Log-Analyse und Auswertung: Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.

Alt 03.02.2014, 10:41   #16
/// the machine
/// TB-Ausbilder

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Scanne den Stick mal mit deinem Antivirenprogramm und mit Malwarebytes.

Alt 03.02.2014, 15:02   #17
Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Hab ich gemacht,

Avast meldet keine Funde, konnte aber die Autorun.inf auf dem Stick nicht prüfen, da sie 'nicht zur Verfügung' stand. Sie ist aber dort vorhanden.
Malwarebytes findet keine Bedrohungen.

-Was ist mit Eset, das doch gar nicht zu Ende gescannt hat?

-Thunderbird hat heute beim Verfassen einer E-Mail plötzlich gemeldet, dass eine Datei angehängt wird, und als ich sofort das Programm schloss, kam die Meldung: Thunderbird ist dabei, eine Nachricht zu versenden (ich war weit weg vom Senden-Button)...


Alt 04.02.2014, 09:59   #18
/// the machine
/// TB-Ausbilder

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

ESET ist nur da um auf Reste zu scannen, und hat bis zum Abbruch nur inaktiven Müll gefunden. Poste bitte mal ein frisches FRST log.

Alt 04.02.2014, 10:25   #19
Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-02-2014
Ran by **** (ATTENTION: The logged in user is not administrator) on ****-PC on 04-02-2014 10:09:30
Running from C:\Users\****\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Acer Inc.) C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(AVAST Software) C:\Program Files\Avast5\AvastUI.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Hidfind.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation)
HKLM\...\Run: [ePower_DMC] - C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [492032 2009-07-21] (Acer Inc.)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8060960 2009-08-06] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [295936 2009-05-22] (Alps Electric Co., Ltd.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.)
HKLM-x32\...\Run: [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\Avast5\AvastUI.exe [3767096 2014-02-04] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Run: [Duden Korrektor SysTray] - C:\Program Files (x86)\Duden\Duden Korrektor\DKtray.exe [619216 2009-05-18] (Expert System S.p.A.)
HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18642024 2013-02-28] (Skype Technologies S.A.)
HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Run: [AutoStart-Manager 2006] - C:\Program Files (x86)\Tools&More\Autostart-Manager\AutoStart-Manager.exe [397312 2005-12-23] (Wirth New Media Sarl )
HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5230&r=27361109a116l0308z185i4751t287
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
URLSearchHook: HKCU - (No Name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No File
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_de
SearchScopes: HKCU - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} -  No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Avast5\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - No Name - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} -  No File
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\Avast5\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - No Name - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} -  No File
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} -  No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default
FF DefaultSearchEngine: benefind
FF SelectedSearchEngine: benefind
FF Homepage: hxxp://www.benefind.de
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.13.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8064.0206 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: nuance.com/DragonRIAPlugin - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\npDgnRia.dll (Nuance Communications Inc.)
FF Plugin HKCU: @citrixonline.com/appdetectorplugin - C:\Users\****\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF SearchPlugin: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default\searchplugins\100-search-engines.xml
FF SearchPlugin: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default\searchplugins\benefind.xml
FF SearchPlugin: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default\searchplugins\ecosia.xml
FF SearchPlugin: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default\searchplugins\scroogle-ssl-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: RequestPolicy - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default\Extensions\requestpolicy@requestpolicy.com.xpi [2013-01-29]
FF Extension: NoScript - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-01-28]
FF Extension: Google Privacy - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\psssww1k.default\Extensions\{ea61041c-1e22-4400-99a0-aea461e69d04}.xpi [2013-01-28]
FF HKLM-x32\...\Firefox\Extensions: [jid0-lmZNVK7a82O8cufhdfB9dUDfA2w@jetpack] - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\ffShim.xpi
FF Extension: No Name - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\ffShim.xpi [2012-07-13]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Avast5\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\Avast5\WebRep\FF [2011-04-25]

==================== Services (Whitelisted) =================

R2 ABBYY.Licensing.FineReader.Professional.11.0; C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe [819976 2011-09-22] (ABBYY)
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759072 2008-10-09] (ABBYY (BIT Software))
R2 avast! Antivirus; C:\Program Files\Avast5\AvastSvc.exe [50344 2014-02-04] (AVAST Software)
R2 ETService; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [24576 2009-08-12] ()
R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 MSSQL$MSSMLBIZ; c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
S2 NewServiceInstall1; C:\Program Files (x86)\SDL International\T2007_FL\TT\Lng\Dialogs1031.lng [11264 2007-04-23] ()
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [253952 2009-07-10] (Acer Incorporated)
S2 LEC TranslateDotNet Server; "C:\Program Files (x86)\Power Translator 12\LogoMedia TranslateDotNet Server.exe" [X]

