|
Log-Analyse und Auswertung: Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
03.02.2014, 10:41 | #16 |
/// the machine /// TB-Ausbilder | Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle?? Scanne den Stick mal mit deinem Antivirenprogramm und mit Malwarebytes.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.02.2014, 15:02 | #17 |
| Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle?? Hab ich gemacht,
__________________Avast meldet keine Funde, konnte aber die Autorun.inf auf dem Stick nicht prüfen, da sie 'nicht zur Verfügung' stand. Sie ist aber dort vorhanden. Malwarebytes findet keine Bedrohungen. -Was ist mit Eset, das doch gar nicht zu Ende gescannt hat? -Thunderbird hat heute beim Verfassen einer E-Mail plötzlich gemeldet, dass eine Datei angehängt wird, und als ich sofort das Programm schloss, kam die Meldung: Thunderbird ist dabei, eine Nachricht zu versenden (ich war weit weg vom Senden-Button)... Gruß, jo07 |
04.02.2014, 09:59 | #18 |
/// the machine /// TB-Ausbilder | Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle?? ESET ist nur da um auf Reste zu scannen, und hat bis zum Abbruch nur inaktiven Müll gefunden. Poste bitte mal ein frisches FRST log.
__________________
__________________ |
04.02.2014, 10:25 | #19 |
| Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle?? Hier: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-02-2014 Ran by **** (ATTENTION: The logged in user is not administrator) on ****-PC on 04-02-2014 10:09:30 Running from C:\Users\****\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Acer Inc.) C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (AVAST Software) C:\Program Files\Avast5\AvastUI.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Hidfind.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation) HKLM\...\Run: [ePower_DMC] - C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [492032 2009-07-21] (Acer Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8060960 2009-08-06] (Realtek Semiconductor) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [295936 2009-05-22] (Alps Electric Co., Ltd.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.) HKLM-x32\...\Run: [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\Avast5\AvastUI.exe [3767096 2014-02-04] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Run: [Duden Korrektor SysTray] - C:\Program Files (x86)\Duden\Duden Korrektor\DKtray.exe [619216 2009-05-18] (Expert System S.p.A.) HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18642024 2013-02-28] (Skype Technologies S.A.) HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Run: [AutoStart-Manager 2006] - C:\Program Files (x86)\Tools&More\Autostart-Manager\AutoStart-Manager.exe [397312 2005-12-23] (Wirth New Media Sarl ) HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.bing.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5230&r=27361109a116l0308z185i4751t287 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR URLSearchHook: HKCU - (No Name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No File SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_de SearchScopes: HKCU - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Avast5\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - No Name - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - No File Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\Avast5\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No File DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default FF DefaultSearchEngine: benefind FF SelectedSearchEngine: benefind FF Homepage: hxxp://www.benefind.de FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.13.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8064.0206 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: nuance.com/DragonRIAPlugin - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\npDgnRia.dll (Nuance Communications Inc.) FF Plugin HKCU: @citrixonline.com/appdetectorplugin - C:\Users\****\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF SearchPlugin: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default\searchplugins\100-search-engines.xml FF SearchPlugin: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default\searchplugins\benefind.xml FF SearchPlugin: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default\searchplugins\ecosia.xml FF SearchPlugin: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default\searchplugins\scroogle-ssl-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: RequestPolicy - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default\Extensions\requestpolicy@requestpolicy.com.xpi [2013-01-29] FF Extension: NoScript - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-01-28] FF Extension: Google Privacy - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default\Extensions\{ea61041c-1e22-4400-99a0-aea461e69d04}.xpi [2013-01-28] FF HKLM-x32\...\Firefox\Extensions: [jid0-lmZNVK7a82O8cufhdfB9dUDfA2w@jetpack] - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\ffShim.xpi FF Extension: No Name - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\ffShim.xpi [2012-07-13] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Avast5\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\Avast5\WebRep\FF [2011-04-25] ==================== Services (Whitelisted) ================= R2 ABBYY.Licensing.FineReader.Professional.11.0; C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe [819976 2011-09-22] (ABBYY) R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759072 2008-10-09] (ABBYY (BIT Software)) R2 avast! Antivirus; C:\Program Files\Avast5\AvastSvc.exe [50344 2014-02-04] (AVAST Software) R2 ETService; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [24576 2009-08-12] () R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 MSSQL$MSSMLBIZ; c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation) S2 NewServiceInstall1; C:\Program Files (x86)\SDL International\T2007_FL\TT\Lng\Dialogs1031.lng [11264 2007-04-23] () R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [253952 2009-07-10] (Acer Incorporated) S2 LEC TranslateDotNet Server; "C:\Program Files (x86)\Power Translator 12\LogoMedia TranslateDotNet Server.exe" [X] ==================== Drivers (Whitelisted) ==================== R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2013-10-23] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-04] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-23] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-23] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-04] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-04] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-04] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-27] () R3 bbcap; C:\Windows\System32\DRIVERS\bbcap.sys [4608 2010-12-23] (Windows (R) Codename Longhorn DDK provider) S3 O2MDRDR; C:\Windows\system32\DRIVERS\o2mdx64.sys [63264 2009-05-07] (O2Micro ) S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-04 10:08 - 2014-02-04 10:08 - 00000000 ____D () C:\Users\****\Downloads\FRST-OlderVersion 2014-02-04 