2013-08-22 12:15 - 00000000 ____D C:\Windows\system32\MRT 2014-01-15 16:51 - 2006-11-02 11:24 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-01-15 01:43 - 2013-10-10 12:42 - 00000000 ____D C:\Program Files\SIW 2014-01-14 23:05 - 2014-01-14 23:05 - 00000000 ____D C:\Windows\ERUNT 2014-01-14 22:33 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\nap 2014-01-14 19:39 - 2014-01-14 19:39 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\Malwarebytes 2014-01-14 19:39 - 2014-01-14 19:39 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-14 19:25 - 2014-01-13 07:55 - 00000000 ____D C:\Program Files\Enigma Software Group 2014-01-14 19:24 - 2014-01-13 23:46 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2014-01-14 19:22 - 2014-01-14 19:22 - 00000079 _____ C:\Windows\wininit.ini 2014-01-14 19:11 - 2014-01-14 19:11 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\ProductData 2014-01-14 19:10 - 2014-01-14 19:10 - 00001050 _____ C:\Users\Dolmi\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk 2014-01-14 19:10 - 2014-01-14 19:10 - 00001026 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk 2014-01-14 19:10 - 2014-01-14 19:10 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\IObit 2014-01-14 19:10 - 2014-01-14 19:10 - 00000000 ____D C:\Program Files\IObit 2014-01-14 18:39 - 2014-01-14 18:39 - 02347384 _____ (ESET) C:\Users\Dolmi\Desktop\esetsmartinstaller_deu.exe 2014-01-14 18:27 - 2014-01-14 18:27 - 00000066 _____ C:\Users\Dolmi\Desktop\Link_Bereinigung.txt 2014-01-14 00:12 - 2006-11-02 11:23 - 00450556 ____R C:\Windows\system32\Drivers\etc\hosts.20140114-001620.backup 2014-01-13 22:58 - 2014-01-12 21:33 - 00000000 ____D C:\Users\Dolmi\AppData\Local\cache 2014-01-13 22:50 - 2014-01-13 11:26 - 00001912 _____ C:\Windows\epplauncher.mif 2014-01-13 22:27 - 2014-01-12 21:33 - 00001410 _____ C:\Users\Dolmi\daemonprocess.txt 2014-01-13 16:57 - 2011-04-27 21:20 - 00012999 _____ C:\Windows\IE9_main.log 2014-01-13 12:36 - 2014-01-12 21:30 - 00000000 ____D C:\Program Files\EnhanceTronic 2014-01-13 11:02 - 2013-01-16 14:03 - 00000000 ____D C:\Users\Dolmi\AppData\Local\NPE 2014-01-13 10:23 - 2006-11-02 13:47 - 00343616 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-13 08:45 - 2014-01-13 08:45 - 00000000 ____D C:\Users\Dolmi\AppData\Roaming\SUPERAntiSpyware.com 2014-01-13 07:57 - 2014-01-14 00:12 - 00000743 _____ C:\Windows\system32\Drivers\etc\hosts.20140114-001258.backup 2014-01-13 00:11 - 2014-01-13 00:11 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUSB_01009.Wdf 2014-01-13 00:11 - 2006-11-02 13:52 - 00126005 _____ C:\Windows\setupact.log 2014-01-13 00:02 - 2014-01-13 00:02 - 01461992 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2014-01-13 00:02 - 2014-01-13 00:02 - 00851176 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller2.dll 2014-01-13 00:02 - 2014-01-13 00:02 - 00053152 _____ C:\Windows\system32\USBCoInstaller.dll 2014-01-12 21:33 - 2014-01-12 21:33 - 00000000 ____D C:\Users\Dolmi\.android 2014-01-12 21:09 - 2007-12-04 17:13 - 00097912 _____ C:\Users\Dolmi\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-07 21:23 - 2007-12-04 18:29 - 00000400 _____ C:\Windows\ODBC.INI 2014-01-06 15:19 - 2010-10-26 21:44 - 00000000 ____D C:\ProgramData\Microsoft Help Some content of TEMP: ==================== C:\Users\Dolmi\AppData\Local\Temp\GenericUninstall.exe C:\Users\Dolmi\AppData\Local\Temp\hsbing_717_active.exe C:\Users\Dolmi\AppData\Local\Temp\mgsqlite3.dll C:\Users\Dolmi\AppData\Local\Temp\Quarantine.exe C:\Users\Dolmi\AppData\Local\Temp\Shortcut_sweetpacks.exe C:\Users\Dolmi\AppData\Local\Temp\uninstaller.exe C:\Users\Dolmi\AppData\Local\Temp\WSSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-26 01:10 ==================== End Of Log ============================ --- --- --- --- --- --- Die Maus bleibt immer noch ab und zu ohne Grund hängen. Ich habe schon eine andere probiert, auch einen anderen USB-Port da ist es genauso. Sie bleibt für ca. 3 oder 4 Sekunden einfach stehen. Eine weitere Info dazu schreibe ich Dir per PN, das möchte ich nicht veröffentlichen. Vielen Dank! Liebe Grüße Geändert von Bethesda (26.01.2014 um 08:22 Uhr) Grund: Nachtrag: Java und Adobe habe ich vorhin aktualisiert |
![]() | #8 |
nach Säuberung: System "hängt" CPU-Auslastung sehr hoch wegen Browser,Flash, Hostprozess Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument
ATTFilter ProxyServer: localhost:8080 Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Bleibt die Maus allgemein hängen oder nur im Browser? Downloade dir bitte Windows Repair (All In One) von hier.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #9 |