==================== Drivers (Whitelisted) ====================

R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2013-10-23] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-04] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-23] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-23] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-04] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-04] (AVAST Software)
R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-04] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-27] ()
R3 bbcap; C:\Windows\System32\DRIVERS\bbcap.sys [4608 2010-12-23] (Windows (R) Codename Longhorn DDK provider)
S3 O2MDRDR; C:\Windows\system32\DRIVERS\o2mdx64.sys [63264 2009-05-07] (O2Micro )
S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] ()
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-02-04 10:08 - 2014-02-04 10:08 - 00000000 ____D () C:\Users\****\Downloads\FRST-OlderVersion
2014-02-04 05:54 - 2014-02-04 05:55 - 01331205 _____ () C:\Users\****\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_es.exe
2014-02-03 16:22 - 2014-02-03 16:22 - 00000936 _____ () C:\Users\Public\Desktop\FreeFileSync.lnk
2014-02-03 16:14 - 2014-02-03 16:14 - 10389616 _____ () C:\Users\****\Downloads\FreeFileSync_6.2_Windows_Setup.exe
2014-02-03 16:12 - 2014-02-03 16:12 - 05329480 _____ (Secunia) C:\Users\****\Downloads\PSISetup_3.0.0.9016.exe
2014-02-03 16:05 - 2014-02-03 16:05 - 00707006 _____ () C:\Users\****\Downloads\delfix.exe
2014-02-01 00:30 - 2014-02-04 10:09 - 00017504 _____ () C:\Users\****\Downloads\FRST.txt
2014-01-31 23:23 - 2014-01-31 23:23 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-01-31 21:32 - 2014-01-31 21:32 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-01-30 18:11 - 2014-01-30 18:11 - 00000000 ____D () C:\Windows\system32\%LOCALAPPDATA%
2014-01-30 17:18 - 2014-01-30 17:18 - 00000893 _____ () C:\Users\Admin\Desktop\JRT.txt
2014-01-30 17:06 - 2014-01-30 17:06 - 00000000 ____D () C:\Windows\ERUNT
2014-01-30 16:14 - 2014-01-30 16:42 - 00000000 ____D () C:\AdwCleaner
2014-01-30 15:37 - 2014-01-30 15:37 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Malwarebytes
2014-01-30 15:34 - 2014-01-30 15:34 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-30 15:34 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-30 15:25 - 2014-01-30 15:25 - 01037068 _____ (Thisisu) C:\Users\****\Downloads\JRT.exe
2014-01-30 15:19 - 2014-01-30 15:19 - 01166132 _____ () C:\Users\****\Downloads\adwcleaner.exe
2014-01-30 15:17 - 2014-01-30 15:18 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\****\Downloads\mbam-setup-
2014-01-29 14:28 - 2014-01-29 14:28 - 00000000 ____D () C:\Users\****\AppData\Roaming\AVAST Software
2014-01-29 13:17 - 2014-01-29 13:24 - 00462752 _____ () C:\Users\****\Desktop\Gmer.txt
2014-01-29 13:16 - 2014-01-29 13:16 - 00462761 _____ () C:\Users\Admin\Desktop\Gmer.log
2014-01-29 12:08 - 2014-01-29 12:08 - 00658328 _____ () C:\Users\Admin\Desktop\Gmer.txt
2014-01-29 10:26 - 2014-01-29 11:07 - 00029581 _____ () C:\Users\****\Desktop\Addition.txt
2014-01-29 10:24 - 2014-01-29 10:55 - 00034881 _____ () C:\Users\****\Desktop\FRST.txt
2014-01-29 10:06 - 2014-02-04 10:09 - 00000000 ____D () C:\FRST
2014-01-29 09:29 - 2014-01-29 09:29 - 00370971 _____ () C:\Users\****\Desktop\gmer_2.1.19355.zip
2014-01-29 09:23 - 2014-02-04 10:08 - 02080256 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe
2014-01-29 09:23 - 2014-01-29 09:23 - 00050477 _____ () C:\Users\****\Downloads\Defogger(1).exe
2014-01-28 23:39 - 2014-01-28 23:40 - 00002210 _____ () C:\Windows\wininit.ini
2014-01-28 20:39 - 2014-01-28 22:54 - 00359656 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\msicuu2.exe
2014-01-28 14:23 - 2014-01-28 14:23 - 00283096 _____ (Mozilla) C:\Users\****\Downloads\Firefox Setup Stub 26.0.exe
2014-01-27 16:46 - 2014-01-27 16:48 - 90578216 _____ (AVAST Software) C:\Users\****\Downloads\avast_free_antivirus_setup.exe
2014-01-26 12:43 - 2014-01-26 12:43 - 00000000 ____D () C:\.jes