05:54 - 2014-02-04 05:55 - 01331205 _____ () C:\Users\****\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_es.exe 2014-02-03 16:22 - 2014-02-03 16:22 - 00000936 _____ () C:\Users\Public\Desktop\FreeFileSync.lnk 2014-02-03 16:14 - 2014-02-03 16:14 - 10389616 _____ () C:\Users\****\Downloads\FreeFileSync_6.2_Windows_Setup.exe 2014-02-03 16:12 - 2014-02-03 16:12 - 05329480 _____ (Secunia) C:\Users\****\Downloads\PSISetup_3.0.0.9016.exe 2014-02-03 16:05 - 2014-02-03 16:05 - 00707006 _____ () C:\Users\****\Downloads\delfix.exe 2014-02-01 00:30 - 2014-02-04 10:09 - 00017504 _____ () C:\Users\****\Downloads\FRST.txt 2014-01-31 23:23 - 2014-01-31 23:23 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-01-31 21:32 - 2014-01-31 21:32 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-01-30 18:11 - 2014-01-30 18:11 - 00000000 ____D () C:\Windows\system32\%LOCALAPPDATA% 2014-01-30 17:18 - 2014-01-30 17:18 - 00000893 _____ () C:\Users\Admin\Desktop\JRT.txt 2014-01-30 17:06 - 2014-01-30 17:06 - 00000000 ____D () C:\Windows\ERUNT 2014-01-30 16:14 - 2014-01-30 16:42 - 00000000 ____D () C:\AdwCleaner 2014-01-30 15:37 - 2014-01-30 15:37 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Malwarebytes 2014-01-30 15:34 - 2014-01-30 15:34 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-30 15:34 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-30 15:25 - 2014-01-30 15:25 - 01037068 _____ (Thisisu) C:\Users\****\Downloads\JRT.exe 2014-01-30 15:19 - 2014-01-30 15:19 - 01166132 _____ () C:\Users\****\Downloads\adwcleaner.exe 2014-01-30 15:17 - 2014-01-30 15:18 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\****\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-29 14:28 - 2014-01-29 14:28 - 00000000 ____D () C:\Users\****\AppData\Roaming\AVAST Software 2014-01-29 13:17 - 2014-01-29 13:24 - 00462752 _____ () C:\Users\****\Desktop\Gmer.txt 2014-01-29 13:16 - 2014-01-29 13:16 - 00462761 _____ () C:\Users\Admin\Desktop\Gmer.log 2014-01-29 12:08 - 2014-01-29 12:08 - 00658328 _____ () C:\Users\Admin\Desktop\Gmer.txt 2014-01-29 10:26 - 2014-01-29 11:07 - 00029581 _____ () C:\Users\****\Desktop\Addition.txt 2014-01-29 10:24 - 2014-01-29 10:55 - 00034881 _____ () C:\Users\****\Desktop\FRST.txt 2014-01-29 10:06 - 2014-02-04 10:09 - 00000000 ____D () C:\FRST 2014-01-29 09:29 - 2014-01-29 09:29 - 00370971 _____ () C:\Users\****\Desktop\gmer_2.1.19355.zip 2014-01-29 09:23 - 2014-02-04 10:08 - 02080256 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe 2014-01-29 09:23 - 2014-01-29 09:23 - 00050477 _____ () C:\Users\****\Downloads\Defogger(1).exe 2014-01-28 23:39 - 2014-01-28 23:40 - 00002210 _____ () C:\Windows\wininit.ini 2014-01-28 20:39 - 2014-01-28 22:54 - 00359656 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\msicuu2.exe 2014-01-28 14:23 - 2014-01-28 14:23 - 00283096 _____ (Mozilla) C:\Users\****\Downloads\Firefox Setup Stub 26.0.exe 2014-01-27 16:46 - 2014-01-27 16:48 - 90578216 _____ (AVAST Software) C:\Users\****\Downloads\avast_free_antivirus_setup.exe 2014-01-26 12:43 - 2014-01-26 12:43 - 00000000 ____D () C:\.jes 2014-01-24 23:40 - 2014-01-24 23:40 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih(1).exe 2014-01-24 22:11 - 2014-01-24 22:11 - 00000000 ____D () C:\ProgramData\Oracle 2014-01-24 22:10 - 2014-01-24 22:10 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-01-24 22:10 - 2014-01-24 22:10 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-01-24 22:10 - 2014-01-24 22:10 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-01-24 22:10 - 2014-01-24 22:10 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-01-24 22:06 - 2014-01-30 16:42 - 00000000 ____D () C:\ProgramData\Uniblue 2014-01-24 21:56 - 2014-01-24 21:56 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\AVAST Software 2014-01-24 21:48 - 2014-01-24 21:51 - 00000000 ____D () C:\Users\Desktop\Dragon NaturallySpeaking 11 Home 2014-01-24 21:48 - 2013-03-04 11:09 - 00005757 _____ () C:\Users\Desktop\ADMIN-Aktionen ab 28-01-13.doc - Verknüpfung.lnk 2014-01-24 21:48 - 2013-02-04 18:21 - 00001042 _____ () C:\Users\Desktop\ProjectX.jar - Verknüpfung.lnk 2014-01-24 21:48 - 2013-02-04 18:11 - 00208384 _____ (Imago) C:\Users\Desktop\ImagoMPEG-Muxer.exe 2014-01-24 21:48 - 2012-10-09 13:55 - 00001014 _____ () C:\Users\Desktop\kreawi Prüfungstrainer (Demo).lnk 2014-01-24 21:48 - 2012-05-05 20:14 - 00001380 _____ () C:\Users\Desktop\CopyTrans Control Center.lnk 2014-01-24 21:48 - 2011-09-22 10:05 - 00001172 _____ () C:\Users\Desktop\WavePad Sound Editor.lnk 2014-01-24 21:48 - 2011-09-01 07:08 - 00000977 _____ () C:\Users\Desktop\Juice.lnk 2014-01-24 21:48 - 2011-05-16 06:41 - 00006332 _____ () C:\Users\Desktop\Router_Setup.html 2014-01-24 21:48 - 2011-04-07 13:35 - 00001304 _____ () C:\Users\Desktop\Audio Converter.lnk 2014-01-24 21:48 - 2011-03-26 12:29 - 00001402 _____ () C:\Users\Desktop\YouTube to MP3 Converter.lnk 2014-01-24 21:48 - 2011-03-26 12:29 - 00001243 _____ () C:\Users\Desktop\DVDVideoSoft Studio.lnk 2014-01-24 21:48 - 2009-05-20 22:32 - 00000172 ____R () C:\Users\Desktop\Router Login.url 2014-01-24 21:42 - 2014-01-24 21:42 - 00000667 _____ () C:\Besitz übernehmen.reg 2014-01-24 21:36 - 2014-01-24 21:36 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe 2014-01-23 12:44 - 2014-01-23 12:44 - 00001781 _____ () C:\Users\Public\Desktop\f4.lnk 2014-01-23 12:43 - 2014-01-23 12:43 - 00006906 _____ () C:\Windows\SysWOW64\jupdate-1.6.0_07-b06.log 2014-01-23 12:42 - 2014-01-23 12:44 - 00000000 ____D () C:\Program Files (x86)\f4 2014-01-15 14:26 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 14:26 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 14:26 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 14:26 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 14:26 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 14:26 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 14:26 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 14:26 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 14:26 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-09 15:09 - 2014-01-09 18:12 - 00000000 ____D () C:\Users\****\Documents\Family Tree Maker 2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\IsolatedStorage 2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\Ancestry.com 2014-01-09 14:49 - 2014-01-09 14:49 - 00000000 ____D () C:\IExp1.tmp 2014-01-09 14:48 - 2014-01-09 14:49 - 00000000 ___HD () C:\Windows\msdownld.tmp 2014-01-09 14:48 - 2014-01-09 14:48 - 00002043 _____ () C:\Users\Public\Desktop\Family Tree Maker 2010 (DE).lnk 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Windows\RegisteredPackages 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft WSE 3.0 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\IExp0.tmp 2014-01-09 14:43 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\Family Tree Maker 2010 (DE) 2014-01-09 14:43 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\BCL Technologies 2014-01-09 14:34 - 2014-01-09 14:34 - 00000000 ____D () C:\Users\****\AppData\Roaming\YORAKO 2014-01-09 14:31 - 2014-01-09 14:31 - 00000000 ____D () C:\Program Files (x86)\Namenslexikon ==================== One Month Modified Files and Folders ======= 2014-02-04 10:09 - 2014-02-01 00:30 - 00017504 _____ () C:\Users\****\Downloads\FRST.txt 2014-02-04 10:09 - 2014-01-29 10:06 - 00000000 ____D () C:\FRST 2014-02-04 10:08 - 2014-02-04 10:08 - 00000000 ____D () C:\Users\****\Downloads\FRST-OlderVersion 2014-02-04 10:08 - 2014-01-29 09:23 - 02080256 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe 2014-02-04 10:00 - 2010-04-05 13:37 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-04 09:58 - 2010-06-20 22:32 - 00000000 ____D () C:\Users\Admin 2014-02-04 09:43 - 2010-04-05 13:46 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-04 09:32 - 2009-09-08 05:37 - 01588905 _____ () C:\Windows\WindowsUpdate.log 2014-02-04 09:14 - 2013-01-28 11:45 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-04 08:09 - 2009-07-14 05:45 - 00017600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-04 08:09 - 2009-07-14 05:45 - 00017600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-04 08:01 - 2011-09-22 18:24 - 00043978 _____ () C:\Windows\setupact.log 2014-02-04 08:01 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-04 05:55 - 2014-02-04 05:54 - 01331205 _____ () C:\Users\****\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_es.exe 2014-02-04 04:57 - 2010-06-06 09:45 - 00000000 ____D () C:\Program Files\Avast5 2014-02-04 04:56 - 2011-11-13 17:03 - 00098946 _____ () C:\Windows\PFRO.log 2014-02-04 04:55 - 2010-05-14 22:01 - 00000404 _____ () C:\Windows\Brownie.ini 2014-02-04 04:53 - 2013-12-27 08:46 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-02-04 04:53 - 2013-10-23 08:24 - 00001836 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-02-04 04:53 - 2013-03-27 21:43 - 00001776 _____ () C:\Users\Public\Desktop\avast! Pro Antivirus.lnk 2014-02-04 04:53 - 2011-04-25 10:51 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-02-04 04:53 - 2011-01-16 11:42 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-02-04 04:53 - 2010-06-29 12:27 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-02-04 04:53 - 2010-06-06 09:46 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2014-02-04 04:53 - 2010-06-06 09:46 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-02-03 21:58 - 2010-10-11 12:25 - 00000000 ___RD () C:\Users\****\Documents\hp 2014-02-03 21:00 - 2009-09-08 15:27 - 00754068 _____ () C:\Windows\system32\perfh007.dat 2014-02-03 21:00 - 2009-09-08 15:27 - 00171888 _____ () C:\Windows\system32\perfc007.dat 2014-02-03 21:00 - 2009-07-14 06:13 - 01760852 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-03 16:22 - 2014-02-03 16:22 - 00000936 _____ () C:\Users\Public\Desktop\FreeFileSync.lnk 2014-02-03 16:14 - 2014-02-03 16:14 - 10389616 _____ () C:\Users\****\Downloads\FreeFileSync_6.2_Windows_Setup.exe 2014-02-03 16:12 - 2014-02-03 16:12 - 05329480 _____ (Secunia) C:\Users\****\Downloads\PSISetup_3.0.0.9016.exe 2014-02-03 16:05 - 2014-02-03 16:05 - 00707006 _____ () C:\Users\****\Downloads\delfix.exe 2014-02-02 10:20 - 2013-05-22 20:58 - 00000244 _____ () C:\Users\****\Downloads\defogger_enable.log 2014-02-02 04:17 - 2013-08-01 11:34 - 00000000 ____D () C:\pending 2014-01-31 23:23 - 2014-01-31 23:23 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-01-31 21:32 - 2014-01-31 21:32 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-01-30 18:11 - 2014-01-30 18:11 - 00000000 ____D () C:\Windows\system32\%LOCALAPPDATA% 2014-01-30 17:52 - 2013-03-10 18:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-01-30 17:52 - 2010-09-10 12:01 - 00000000 ____D () C:\Users\Admin\AppData\Local\Thunderbird 2014-01-30 17:18 - 2014-01-30 17:18 - 00000893 _____ () C:\Users\Admin\Desktop\JRT.txt 2014-01-30 17:06 - 2014-01-30 17:06 - 00000000 ____D () C:\Windows\ERUNT 2014-01-30 16:42 - 2014-01-30 16:14 - 00000000 ____D () C:\AdwCleaner 2014-01-30 16:42 - 2014-01-24 22:06 - 00000000 ____D () C:\ProgramData\Uniblue 2014-01-30 16:42 - 2011-11-30 17:44 - 00000000 ____D () C:\Users\****\AppData\Roaming\Babylon 2014-01-30 15:37 - 2014-01-30 15:37 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Malwarebytes 2014-01-30 15:34 - 2014-01-30 15:34 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-30 15:25 - 2014-01-30 15:25 - 01037068 _____ (Thisisu) C:\Users\****\Downloads\JRT.exe 2014-01-30 15:19 - 2014-01-30 15:19 - 01166132 _____ () C:\Users\****\Downloads\adwcleaner.exe 2014-01-30 15:18 - 2014-01-30 15:17 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\****\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-30 11:38 - 2010-03-30 15:51 - 00088479 _____ () C:\Windows\Run32A50.mch 2014-01-30 09:58 - 2010-03-31 16:16 - 00000131 _____ () C:\Windows\Star.ini 2014-01-30 09:58 - 2010-03-30 15:59 - 00000000 ____D () C:\Program Files (x86)\Transit XV 2014-01-30 09:58 - 2010-03-30 15:28 - 00000035 _____ () C:\Windows\A5W.INI 2014-01-30 09:58 - 2010-03-30 15:28 - 00000000 ____D () C:\Windows\A5W_DATA 2014-01-29 15:06 - 2011-10-28 20:16 - 00002035 _____ () C:\Users\****\AppData\Roaming\SAS7_000.DAT 2014-01-29 14:39 - 2013-01-28 11:45 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-01-29 14:39 - 2013-01-28 11:45 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-01-29 14:39 - 2010-10-13 14:13 - 00000000 ____D () C:\Users\Admin\AppData\Local\Adobe 2014-01-29 14:35 - 2011-06-21 08:30 - 00000000 ____D () C:\Users\**** 2014-01-29 14:28 - 2014-01-29 14:28 - 00000000 ____D () C:\Users\****\AppData\Roaming\AVAST Software 2014-01-29 13:24 - 2014-01-29 13:17 - 00462752 _____ () C:\Users\****\Desktop\Gmer.txt 2014-01-29 13:16 - 2014-01-29 13:16 - 00462761 _____ () C:\Users\Admin\Desktop\Gmer.log 2014-01-29 12:08 - 2014-01-29 12:08 - 00658328 _____ () C:\Users\Admin\Desktop\Gmer.txt 2014-01-29 11:07 - 2014-01-29 10:26 - 00029581 _____ () C:\Users\****\Desktop\Addition.txt 2014-01-29 10:55 - 2014-01-29 10:24 - 00034881 _____ () C:\Users\****\Desktop\FRST.txt 2014-01-29 09:33 - 2013-05-07 18:29 - 00000472 _____ () C:\Users\****\Desktop\defogger_disable.log 2014-01-29 09:29 - 2014-01-29 09:29 - 00370971 _____ () C:\Users\****\Desktop\gmer_2.1.19355.zip 2014-01-29 09:23 - 2014-01-29 09:23 - 00050477 _____ () C:\Users\****\Downloads\Defogger(1).exe 2014-01-29 07:14 - 2012-02-17 20:49 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-01-28 23:40 - 2014-01-28 23:39 - 00002210 _____ () C:\Windows\wininit.ini 2014-01-28 23:11 - 2012-02-17 20:49 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2014-01-28 23:10 - 2011-10-28 02:28 - 00000000 ____D () C:\Program Files (x86)\Power Translator 12 2014-01-28 22:54 - 2014-01-28 20:39 - 00359656 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\msicuu2.exe 2014-01-28 22:03 - 2013-06-11 12:23 - 00000000 ____D () C:\Program Files\WinRAR 2014-01-28 20:17 - 2013-11-17 21:07 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-28 20:17 - 2012-05-05 21:43 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-01-28 20:14 - 2011-11-13 15:37 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-01-28 20:11 - 2011-01-02 21:41 - 00000000 ____D () C:\ProgramData\Apple 