| ![]() nach Säuberung: System "hängt" CPU-Auslastung sehr hoch wegen Browser,Flash, Hostprozess Hallo, danke für die schnelle Antwort. Hier erstmal die Fixlist: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 23-01-2014 Ran by Dolmi at 2014-01-26 08:40:40 Run:1 Running from C:\Users\Dolmi\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** ProxyServer: localhost:8080 ***************** HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value deleted successfully. ==== End of Fixlog ==== Das geht dann eine ganze Zeit lang so. War vorhin auch wieder so. Irgendwann ist dann Ruhe. Aber das muss ich jetzt erst mal weiter beobachten. Jetzt mache ich noch die anderen Dinge, die Du mir gesagt hast. Mensch, vielen vielen Dank! Liebe Grüße Hallo, so, jetzt ist alles erledigt. Winrepair scheint auch so einiges gemacht zu haben, aber leider hängt die Maus immer noch und der Arbeitsspeicher ist mit fast 1,5 GB belastet, obwohl ich jetzt nichts auf habe, außer Outlook, aber das kann es ja nicht sein, und hier das Board. Ich sehe das am TaskManager, der kann ja damit auch nichts zu tun haben. Wenn ich auf den Ressourcenmonitor vom TaskManager gehe, dann sehe ich - nein, das brauche ich gar nicht. Ich klicke drauf und er macht erst gar nicht auf, meine Festplatte ist ununterbrochen beschäftigt. Und jetzt? Oh mein Gott ist das krass. Bitte nicht neu installieren - jetzt bekomme ich eine Leistungswarnmeldung vom Norton, dass der Datenträger stark durch einen Hostprozess für Windows beansprucht ist, welchen, kann ich natürlich nicht ablesen. So, jetzt nach ca. 1 oder 2 Min. macht sich der Ressourcenmonitor auf. Liebe Grüße Hallo, die Maus hängt immer noch, er rödelt total auf der Festplatte und Arbeitsspeicher braucht er fast 1,5 GB, obowhl nicht viel offen ist, jedenfalls nichts, was z. B. die Festplatte so beanspruchen würde, oder den Arbeitsspeicher. Sag jetzt bitte nicht, neu installieren. Ist ja echt krass, ich komme da nicht mit. Du kannst gerne mal mit TeamViewer nachschauen, wenn Du willst. Liebe Grüße Hallo, ja, es hängt immer noch alles unverändert. Da ich morgen mit dem System unbedingt arbeiten muss und nicht freinehmen kann, werde ich nun doch alles neu installieren. Die zweite Option für mich wäre, damit ich arbeiten kann, auf die Schnelle einen Laptop kaufen. Da werde ich wohl in den sauren Apfel beißen und neu installieren. Ich danke Dir aber trotzdem sehr für Deine Hilfe! Viele liebe Grüße |
![]() | #10 |
nach Säuberung: System "hängt" CPU-Auslastung sehr hoch wegen Browser,Flash, Hostprozess Ich glaube da ja schon fast an nen Hardware Schaden der Platte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #11 |
| ![]() nach Säuberung: System "hängt" CPU-Auslastung sehr hoch wegen Browser,Flash, Hostprozess Hallo lieber Schrauber, ich hab es letztendlich gelöst und will Dir gerne Rückmeldung geben. Ich hatte multiple Probleme. Zum einen das Ungeziefer, das wir verscheucht haben. Dann habe ich ja neu installiert, weil mir die Zeit unter den Nägeln brannte, da ich berufsmäßig abhängig war. Nach dem Installieren merkte ich, die Maus hängte immer noch. Das Problem war, ich hatte die Maus auf einem anderen Laptop probiert und da war das Problem, dass der Laptop wohl auch verseucht ist, es war also nicht zu differenzieren, dass meine Maus nicht richtig funktionierte. Lange Rede kurzer Sinn, meine Maus funktionierte nicht einwandfrei, ich hatte Ungeziefer drauf und am Ende hatte ich zu wenig RAM (Vista, Intel Duo Core 2,00 GHz, 2 GB RAM) für das, was ich beruflich mache. Ich habe neu installiert, die Maus getauscht, RAM's aufgerüstet und siehe da, alles funktioniert einwandfrei. Ich danke Dir nochmals sehr für Deine Hilfe. Wegen dem anderen Laptop, das werde ich selbst probieren zu säubern und wenn ich nicht zurande komme, würde ich gerne noch mal hierher kommen. Viele liebe Grüße ![]() ![]() ![]() ![]() ![]() ![]() |
![]() | #12 |
nach Säuberung: System "hängt" CPU-Auslastung sehr hoch wegen Browser,Flash, Hostprozess Gern Geschehen ![]()

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() |
Themen zu nach Säuberung: System "hängt" CPU-Auslastung sehr hoch wegen Browser,Flash, Hostprozess |
browser, cpu-auslastung, daten, eset, heute, hostprozess, hängt, komplett, laptop, malware, malwarebytes, maus, meldungen, nicht mehr, nichts, norton, problem, prozess, registry, security, system, total, trojan.agent, wirklich, woche |