2014-01-24 23:40 - 2014-01-24 23:40 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih(1).exe
2014-01-24 22:11 - 2014-01-24 22:11 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-24 22:10 - 2014-01-24 22:10 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-24 22:10 - 2014-01-24 22:10 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-24 22:10 - 2014-01-24 22:10 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-24 22:10 - 2014-01-24 22:10 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-24 22:06 - 2014-01-30 16:42 - 00000000 ____D () C:\ProgramData\Uniblue
2014-01-24 21:56 - 2014-01-24 21:56 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\AVAST Software
2014-01-24 21:48 - 2014-01-24 21:51 - 00000000 ____D () C:\Users\Desktop\Dragon NaturallySpeaking 11 Home
2014-01-24 21:48 - 2013-03-04 11:09 - 00005757 _____ () C:\Users\Desktop\ADMIN-Aktionen ab 28-01-13.doc - Verknüpfung.lnk
2014-01-24 21:48 - 2013-02-04 18:21 - 00001042 _____ () C:\Users\Desktop\ProjectX.jar - Verknüpfung.lnk
2014-01-24 21:48 - 2013-02-04 18:11 - 00208384 _____ (Imago) C:\Users\Desktop\ImagoMPEG-Muxer.exe
2014-01-24 21:48 - 2012-10-09 13:55 - 00001014 _____ () C:\Users\Desktop\kreawi Prüfungstrainer (Demo).lnk
2014-01-24 21:48 - 2012-05-05 20:14 - 00001380 _____ () C:\Users\Desktop\CopyTrans Control Center.lnk
2014-01-24 21:48 - 2011-09-22 10:05 - 00001172 _____ () C:\Users\Desktop\WavePad Sound Editor.lnk
2014-01-24 21:48 - 2011-09-01 07:08 - 00000977 _____ () C:\Users\Desktop\Juice.lnk
2014-01-24 21:48 - 2011-05-16 06:41 - 00006332 _____ () C:\Users\Desktop\Router_Setup.html
2014-01-24 21:48 - 2011-04-07 13:35 - 00001304 _____ () C:\Users\Desktop\Audio Converter.lnk
2014-01-24 21:48 - 2011-03-26 12:29 - 00001402 _____ () C:\Users\Desktop\YouTube to MP3 Converter.lnk
2014-01-24 21:48 - 2011-03-26 12:29 - 00001243 _____ () C:\Users\Desktop\DVDVideoSoft Studio.lnk
2014-01-24 21:48 - 2009-05-20 22:32 - 00000172 ____R () C:\Users\Desktop\Router Login.url
2014-01-24 21:42 - 2014-01-24 21:42 - 00000667 _____ () C:\Besitz übernehmen.reg
2014-01-24 21:36 - 2014-01-24 21:36 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-23 12:44 - 2014-01-23 12:44 - 00001781 _____ () C:\Users\Public\Desktop\f4.lnk
2014-01-23 12:43 - 2014-01-23 12:43 - 00006906 _____ () C:\Windows\SysWOW64\jupdate-1.6.0_07-b06.log
2014-01-23 12:42 - 2014-01-23 12:44 - 00000000 ____D () C:\Program Files (x86)\f4
2014-01-15 14:26 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 14:26 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 14:26 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 14:26 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 14:26 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 14:26 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 14:26 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 14:26 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 14:26 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-09 15:09 - 2014-01-09 18:12 - 00000000 ____D () C:\Users\****\Documents\Family Tree Maker
2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\IsolatedStorage
2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\Ancestry.com
2014-01-09 14:49 - 2014-01-09 14:49 - 00000000 ____D () C:\IExp1.tmp
2014-01-09 14:48 - 2014-01-09 14:49 - 00000000 ___HD () C:\Windows\msdownld.tmp
2014-01-09 14:48 - 2014-01-09 14:48 - 00002043 _____ () C:\Users\Public\Desktop\Family Tree Maker 2010 (DE).lnk
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Windows\RegisteredPackages
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft WSE 3.0
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\IExp0.tmp
2014-01-09 14:43 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\Family Tree Maker 2010 (DE)
2014-01-09 14:43 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\BCL Technologies
2014-01-09 14:34 - 2014-01-09 14:34 - 00000000 ____D () C:\Users\****\AppData\Roaming\YORAKO
2014-01-09 14:31 - 2014-01-09 14:31 - 00000000 ____D () C:\Program Files (x86)\Namenslexikon