2014-01-28 19:44 - 2009-08-26 06:16 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-01-28 19:44 - 2009-08-22 11:23 - 00000000 ____D () C:\Windows\ShellNew 2014-01-28 19:27 - 2009-08-26 06:16 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-01-28 19:27 - 2009-07-14 03:34 - 00000449 _____ () C:\Windows\win.ini 2014-01-28 18:12 - 2011-10-29 23:34 - 00000000 ____D () C:\Program Files (x86)\ABBYY FineReader 11 2014-01-28 14:23 - 2014-01-28 14:23 - 00283096 _____ (Mozilla) C:\Users\****\Downloads\Firefox Setup Stub 26.0.exe 2014-01-28 11:34 - 2009-08-22 10:33 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-01-28 11:32 - 2013-10-22 10:58 - 00000000 ____D () C:\ProgramData\SYSTRAN 2014-01-27 16:48 - 2014-01-27 16:46 - 90578216 _____ (AVAST Software) C:\Users\****\Downloads\avast_free_antivirus_setup.exe 2014-01-26 19:15 - 2010-08-05 10:27 - 00000000 ____D () C:\Users\****\AppData\Roaming\FileZilla 2014-01-26 13:57 - 2009-11-16 20:36 - 00115976 _____ () C:\Users\****\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-26 13:55 - 2009-07-14 05:45 - 00453088 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-26 13:48 - 2010-07-06 09:38 - 00115976 _____ () C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-26 12:50 - 2009-11-29 16:01 - 00000633 _____ () C:\Windows\ODBC.INI 2014-01-26 12:49 - 2010-07-06 09:38 - 00000000 ___RD () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-26 12:49 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system 2014-01-26 12:43 - 2014-01-26 12:43 - 00000000 ____D () C:\.jes 2014-01-25 10:46 - 2011-11-05 14:56 - 00000000 ____D () C:\Users\****\Downloads\F4 installationsordner 2014-01-24 23:52 - 2013-10-22 13:47 - 00000000 ____D () C:\Users\****\AppData\Roaming\SYSTRAN 2014-01-24 23:52 - 2013-10-22 13:47 - 00000000 ____D () C:\Users\****\AppData\Local\SYSTRAN 2014-01-24 23:40 - 2014-01-24 23:40 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih(1).exe 2014-01-24 22:13 - 2010-07-06 09:39 - 00000000 ____D () C:\Users\Admin\AppData\Local\Mozilla 2014-01-24 22:11 - 2014-01-24 22:11 - 00000000 ____D () C:\ProgramData\Oracle 2014-01-24 22:10 - 2014-01-24 22:10 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-01-24 22:10 - 2014-01-24 22:10 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-01-24 22:10 - 2014-01-24 22:10 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-01-24 22:10 - 2014-01-24 22:10 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-01-24 22:10 - 2010-06-29 13:48 - 00000000 ____D () C:\Program Files (x86)\Java 2014-01-24 21:56 - 2014-01-24 21:56 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\AVAST Software 2014-01-24 21:56 - 2010-07-06 09:38 - 00001425 _____ () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-24 21:56 - 2010-07-06 09:38 - 00000000 ___RD () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-01-24 21:56 - 2010-07-06 09:37 - 00000000 ____D () C:\Users\Admin\AppData\Local\VirtualStore 2014-01-24 21:51 - 2014-01-24 21:48 - 00000000 ____D () C:\Users\Desktop\Dragon NaturallySpeaking 11 Home 2014-01-24 21:42 - 2014-01-24 21:42 - 00000667 _____ () C:\Besitz übernehmen.reg 2014-01-24 21:36 - 2014-01-24 21:36 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe 2014-01-24 06:51 - 2010-05-14 22:04 - 00000432 _____ () C:\Windows\BRWMARK.INI 2014-01-24 04:39 - 2011-12-18 18:23 - 00000000 ____D () C:\Users\****\AppData\Local\.elfohilfe 2014-01-23 12:44 - 2014-01-23 12:44 - 00001781 _____ () C:\Users\Public\Desktop\f4.lnk 2014-01-23 12:44 - 2014-01-23 12:42 - 00000000 ____D () C:\Program Files (x86)\f4 2014-01-23 12:43 - 2014-01-23 12:43 - 00006906 _____ () C:\Windows\SysWOW64\jupdate-1.6.0_07-b06.log 2014-01-23 01:17 - 2010-08-04 21:37 - 00000000 ____D () C:\Users\****\AppData\Roaming\vlc 2014-01-23 01:12 - 2012-04-19 18:52 - 00000000 ____D () C:\Users\****\AppData\Roaming\dvdcss 2014-01-22 15:22 - 2013-03-27 19:49 - 00030863 _____ () C:\Users\****\Downloads\Feiertage_2009-2013_DE.ics 2014-01-15 18:11 - 2013-07-27 10:08 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-15 18:07 - 2010-05-09 20:43 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-09 18:12 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\Documents\Family Tree Maker 2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\IsolatedStorage 2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\Ancestry.com 2014-01-09 14:49 - 2014-01-09 14:49 - 00000000 ____D () C:\IExp1.tmp 2014-01-09 14:49 - 2014-01-09 14:48 - 00000000 ___HD () C:\Windows\msdownld.tmp 2014-01-09 14:48 - 2014-01-09 14:48 - 00002043 _____ () C:\Users\Public\Desktop\Family Tree Maker 2010 (DE).lnk 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Windows\RegisteredPackages 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft WSE 3.0 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\IExp0.tmp 2014-01-09 14:48 - 2014-01-09 14:43 - 00000000 ____D () C:\Program Files (x86)\Family Tree Maker 2010 (DE) 2014-01-09 14:48 - 2014-01-09 14:43 - 00000000 ____D () C:\Program Files (x86)\BCL Technologies 2014-01-09 14:34 - 2014-01-09 14:34 - 00000000 ____D () C:\Users\****\AppData\Roaming\YORAKO 2014-01-09 14:31 - 2014-01-09 14:31 - 00000000 ____D () C:\Program Files (x86)\Namenslexikon Files to move or delete: ==================== C:\Users\Desktop\ImagoMPEG-Muxer.exe C:\Users\****\FineCount.reg Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\Quarantine.exe C:\Users\****\AppData\Local\Temp\DivXSetup.exe C:\Users\****\AppData\Local\Temp\DWPUpgradeInstaller.exe C:\Users\****\AppData\Local\Temp\ffmpeg13.exe C:\Users\****\AppData\Local\Temp\jna666123695494861687.dll C:\Users\****\AppData\Local\Temp\RSPUpgradeInstaller.exe C:\Users\****\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== End Of Log ============================ |
05.02.2014, 08:20 | #20 |
/// the machine /// TB-Ausbilder | Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle?? Unsre Tools brauchen immer Adminrechte, bitte FRST mit ADminrechten scannen lassen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
05.02.2014, 10:50 | #21 |
| Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-02-2014 Ran by Admin (administrator) on ****-PC on 05-02-2014 10:44:07 Running from C:\Users\****\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVAST Software) C:\Program Files\Avast5\AvastSvc.exe (ABBYY) C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe (ABBYY (BIT Software)) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe () C:\Program Files\Acer\Empowering Technology\Service\ETService.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (O2Micro International) C:\Windows\System32\drivers\o2flash.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Acer Inc.) C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (AVAST Software) C:\Program Files\Avast5\AvastUI.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Hidfind.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\splwow64.exe (brother) C:\Program Files (x86)\Brownie\BrStsW64.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation) HKLM\...\Run: [ePower_DMC] - C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [492032 2009-07-21] (Acer Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8060960 2009-08-06] (Realtek Semiconductor) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [295936 2009-05-22] (Alps Electric Co., Ltd.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.) HKLM-x32\...\Run: [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\Avast5\AvastUI.exe [3767096 2014-02-04] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Run: [Duden Korrektor SysTray] - C:\Program Files (x86)\Duden\Duden Korrektor\DKtray.exe [619216 2009-05-18] (Expert System S.p.A.) HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18642024 2013-02-28] (Skype Technologies S.A.) HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Run: [AutoStart-Manager 2006] - C:\Program Files (x86)\Tools&More\Autostart-Manager\AutoStart-Manager.exe [397312 2005-12-23] (Wirth New Media Sarl ) HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-739932340-378401146-3079080163-1005\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2068856 2011-10-12] (Flexera Software LLC.) HKU\S-1-5-21-739932340-378401146-3079080163-1005\...\Run: [SpybotSD TeaTimer] - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\S-1-5-21-739932340-378401146-3079080163-1005\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-739932340-378401146-3079080163-1005\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5230&r=27361109a116l0308z185i4751t287 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5230&r=27361109a116l0308z185i4751t287 SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&r=83 SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Avast5\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - No Name - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - No File Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\Avast5\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i7k1i9pr.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.13.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8064.0206 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: nuance.com/DragonRIAPlugin - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\npDgnRia.dll (Nuance Communications Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: FTdownloader V3.0 - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i7k1i9pr.default\Extensions\ftdownloader3@ftdownloader.com.xpi [2013-04-11] FF HKLM-x32\...\Firefox\Extensions: [jid0-lmZNVK7a82O8cufhdfB9dUDfA2w@jetpack] - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\ffShim.xpi FF Extension: No Name - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\ffShim.xpi [2012-07-13] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Avast5\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\Avast5\WebRep\FF [2011-04-25] ==================== Services (Whitelisted) ================= R2 ABBYY.Licensing.FineReader.Professional.11.0; C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe [819976 2011-09-22] (ABBYY) R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759072 2008-10-09] (ABBYY (BIT Software)) R2 avast! Antivirus; C:\Program Files\Avast5\AvastSvc.exe [50344 2014-02-04] (AVAST Software) R2 ETService; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [24576 2009-08-12] () R2 MSSQL$MSSMLBIZ; c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation) S2 NewServiceInstall1; C:\Program Files (x86)\SDL International\T2007_FL\TT\Lng\Dialogs1031.lng [11264 2007-04-23] () R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [253952 2009-07-10] (Acer Incorporated) S2 LEC TranslateDotNet Server; "C:\Program Files (x86)\Power Translator 12\LogoMedia TranslateDotNet Server.exe" [X] ==================== Drivers (Whitelisted) ==================== R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2013-10-23] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-04] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-23] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-23] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-04] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-04] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-04] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-27] () R3 bbcap; C:\Windows\System32\DRIVERS\bbcap.sys [4608 2010-12-23] (Windows (R) Codename Longhorn DDK provider) S3 O2MDRDR; C:\Windows\system32\DRIVERS\o2mdx64.sys [63264 2009-05-07] (O2Micro ) S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-05 08:31 - 2014-02-05 08:31 - 00113513 _____ () C:\Users\****\Downloads\S_20140205_083134_Kontoauszuege.zip 2014-02-04 10:08 - 2014-02-04 10:08 - 00000000 ____D () C:\Users\****\Downloads\FRST-OlderVersion 2014-02-04 05:54 - 2014-02-04 05:55 - 01331205 _____ () C:\Users\****\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_es.exe 2014-02-03 16:22 - 2014-02-03 16:22 - 00000936 _____ () C:\Users\Public\Desktop\FreeFileSync.lnk 2014-02-03 16:14 - 2014-02-03 16:14 - 10389616 _____ () C:\Users\****\Downloads\FreeFileSync_6.2_Windows_Setup.exe 2014-02-03 16:12 - 2014-02-03 16:12 - 05329480 _____ (Secunia) C:\Users\****\Downloads\PSISetup_3.0.0.9016.exe 2014-02-03 16:05 - 2014-02-03 16:05 - 00707006 _____ () C:\Users\****\Downloads\delfix.exe 2014-02-01 00:30 - 2014-02-05 10:44 - 00018001 _____ () C:\Users\****\Downloads\FRST.txt 2014-01-31 23:23 - 2014-01-31 23:23 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-01-31 21:32 - 2014-01-31 21:32 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-01-30 18:11 - 2014-01-30 18:11 - 00000000 ____D () C:\Windows\system32\%LOCALAPPDATA% 2014-01-30 17:18 - 2014-01-30 17:18 - 00000893 _____ () C:\Users\Admin\Desktop\JRT.txt 2014-01-30 17:06 - 2014-01-30 17:06 - 00000000 ____D () C:\Windows\ERUNT 2014-01-30 16:14 - 2014-01-30 16:42 - 00000000 ____D () C:\AdwCleaner 2014-01-30 15:37 - 2014-01-30 15:37 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Malwarebytes 2014-01-30 15:34 - 2014-01-30 15:34 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-30 15:34 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-30 15:25 - 2014-01-30 15:25 - 01037068 _____ (Thisisu) C:\Users\****\Downloads\JRT.exe 2014-01-30 15:19 - 2014-01-30 15:19 - 01166132 _____ () C:\Users\****\Downloads\adwcleaner.exe 2014-01-30 15:17 - 2014-01-30 15:18 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\****\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-29 14:35 - 2014-01-29 14:35 - 00000000 ____D () C:\Users\****\AppData\Roaming\AVAST Software 2014-01-29 14:28 - 2014-01-29 14:28 - 00000000 ____D () C:\Users\****\AppData\Roaming\AVAST Software 2014-01-29 13:17 - 2014-01-29 13:24 - 00462752 _____ () C:\Users\****\Desktop\Gmer.txt 2014-01-29 13:16 - 2014-01-29 13:16 - 00462761 _____ () C:\Users\Admin\Desktop\Gmer.log 2014-01-29 12:08 - 2014-01-29 12:08 - 00658328 _____ () C:\Users\Admin\Desktop\Gmer.txt 2014-01-29 10:26 - 2014-01-29 11:07 - 00029581 _____ () C:\Users\****\Desktop\Addition.txt 2014-01-29 10:24 - 2014-01-29 10:55 - 00034881 _____ () C:\Users\****\Desktop\FRST.txt 2014-01-29 10:06 - 2014-02-05 10:44 - 00000000 ____D () C:\FRST 2014-01-29 09:29 - 2014-01-29 09:29 - 00370971 _____ () C:\Users\****\Desktop\gmer_2.1.19355.zip 2014-01-29 09:23 - 2014-02-04 10:08 - 02080256 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe 2014-01-29 09:23 - 2014-01-29 09:23 - 00050477 _____ () C:\Users\****\Downloads\Defogger(1).exe 2014-01-28 23:39 - 2014-01-28 23:40 - 00002210 _____ () C:\Windows\wininit.ini 2014-01-28 20:39 - 2014-01-28 22:54 - 00359656 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\msicuu2.exe 2014-01-28 14:23 - 2014-01-28 14:23 - 00283096 _____ (Mozilla) C:\Users\****\Downloads\Firefox Setup Stub 26.0.exe 2014-01-27 16:46 - 2014-01-27 16:48 - 90578216 _____ (AVAST Software) C:\Users\****\Downloads\avast_free_antivirus_setup.exe 2014-01-26 12:43 - 2014-01-26 12:43 - 00000000 ____D () C:\.jes 2014-01-25 10:19 - 2014-01-25 10:19 - 00002990 _____ () C:\Windows\System32\Tasks\{0D62AA74-773C-46F2-8D73-5A27790ADB3C} 2014-01-25 10:18 - 2014-01-25 10:18 - 00002990 _____ () C:\Windows\System32\Tasks\{B23F0548-59D2-45AD-ABA2-4A3298638B83} 2014-01-24 23:40 - 2014-01-24 23:40 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih(1).exe 2014-01-24 22:11 - 2014-01-24 22:11 - 00000000 ____D () C:\ProgramData\Oracle 2014-01-24 22:10 - 2014-01-24 22:10 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-01-24 22:10 - 2014-01-24 22:10 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-01-24 22:10 - 2014-01-24 22:10 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-01-24 22:10 - 2014-01-24 22:10 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-01-24 22:06 - 2014-01-30 16:42 - 00000000 ____D () C:\ProgramData\Uniblue 2014-01-24 21:56 - 2014-01-24 21:56 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\AVAST Software 2014-01-24 21:48 - 2014-01-24 21:51 - 00000000 ____D () C:\Users\Desktop\Dragon NaturallySpeaking 11 Home 2014-01-24 21:48 - 2013-03-04 11:09 - 00005757 _____ () C:\Users\Desktop\ADMIN-Aktionen ab 28-01-13.doc - Verknüpfung.lnk 2014-01-24 21:48 - 2013-02-04 18:21 - 00001042 _____ () C:\Users\Desktop\ProjectX.jar - Verknüpfung.lnk 2014-01-24 21:48 - 2013-02-04 18:11 - 00208384 _____ (Imago) C:\Users\Desktop\ImagoMPEG-Muxer.exe 2014-01-24 21:48 - 2012-10-09 13:55 - 00001014 _____ () C:\Users\Desktop\kreawi Prüfungstrainer (Demo).lnk 2014-01-24 21:48 - 2012-05-05 20:14 - 00001380 _____ () C:\Users\Desktop\CopyTrans Control Center.lnk 2014-01-24 21:48 - 2011-09-22 10:05 - 00001172 _____ () C:\Users\Desktop\WavePad Sound Editor.lnk 2014-01-24 21:48 - 2011-09-01 07:08 - 00000977 _____ () C:\Users\Desktop\Juice.lnk 2014-01-24 21:48 - 2011-05-16 06:41 - 00006332 _____ () C:\Users\Desktop\Router_Setup.html 2014-01-24 21:48 - 2011-04-07 13:35 - 00001304 _____ () C:\Users\Desktop\Audio Converter.lnk 2014-01-24 21:48 - 2011-03-26 12:29 - 00001402 _____ () C:\Users\Desktop\YouTube to MP3 Converter.lnk 2014-01-24 21:48 - 2011-03-26 12:29 - 00001243 _____ () C:\Users\Desktop\DVDVideoSoft Studio.lnk 2014-01-24 21:48 - 2009-05-20 22:32 - 00000172 ____R () C:\Users\Desktop\Router Login.url 2014-01-24 21:42 - 2014-01-24 21:42 - 00000667 _____ () C:\Besitz übernehmen.reg 2014-01-24 21:36 - 2014-01-24 21:36 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe 2014-01-23 12:44 - 2014-01-23 12:44 - 00001781 _____ () C:\Users\Public\Desktop\f4.lnk 2014-01-23 12:43 - 2014-01-23 12:43 - 00006906 _____ () C:\Windows\SysWOW64\jupdate-1.6.0_07-b06.log 2014-01-23 12:42 - 2014-01-23 12:44 - 00000000 ____D () C:\Program Files (x86)\f4 2014-01-15 14:26 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 14:26 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 14:26 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 14:26 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 14:26 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 14:26 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 14:26 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 14:26 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 14:26 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-09 15:09 - 2014-01-09 18:12 - 00000000 ____D () C:\Users\****\Documents\Family Tree Maker 2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\IsolatedStorage 2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\Ancestry.com 2014-01-09 14:49 - 2014-01-09 14:49 - 00000000 ____D () C:\IExp1.tmp 2014-01-09 14:48 - 2014-01-09 14:49 - 00000000 ___HD () C:\Windows\msdownld.tmp 2014-01-09 14:48 - 2014-01-09 14:48 - 00002043 _____ () C:\Users\Public\Desktop\Family Tree Maker 2010 (DE).lnk 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Windows\RegisteredPackages 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft WSE 3.0 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\IExp0.tmp 2014-01-09 14:43 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\Family Tree Maker 2010 (DE) 2014-01-09 14:43 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\BCL Technologies 2014-01-09 14:34 - 2014-01-09 14:34 - 00000000 ____D () C:\Users\****\AppData\Roaming\YORAKO 2014-01-09 14:31 - 2014-01-09 14:31 - 00000000 ____D () C:\Program Files (x86)\Namenslexikon ==================== One Month Modified Files and Folders ======= 2014-02-05 10:44 - 2014-02-01 00:30 - 00018001 _____ () C:\Users\****\Downloads\FRST.txt 2014-02-05 10:44 - 2014-01-29 10:06 - 00000000 ____D () C:\FRST 2014-02-05 10:43 - 2010-04-05 13:46 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-05 10:14 - 2013-01-28 11:45 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-05 10:14 - 2013-01-28 11:45 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-05 10:14 - 2013-01-28 11:45 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-05 10:14 - 2013-01-28 11:45 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-05 09:18 - 2010-05-14 22:04 - 00000432 _____ () C:\Windows\BRWMARK.INI 2014-02-05 08:42 - 2009-09-08 05:37 - 01641959 _____ () C:\Windows\WindowsUpdate.log 2014-02-05 08:32 - 2010-05-14 22:01 - 00000418 _____ () C:\Windows\Brownie.ini 2014-02-05 08:31 - 2014-02-05 08:31 - 00113513 _____ () C:\Users\****\Downloads\S_20140205_083134_Kontoauszuege.zip 2014-02-04 17:25 - 2010-08-02 08:10 - 00000000 ____D () C:\Users\****\.gimp-2.6 2014-02-04 13:43 - 2010-04-05 13:37 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-04 13:43 - 2009-09-08 15:27 - 00754068 _____ () C:\Windows\system32\perfh007.dat 2014-02-04 13:43 - 2009-09-08 15:27 - 00171888 _____ () C:\Windows\system32\perfc007.dat 2014-02-04 13:43 - 2009-07-14 06:13 - 01760852 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-04 13:03 - 2011-09-22 18:24 - 00044773 _____ () C:\Windows\setupact.log 2014-02-04 11:47 - 2013-02-03 14:02 - 00000000 ____D () C:\Users\****\AppData\Roaming\FreeFileSync 2014-02-04 10:08 - 2014-02-04 10:08 - 00000000 ____D () C:\Users\****\Downloads\FRST-OlderVersion 2014-02-04 10:08 - 2014-01-29 09:23 - 02080256 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe 2014-02-04 09:58 - 2010-06-20 22:32 - 00000000 ____D () C:\Users\Admin 2014-02-04 08:09 - 2009-07-14 05:45 - 00017600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-04 08:09 - 2009-07-14 05:45 - 00017600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-04 