==================== One Month Modified Files and Folders =======

2014-02-04 10:09 - 2014-02-01 00:30 - 00017504 _____ () C:\Users\****\Downloads\FRST.txt
2014-02-04 10:09 - 2014-01-29 10:06 - 00000000 ____D () C:\FRST
2014-02-04 10:08 - 2014-02-04 10:08 - 00000000 ____D () C:\Users\****\Downloads\FRST-OlderVersion
2014-02-04 10:08 - 2014-01-29 09:23 - 02080256 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe
2014-02-04 10:00 - 2010-04-05 13:37 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-04 09:58 - 2010-06-20 22:32 - 00000000 ____D () C:\Users\Admin
2014-02-04 09:43 - 2010-04-05 13:46 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-04 09:32 - 2009-09-08 05:37 - 01588905 _____ () C:\Windows\WindowsUpdate.log
2014-02-04 09:14 - 2013-01-28 11:45 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-04 08:09 - 2009-07-14 05:45 - 00017600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-04 08:09 - 2009-07-14 05:45 - 00017600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-04 08:01 - 2011-09-22 18:24 - 00043978 _____ () C:\Windows\setupact.log
2014-02-04 08:01 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-04 05:55 - 2014-02-04 05:54 - 01331205 _____ () C:\Users\****\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_es.exe
2014-02-04 04:57 - 2010-06-06 09:45 - 00000000 ____D () C:\Program Files\Avast5
2014-02-04 04:56 - 2011-11-13 17:03 - 00098946 _____ () C:\Windows\PFRO.log
2014-02-04 04:55 - 2010-05-14 22:01 - 00000404 _____ () C:\Windows\Brownie.ini
2014-02-04 04:53 - 2013-12-27 08:46 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-02-04 04:53 - 2013-10-23 08:24 - 00001836 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk
2014-02-04 04:53 - 2013-03-27 21:43 - 00001776 _____ () C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
2014-02-04 04:53 - 2011-04-25 10:51 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-02-04 04:53 - 2011-01-16 11:42 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-02-04 04:53 - 2010-06-29 12:27 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-02-04 04:53 - 2010-06-06 09:46 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-02-04 04:53 - 2010-06-06 09:46 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-02-03 21:58 - 2010-10-11 12:25 - 00000000 ___RD () C:\Users\****\Documents\hp
2014-02-03 21:00 - 2009-09-08 15:27 - 00754068 _____ () C:\Windows\system32\perfh007.dat
2014-02-03 21:00 - 2009-09-08 15:27 - 00171888 _____ () C:\Windows\system32\perfc007.dat
2014-02-03 21:00 - 2009-07-14 06:13 - 01760852 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-03 16:22 - 2014-02-03 16:22 - 00000936 _____ () C:\Users\Public\Desktop\FreeFileSync.lnk
2014-02-03 16:14 - 2014-02-03 16:14 - 10389616 _____ () C:\Users\****\Downloads\FreeFileSync_6.2_Windows_Setup.exe
2014-02-03 16:12 - 2014-02-03 16:12 - 05329480 _____ (Secunia) C:\Users\****\Downloads\PSISetup_3.0.0.9016.exe
2014-02-03 16:05 - 2014-02-03 16:05 - 00707006 _____ () C:\Users\****\Downloads\delfix.exe
2014-02-02 10:20 - 2013-05-22 20:58 - 00000244 _____ () C:\Users\****\Downloads\defogger_enable.log
2014-02-02 04:17 - 2013-08-01 11:34 - 00000000 ____D () C:\pending
2014-01-31 23:23 - 2014-01-31 23:23 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-01-31 21:32 - 2014-01-31 21:32 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-01-30 18:11 - 2014-01-30 18:11 - 00000000 ____D () C:\Windows\system32\%LOCALAPPDATA%
2014-01-30 17:52 - 2013-03-10 18:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-01-30 17:52 - 2010-09-10 12:01 - 00000000 ____D () C:\Users\Admin\AppData\Local\Thunderbird
2014-01-30 17:18 - 2014-01-30 17:18 - 00000893 _____ () C:\Users\Admin\Desktop\JRT.txt
2014-01-30 17:06 - 2014-01-30 17:06 - 00000000 ____D () C:\Windows\ERUNT
2014-01-30 16:42 - 2014-01-30 16:14 - 00000000 ____D () C:\AdwCleaner
2014-01-30 16:42 - 2014-01-24 22:06 - 00000000 ____D () C:\ProgramData\Uniblue
2014-01-30 16:42 - 2011-11-30 17:44 - 00000000 ____D () C:\Users\****\AppData\Roaming\Babylon
2014-01-30 15:37 - 2014-01-30 15:37 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Malwarebytes
2014-01-30 15:34 - 2014-01-30 15:34 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-30 15:25 - 2014-01-30 15:25 - 01037068 _____ (Thisisu) C:\Users\****\Downloads\JRT.exe
2014-01-30 15:19 - 2014-01-30 15:19 - 01166132 _____ () C:\Users\****\Downloads\adwcleaner.exe
2014-01-30 15:18 - 2014-01-30 15:17 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\****\Downloads\mbam-setup-
2014-01-30 11:38 - 2010-03-30 15:51 - 00088479 _____ () C:\Windows\Run32A50.mch
2014-01-30 09:58 - 2010-03-31 16:16 - 00000131 _____ () C:\Windows\Star.ini
2014-01-30 09:58 - 2010-03-30 15:59 - 00000000 ____D () C:\Program Files (x86)\Transit XV
2014-01-30 09:58 - 2010-03-30 15:28 - 00000035 _____ () C:\Windows\A5W.INI
2014-01-30 09:58 - 2010-03-30 15:28 - 00000000 ____D () C:\Windows\A5W_DATA
2014-01-29 15:06 - 2011-10-28 20:16 - 00002035 _____ () C:\Users\****\AppData\Roaming\SAS7_000.DAT
2014-01-29 14:39 - 2013-01-28 11:45 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-01-29 14:39 - 2013-01-28 11:45 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-29 14:39 - 2010-10-13 14:13 - 00000000 ____D () C:\Users\Admin\AppData\Local\Adobe
2014-01-29 14:35 - 2011-06-21 08:30 - 00000000 ____D () C:\Users\****
2014-01-29 14:28 - 2014-01-29 14:28 - 00000000 ____D () C:\Users\****\AppData\Roaming\AVAST Software
2014-01-29 13:24 - 2014-01-29 13:17 - 00462752 _____ () C:\Users\****\Desktop\Gmer.txt
2014-01-29 13:16 - 2014-01-29 13:16 - 00462761 _____ () C:\Users\Admin\Desktop\Gmer.log
2014-01-29 12:08 - 2014-01-29 12:08 - 00658328 _____ () C:\Users\Admin\Desktop\Gmer.txt
2014-01-29 11:07 - 2014-01-29 10:26 - 00029581 _____ () C:\Users\****\Desktop\Addition.txt
2014-01-29 10:55 - 2014-01-29 10:24 - 00034881 _____ () C:\Users\****\Desktop\FRST.txt
2014-01-29 09:33 - 2013-05-07 18:29 - 00000472 _____ () C:\Users\****\Desktop\defogger_disable.log
2014-01-29 09:29 - 2014-01-29 09:29 - 00370971 _____ () C:\Users\****\Desktop\gmer_2.1.19355.zip
2014-01-29 09:23 - 2014-01-29 09:23 - 00050477 _____ () C:\Users\****\Downloads\Defogger(1).exe
2014-01-29 07:14 - 2012-02-17 20:49 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-01-28 23:40 - 2014-01-28 23:39 - 00002210 _____ () C:\Windows\wininit.ini
2014-01-28 23:11 - 2012-02-17 20:49 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy
2014-01-28 23:10 - 2011-10-28 02:28 - 00000000 ____D () C:\Program Files (x86)\Power Translator 12
2014-01-28 22:54 - 2014-01-28 20:39 - 00359656 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\msicuu2.exe
2014-01-28 22:03 - 2013-06-11 12:23 - 00000000 ____D () C:\Program Files\WinRAR
2014-01-28 20:17 - 2013-11-17 21:07 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-28 20:17 - 2012-05-05 21:43 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-01-28 20:14 - 2011-11-13 15:37 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-01-28 20:11 - 2011-01-02 21:41 - 00000000 ____D () C:\ProgramData\Apple
2014-01-28 19:44 - 2009-08-26 06:16 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-01-28 19:44 - 2009-08-22 11:23 - 00000000 ____D () C:\Windows\ShellNew
2014-01-28 19:27 - 2009-08-26 06:16 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-01-28 19:27 - 2009-07-14 03:34 - 00000449 _____ () C:\Windows\win.ini
2014-01-28 18:12 - 2011-10-29 23:34 - 00000000 ____D () C:\Program Files (x86)\ABBYY FineReader 11
2014-01-28 14:23 - 2014-01-28 14:23 - 00283096 _____ (Mozilla) C:\Users\****\Downloads\Firefox Setup Stub 26.0.exe
2014-01-28 11:34 - 2009-08-22 10:33 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-01-28 11:32 - 2013-10-22 10:58 - 00000000 ____D () C:\ProgramData\SYSTRAN
2014-01-27 16:48 - 2014-01-27 16:46 - 90578216 _____ (AVAST Software) C:\Users\****\Downloads\avast_free_antivirus_setup.exe
2014-01-26 19:15 - 2010-08-05 10:27 - 00000000 ____D () C:\Users\****\AppData\Roaming\FileZilla
2014-01-26 13:57 - 2009-11-16 20:36 - 00115976 _____ () C:\Users\****\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-26 13:55 - 2009-07-14 05:45 - 00453088 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-01-26 13:48 - 2010-07-06 09:38 - 00115976 _____ () C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-26 12:50 - 2009-11-29 16:01 - 00000633 _____ () C:\Windows\ODBC.INI