08:01 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-04 05:55 - 2014-02-04 05:54 - 01331205 _____ () C:\Users\****\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_es.exe 2014-02-04 04:57 - 2010-06-06 09:45 - 00000000 ____D () C:\Program Files\Avast5 2014-02-04 04:56 - 2011-11-13 17:03 - 00098946 _____ () C:\Windows\PFRO.log 2014-02-04 04:53 - 2013-12-27 08:46 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-02-04 04:53 - 2013-10-23 08:24 - 00001836 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-02-04 04:53 - 2013-03-27 21:43 - 00001776 _____ () C:\Users\Public\Desktop\avast! Pro Antivirus.lnk 2014-02-04 04:53 - 2012-07-08 15:26 - 00003896 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-02-04 04:53 - 2011-04-25 10:51 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-02-04 04:53 - 2011-01-16 11:42 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-02-04 04:53 - 2010-06-29 12:27 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-02-04 04:53 - 2010-06-06 09:46 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2014-02-04 04:53 - 2010-06-06 09:46 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-02-03 21:58 - 2010-10-11 12:25 - 00000000 ___RD () C:\Users\****\Documents\hp 2014-02-03 16:22 - 2014-02-03 16:22 - 00000936 _____ () C:\Users\Public\Desktop\FreeFileSync.lnk 2014-02-03 16:14 - 2014-02-03 16:14 - 10389616 _____ () C:\Users\****\Downloads\FreeFileSync_6.2_Windows_Setup.exe 2014-02-03 16:12 - 2014-02-03 16:12 - 05329480 _____ (Secunia) C:\Users\****\Downloads\PSISetup_3.0.0.9016.exe 2014-02-03 16:05 - 2014-02-03 16:05 - 00707006 _____ () C:\Users\****\Downloads\delfix.exe 2014-02-02 10:20 - 2013-05-22 20:58 - 00000244 _____ () C:\Users\****\Downloads\defogger_enable.log 2014-02-02 04:17 - 2013-08-01 11:34 - 00000000 ____D () C:\pending 2014-01-31 23:23 - 2014-01-31 23:23 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-01-31 21:32 - 2014-01-31 21:32 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-01-30 18:11 - 2014-01-30 18:11 - 00000000 ____D () C:\Windows\system32\%LOCALAPPDATA% 2014-01-30 17:52 - 2013-03-10 18:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-01-30 17:52 - 2010-09-10 12:01 - 00000000 ____D () C:\Users\Admin\AppData\Local\Thunderbird 2014-01-30 17:18 - 2014-01-30 17:18 - 00000893 _____ () C:\Users\Admin\Desktop\JRT.txt 2014-01-30 17:06 - 2014-01-30 17:06 - 00000000 ____D () C:\Windows\ERUNT 2014-01-30 16:42 - 2014-01-30 16:14 - 00000000 ____D () C:\AdwCleaner 2014-01-30 16:42 - 2014-01-24 22:06 - 00000000 ____D () C:\ProgramData\Uniblue 2014-01-30 16:42 - 2011-11-30 17:44 - 00000000 ____D () C:\Users\****\AppData\Roaming\Babylon 2014-01-30 15:37 - 2014-01-30 15:37 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Malwarebytes 2014-01-30 15:34 - 2014-01-30 15:34 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-30 15:25 - 2014-01-30 15:25 - 01037068 _____ (Thisisu) C:\Users\****\Downloads\JRT.exe 2014-01-30 15:19 - 2014-01-30 15:19 - 01166132 _____ () C:\Users\****\Downloads\adwcleaner.exe 2014-01-30 15:18 - 2014-01-30 15:17 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\****\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-30 11:38 - 2010-03-30 15:51 - 00088479 _____ () C:\Windows\Run32A50.mch 2014-01-30 09:58 - 2010-03-31 16:16 - 00000131 _____ () C:\Windows\Star.ini 2014-01-30 09:58 - 2010-03-30 15:59 - 00000000 ____D () C:\Program Files (x86)\Transit XV 2014-01-30 09:58 - 2010-03-30 15:28 - 00000035 _____ () C:\Windows\A5W.INI 2014-01-30 09:58 - 2010-03-30 15:28 - 00000000 ____D () C:\Windows\A5W_DATA 2014-01-29 15:06 - 2011-10-28 20:16 - 00002035 _____ () C:\Users\****\AppData\Roaming\SAS7_000.DAT 2014-01-29 14:39 - 2010-10-13 14:13 - 00000000 ____D () C:\Users\Admin\AppData\Local\Adobe 2014-01-29 14:35 - 2014-01-29 14:35 - 00000000 ____D () C:\Users\****\AppData\Roaming\AVAST Software 2014-01-29 14:35 - 2011-06-21 08:31 - 00115976 _____ () C:\Users\****\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-29 14:35 - 2011-06-21 08:31 - 00001425 _____ () C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-29 14:35 - 2011-06-21 08:31 - 00000000 ___RD () C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-29 14:35 - 2011-06-21 08:31 - 00000000 ___RD () C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-01-29 14:35 - 2011-06-21 08:30 - 00000680 __RSH () C:\Users\****\ntuser.pol 2014-01-29 14:35 - 2011-06-21 08:30 - 00000000 ____D () C:\Users\**** 2014-01-29 14:30 - 2010-05-08 09:32 - 00000000 ____D () C:\Users\****\AppData\Local\Mozilla 2014-01-29 14:28 - 2014-01-29 14:28 - 00000000 ____D () C:\Users\****\AppData\Roaming\AVAST Software 2014-01-29 14:28 - 2013-05-09 09:07 - 00001425 _____ () C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-29 14:28 - 2010-04-06 16:56 - 00115976 _____ () C:\Users\****\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-29 13:24 - 2014-01-29 13:17 - 00462752 _____ () C:\Users\****\Desktop\Gmer.txt 2014-01-29 13:16 - 2014-01-29 13:16 - 00462761 _____ () C:\Users\Admin\Desktop\Gmer.log 2014-01-29 12:08 - 2014-01-29 12:08 - 00658328 _____ () C:\Users\Admin\Desktop\Gmer.txt 2014-01-29 11:07 - 2014-01-29 10:26 - 00029581 _____ () C:\Users\****\Desktop\Addition.txt 2014-01-29 10:55 - 2014-01-29 10:24 - 00034881 _____ () C:\Users\****\Desktop\FRST.txt 2014-01-29 09:33 - 2013-05-07 18:29 - 00000472 _____ () C:\Users\****\Desktop\defogger_disable.log 2014-01-29 09:29 - 2014-01-29 09:29 - 00370971 _____ () C:\Users\****\Desktop\gmer_2.1.19355.zip 2014-01-29 09:23 - 2014-01-29 09:23 - 00050477 _____ () C:\Users\****\Downloads\Defogger(1).exe 2014-01-29 07:14 - 2012-02-17 20:49 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-01-28 23:40 - 2014-01-28 23:39 - 00002210 _____ () C:\Windows\wininit.ini 2014-01-28 23:11 - 2012-02-17 20:49 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2014-01-28 23:10 - 2011-10-28 02:28 - 00000000 ____D () C:\Program Files (x86)\Power Translator 12 2014-01-28 22:54 - 2014-01-28 20:39 - 00359656 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\msicuu2.exe 2014-01-28 22:03 - 2013-06-11 12:23 - 00000000 ____D () C:\Program Files\WinRAR 2014-01-28 20:17 - 2013-11-17 21:07 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-28 20:17 - 2012-05-05 21:43 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-01-28 20:14 - 2011-11-13 15:37 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-01-28 20:11 - 2011-01-02 21:41 - 00000000 ____D () C:\ProgramData\Apple 2014-01-28 19:44 - 2009-08-26 06:16 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-01-28 19:44 - 2009-08-22 11:23 - 00000000 ____D () C:\Windows\ShellNew 2014-01-28 19:27 - 2009-08-26 06:16 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-01-28 19:27 - 2009-07-14 03:34 - 00000449 _____ () C:\Windows\win.ini 2014-01-28 18:12 - 2011-10-29 23:34 - 00000000 ____D () C:\Program Files (x86)\ABBYY FineReader 11 2014-01-28 14:23 - 2014-01-28 14:23 - 00283096 _____ (Mozilla) C:\Users\****\Downloads\Firefox Setup Stub 26.0.exe 2014-01-28 11:34 - 2009-08-22 10:33 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-01-28 