2014-01-26 12:49 - 2010-07-06 09:38 - 00000000 ___RD () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-26 12:49 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system
2014-01-26 12:43 - 2014-01-26 12:43 - 00000000 ____D () C:\.jes
2014-01-25 10:46 - 2011-11-05 14:56 - 00000000 ____D () C:\Users\****\Downloads\F4 installationsordner
2014-01-24 23:52 - 2013-10-22 13:47 - 00000000 ____D () C:\Users\****\AppData\Roaming\SYSTRAN
2014-01-24 23:52 - 2013-10-22 13:47 - 00000000 ____D () C:\Users\****\AppData\Local\SYSTRAN
2014-01-24 23:40 - 2014-01-24 23:40 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih(1).exe
2014-01-24 22:13 - 2010-07-06 09:39 - 00000000 ____D () C:\Users\Admin\AppData\Local\Mozilla
2014-01-24 22:11 - 2014-01-24 22:11 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-24 22:10 - 2014-01-24 22:10 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-24 22:10 - 2014-01-24 22:10 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-24 22:10 - 2014-01-24 22:10 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-24 22:10 - 2014-01-24 22:10 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-24 22:10 - 2010-06-29 13:48 - 00000000 ____D () C:\Program Files (x86)\Java
2014-01-24 21:56 - 2014-01-24 21:56 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\AVAST Software
2014-01-24 21:56 - 2010-07-06 09:38 - 00001425 _____ () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-24 21:56 - 2010-07-06 09:38 - 00000000 ___RD () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-01-24 21:56 - 2010-07-06 09:37 - 00000000 ____D () C:\Users\Admin\AppData\Local\VirtualStore
2014-01-24 21:51 - 2014-01-24 21:48 - 00000000 ____D () C:\Users\Desktop\Dragon NaturallySpeaking 11 Home
2014-01-24 21:42 - 2014-01-24 21:42 - 00000667 _____ () C:\Besitz übernehmen.reg
2014-01-24 21:36 - 2014-01-24 21:36 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-24 06:51 - 2010-05-14 22:04 - 00000432 _____ () C:\Windows\BRWMARK.INI
2014-01-24 04:39 - 2011-12-18 18:23 - 00000000 ____D () C:\Users\****\AppData\Local\.elfohilfe
2014-01-23 12:44 - 2014-01-23 12:44 - 00001781 _____ () C:\Users\Public\Desktop\f4.lnk
2014-01-23 12:44 - 2014-01-23 12:42 - 00000000 ____D () C:\Program Files (x86)\f4
2014-01-23 12:43 - 2014-01-23 12:43 - 00006906 _____ () C:\Windows\SysWOW64\jupdate-1.6.0_07-b06.log
2014-01-23 01:17 - 2010-08-04 21:37 - 00000000 ____D () C:\Users\****\AppData\Roaming\vlc
2014-01-23 01:12 - 2012-04-19 18:52 - 00000000 ____D () C:\Users\****\AppData\Roaming\dvdcss
2014-01-22 15:22 - 2013-03-27 19:49 - 00030863 _____ () C:\Users\****\Downloads\Feiertage_2009-2013_DE.ics
2014-01-15 18:11 - 2013-07-27 10:08 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-15 18:07 - 2010-05-09 20:43 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-09 18:12 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\Documents\Family Tree Maker
2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\IsolatedStorage
2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\Ancestry.com
2014-01-09 14:49 - 2014-01-09 14:49 - 00000000 ____D () C:\IExp1.tmp
2014-01-09 14:49 - 2014-01-09 14:48 - 00000000 ___HD () C:\Windows\msdownld.tmp
2014-01-09 14:48 - 2014-01-09 14:48 - 00002043 _____ () C:\Users\Public\Desktop\Family Tree Maker 2010 (DE).lnk
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Windows\RegisteredPackages
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft WSE 3.0
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\IExp0.tmp
2014-01-09 14:48 - 2014-01-09 14:43 - 00000000 ____D () C:\Program Files (x86)\Family Tree Maker 2010 (DE)
2014-01-09 14:48 - 2014-01-09 14:43 - 00000000 ____D () C:\Program Files (x86)\BCL Technologies
2014-01-09 14:34 - 2014-01-09 14:34 - 00000000 ____D () C:\Users\****\AppData\Roaming\YORAKO
2014-01-09 14:31 - 2014-01-09 14:31 - 00000000 ____D () C:\Program Files (x86)\Namenslexikon

Files to move or delete:

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== End Of Log ============================
--- --- ---

Alt 05.02.2014, 08:20   #20
/// the machine
/// TB-Ausbilder

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Unsre Tools brauchen immer Adminrechte, bitte FRST mit ADminrechten scannen lassen.


Alt 05.02.2014, 10:50   #21
Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-02-2014
Ran by Admin (administrator) on ****-PC on 05-02-2014 10:44:07
Running from C:\Users\****\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AVAST Software) C:\Program Files\Avast5\AvastSvc.exe
(ABBYY) C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe
(ABBYY (BIT Software)) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe
() C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
(O2Micro International) C:\Windows\System32\drivers\o2flash.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Acer Inc.) C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(AVAST Software) C:\Program Files\Avast5\AvastUI.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Hidfind.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(brother) C:\Program Files (x86)\Brownie\BrStsW64.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation)
HKLM\...\Run: [ePower_DMC] - C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [492032 2009-07-21] (Acer Inc.)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8060960 2009-08-06] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [295936 2009-05-22] (Alps Electric Co., Ltd.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.)
HKLM-x32\...\Run: [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\Avast5\AvastUI.exe [3767096 2014-02-04] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Run: [Duden Korrektor SysTray] - C:\Program Files (x86)\Duden\Duden Korrektor\DKtray.exe [619216 2009-05-18] (Expert System S.p.A.)
HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18642024 2013-02-28] (Skype Technologies S.A.)
HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Run: [AutoStart-Manager 2006] - C:\Program Files (x86)\Tools&More\Autostart-Manager\AutoStart-Manager.exe [397312 2005-12-23] (Wirth New Media Sarl )
HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-739932340-378401146-3079080163-1003\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-739932340-378401146-3079080163-1005\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2068856 2011-10-12] (Flexera Software LLC.)
HKU\S-1-5-21-739932340-378401146-3079080163-1005\...\Run: [SpybotSD TeaTimer] - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-739932340-378401146-3079080163-1005\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-739932340-378401146-3079080163-1005\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5230&r=27361109a116l0308z185i4751t287
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5230&r=27361109a116l0308z185i4751t287
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&r=83
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} -  No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Avast5\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\Avast5\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - No Name - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} -  No File
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\Avast5\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} -  No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i7k1i9pr.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.13.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8064.0206 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: nuance.com/DragonRIAPlugin - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\npDgnRia.dll (Nuance Communications Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: FTdownloader V3.0 - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i7k1i9pr.default\Extensions\ftdownloader3@ftdownloader.com.xpi [2013-04-11]
FF HKLM-x32\...\Firefox\Extensions: [jid0-lmZNVK7a82O8cufhdfB9dUDfA2w@jetpack] - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\ffShim.xpi
FF Extension: No Name - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\ffShim.xpi [2012-07-13]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Avast5\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\Avast5\WebRep\FF [2011-04-25]

==================== Services (Whitelisted) =================

R2 ABBYY.Licensing.FineReader.Professional.11.0; C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe [819976 2011-09-22] (ABBYY)
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759072 2008-10-09] (ABBYY (BIT Software))
R2 avast! Antivirus; C:\Program Files\Avast5\AvastSvc.exe [50344 2014-02-04] (AVAST Software)
R2 ETService; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [24576 2009-08-12] ()
R2 MSSQL$MSSMLBIZ; c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
S2 NewServiceInstall1; C:\Program Files (x86)\SDL International\T2007_FL\TT\Lng\Dialogs1031.lng [11264 2007-04-23] ()
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [253952 2009-07-10] (Acer Incorporated)
S2 LEC TranslateDotNet Server; "C:\Program Files (x86)\Power Translator 12\LogoMedia TranslateDotNet Server.exe" [X]