11:32 - 2013-10-22 10:58 - 00000000 ____D () C:\ProgramData\SYSTRAN 2014-01-27 16:48 - 2014-01-27 16:46 - 90578216 _____ (AVAST Software) C:\Users\****\Downloads\avast_free_antivirus_setup.exe 2014-01-26 19:15 - 2010-08-05 10:27 - 00000000 ____D () C:\Users\****\AppData\Roaming\FileZilla 2014-01-26 13:57 - 2009-11-16 20:36 - 00115976 _____ () C:\Users\****\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-26 13:55 - 2009-07-14 05:45 - 00453088 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-26 13:48 - 2010-07-06 09:38 - 00115976 _____ () C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-26 12:50 - 2009-11-29 16:01 - 00000633 _____ () C:\Windows\ODBC.INI 2014-01-26 12:49 - 2010-07-06 09:38 - 00000000 ___RD () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-26 12:49 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system 2014-01-26 12:43 - 2014-01-26 12:43 - 00000000 ____D () C:\.jes 2014-01-25 10:46 - 2011-11-05 14:56 - 00000000 ____D () C:\Users\****\Downloads\F4 installationsordner 2014-01-25 10:19 - 2014-01-25 10:19 - 00002990 _____ () C:\Windows\System32\Tasks\{0D62AA74-773C-46F2-8D73-5A27790ADB3C} 2014-01-25 10:18 - 2014-01-25 10:18 - 00002990 _____ () C:\Windows\System32\Tasks\{B23F0548-59D2-45AD-ABA2-4A3298638B83} 2014-01-24 23:52 - 2013-10-22 13:47 - 00000000 ____D () C:\Users\****\AppData\Roaming\SYSTRAN 2014-01-24 23:52 - 2013-10-22 13:47 - 00000000 ____D () C:\Users\****\AppData\Local\SYSTRAN 2014-01-24 23:40 - 2014-01-24 23:40 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih(1).exe 2014-01-24 22:13 - 2010-07-06 09:39 - 00000000 ____D () C:\Users\Admin\AppData\Local\Mozilla 2014-01-24 22:11 - 2014-01-24 22:11 - 00000000 ____D () C:\ProgramData\Oracle 2014-01-24 22:10 - 2014-01-24 22:10 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-01-24 22:10 - 2014-01-24 22:10 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-01-24 22:10 - 2014-01-24 22:10 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-01-24 22:10 - 2014-01-24 22:10 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-01-24 22:10 - 2010-06-29 13:48 - 00000000 ____D () C:\Program Files (x86)\Java 2014-01-24 21:56 - 2014-01-24 21:56 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\AVAST Software 2014-01-24 21:56 - 2010-07-06 09:38 - 00001425 _____ () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-24 21:56 - 2010-07-06 09:38 - 00000000 ___RD () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-01-24 21:56 - 2010-07-06 09:37 - 00000000 ____D () C:\Users\Admin\AppData\Local\VirtualStore 2014-01-24 21:51 - 2014-01-24 21:48 - 00000000 ____D () C:\Users\Desktop\Dragon NaturallySpeaking 11 Home 2014-01-24 21:42 - 2014-01-24 21:42 - 00000667 _____ () C:\Besitz übernehmen.reg 2014-01-24 21:36 - 2014-01-24 21:36 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe 2014-01-24 04:39 - 2011-12-18 18:23 - 00000000 ____D () C:\Users\****\AppData\Local\.elfohilfe 2014-01-23 12:44 - 2014-01-23 12:44 - 00001781 _____ () C:\Users\Public\Desktop\f4.lnk 2014-01-23 12:44 - 2014-01-23 12:42 - 00000000 ____D () C:\Program Files (x86)\f4 2014-01-23 12:43 - 2014-01-23 12:43 - 00006906 _____ () C:\Windows\SysWOW64\jupdate-1.6.0_07-b06.log 2014-01-23 01:17 - 2010-08-04 21:37 - 00000000 ____D () C:\Users\****\AppData\Roaming\vlc 2014-01-23 01:12 - 2012-04-19 18:52 - 00000000 ____D () C:\Users\****\AppData\Roaming\dvdcss 2014-01-22 15:22 - 2013-03-27 19:49 - 00030863 _____ () C:\Users\****\Downloads\Feiertage_2009-2013_DE.ics 2014-01-21 15:22 - 2011-09-22 10:05 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software 2014-01-15 18:11 - 2013-07-27 10:08 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-15 18:07 - 2010-05-09 20:43 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-09 18:12 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\Documents\Family Tree Maker 2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\IsolatedStorage 2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\Ancestry.com 2014-01-09 14:49 - 2014-01-09 14:49 - 00000000 ____D () C:\IExp1.tmp 2014-01-09 14:49 - 2014-01-09 14:48 - 00000000 ___HD () C:\Windows\msdownld.tmp 2014-01-09 14:48 - 2014-01-09 14:48 - 00002043 _____ () C:\Users\Public\Desktop\Family Tree Maker 2010 (DE).lnk 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Windows\RegisteredPackages 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft WSE 3.0 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE 2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\IExp0.tmp 2014-01-09 14:48 - 2014-01-09 14:43 - 00000000 ____D () C:\Program Files (x86)\Family Tree Maker 2010 (DE) 2014-01-09 14:48 - 2014-01-09 14:43 - 00000000 ____D () C:\Program Files (x86)\BCL Technologies 2014-01-09 14:34 - 2014-01-09 14:34 - 00000000 ____D () C:\Users\****\AppData\Roaming\YORAKO 2014-01-09 14:31 - 2014-01-09 14:31 - 00000000 ____D () C:\Program Files (x86)\Namenslexikon Files to move or delete: ==================== C:\Users\Desktop\ImagoMPEG-Muxer.exe C:\Users\****\FineCount.reg Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\Quarantine.exe C:\Users\****\AppData\Local\Temp\DivXSetup.exe C:\Users\****\AppData\Local\Temp\DWPUpgradeInstaller.exe C:\Users\****\AppData\Local\Temp\ffmpeg13.exe C:\Users\****\AppData\Local\Temp\jna666123695494861687.dll C:\Users\****\AppData\Local\Temp\RSPUpgradeInstaller.exe C:\Users\****\AppData\Local\Temp\SkypeSetup.exe C:\Users\****\AppData\Local\Temp\SearchWithGoogleUpdate.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-29 02:44 ==================== End Of Log ============================ |
06.02.2014, 09:13 | #22 |
/// the machine /// TB-Ausbilder | Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle?? Macht Thunderbird immer noch solche Scherze?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
06.02.2014, 15:27 | #23 |
| Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle?? Nein, ist nur einmal vorgekommen. Thunderbird inklusive Mails wurde auch bereits nach Eset und Security Check wieder vollständig angezeigt. Seltsam ist nur, dass zwischendurch auch bei den Dateien im Profilordner die Mails der letzten Monate fehlten, und dann wieder da waren. Jetzt ist aber alles gesichert Delfix ausgeführt, alles ok. Secunia lokal ausgeführt, plötzlich war wieder 100% CPU-Auslastung (auch nach Neustart ohne laufende Prozesse) Von Delfix gesetzten Wiederherstellungspunkt genutzt, alles wieder ok. Secunia erzeugt beim Laden eine Fehlermeldung...siehe Grafik Gruß jo07 |
07.02.2014, 09:51 | #24 |
/// the machine /// TB-Ausbilder | Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle?? Deinstalliere Secunia, und teste mal den FileHippo UpdateChecker.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.02.2014, 11:34 | #25 |
| Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle?? FileHippo ist besser. Alles ok. Vielen Dank. Grußjo07 |
09.02.2014, 08:47 | #26 |
/// the machine /// TB-Ausbilder | Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle?? Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle?? |
avast, scan, security, smartpcfixer spybot, software, spybot, win |