==================== Drivers (Whitelisted) ====================

R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2013-10-23] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-04] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-23] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-23] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-04] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-04] (AVAST Software)
R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-04] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-27] ()
R3 bbcap; C:\Windows\System32\DRIVERS\bbcap.sys [4608 2010-12-23] (Windows (R) Codename Longhorn DDK provider)
S3 O2MDRDR; C:\Windows\system32\DRIVERS\o2mdx64.sys [63264 2009-05-07] (O2Micro )
S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] ()
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-02-05 08:31 - 2014-02-05 08:31 - 00113513 _____ () C:\Users\****\Downloads\S_20140205_083134_Kontoauszuege.zip
2014-02-04 10:08 - 2014-02-04 10:08 - 00000000 ____D () C:\Users\****\Downloads\FRST-OlderVersion
2014-02-04 05:54 - 2014-02-04 05:55 - 01331205 _____ () C:\Users\****\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_es.exe
2014-02-03 16:22 - 2014-02-03 16:22 - 00000936 _____ () C:\Users\Public\Desktop\FreeFileSync.lnk
2014-02-03 16:14 - 2014-02-03 16:14 - 10389616 _____ () C:\Users\****\Downloads\FreeFileSync_6.2_Windows_Setup.exe
2014-02-03 16:12 - 2014-02-03 16:12 - 05329480 _____ (Secunia) C:\Users\****\Downloads\PSISetup_3.0.0.9016.exe
2014-02-03 16:05 - 2014-02-03 16:05 - 00707006 _____ () C:\Users\****\Downloads\delfix.exe
2014-02-01 00:30 - 2014-02-05 10:44 - 00018001 _____ () C:\Users\****\Downloads\FRST.txt
2014-01-31 23:23 - 2014-01-31 23:23 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-01-31 21:32 - 2014-01-31 21:32 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-01-30 18:11 - 2014-01-30 18:11 - 00000000 ____D () C:\Windows\system32\%LOCALAPPDATA%
2014-01-30 17:18 - 2014-01-30 17:18 - 00000893 _____ () C:\Users\Admin\Desktop\JRT.txt
2014-01-30 17:06 - 2014-01-30 17:06 - 00000000 ____D () C:\Windows\ERUNT
2014-01-30 16:14 - 2014-01-30 16:42 - 00000000 ____D () C:\AdwCleaner
2014-01-30 15:37 - 2014-01-30 15:37 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Malwarebytes
2014-01-30 15:34 - 2014-01-30 15:34 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-30 15:34 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-30 15:25 - 2014-01-30 15:25 - 01037068 _____ (Thisisu) C:\Users\****\Downloads\JRT.exe
2014-01-30 15:19 - 2014-01-30 15:19 - 01166132 _____ () C:\Users\****\Downloads\adwcleaner.exe
2014-01-30 15:17 - 2014-01-30 15:18 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\****\Downloads\mbam-setup-
2014-01-29 14:35 - 2014-01-29 14:35 - 00000000 ____D () C:\Users\****\AppData\Roaming\AVAST Software
2014-01-29 14:28 - 2014-01-29 14:28 - 00000000 ____D () C:\Users\****\AppData\Roaming\AVAST Software
2014-01-29 13:17 - 2014-01-29 13:24 - 00462752 _____ () C:\Users\****\Desktop\Gmer.txt
2014-01-29 13:16 - 2014-01-29 13:16 - 00462761 _____ () C:\Users\Admin\Desktop\Gmer.log
2014-01-29 12:08 - 2014-01-29 12:08 - 00658328 _____ () C:\Users\Admin\Desktop\Gmer.txt
2014-01-29 10:26 - 2014-01-29 11:07 - 00029581 _____ () C:\Users\****\Desktop\Addition.txt
2014-01-29 10:24 - 2014-01-29 10:55 - 00034881 _____ () C:\Users\****\Desktop\FRST.txt
2014-01-29 10:06 - 2014-02-05 10:44 - 00000000 ____D () C:\FRST
2014-01-29 09:29 - 2014-01-29 09:29 - 00370971 _____ () C:\Users\****\Desktop\gmer_2.1.19355.zip
2014-01-29 09:23 - 2014-02-04 10:08 - 02080256 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe
2014-01-29 09:23 - 2014-01-29 09:23 - 00050477 _____ () C:\Users\****\Downloads\Defogger(1).exe
2014-01-28 23:39 - 2014-01-28 23:40 - 00002210 _____ () C:\Windows\wininit.ini
2014-01-28 20:39 - 2014-01-28 22:54 - 00359656 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\msicuu2.exe
2014-01-28 14:23 - 2014-01-28 14:23 - 00283096 _____ (Mozilla) C:\Users\****\Downloads\Firefox Setup Stub 26.0.exe
2014-01-27 16:46 - 2014-01-27 16:48 - 90578216 _____ (AVAST Software) C:\Users\****\Downloads\avast_free_antivirus_setup.exe
2014-01-26 12:43 - 2014-01-26 12:43 - 00000000 ____D () C:\.jes
2014-01-25 10:19 - 2014-01-25 10:19 - 00002990 _____ () C:\Windows\System32\Tasks\{0D62AA74-773C-46F2-8D73-5A27790ADB3C}
2014-01-25 10:18 - 2014-01-25 10:18 - 00002990 _____ () C:\Windows\System32\Tasks\{B23F0548-59D2-45AD-ABA2-4A3298638B83}
2014-01-24 23:40 - 2014-01-24 23:40 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih(1).exe
2014-01-24 22:11 - 2014-01-24 22:11 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-24 22:10 - 2014-01-24 22:10 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-24 22:10 - 2014-01-24 22:10 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-24 22:10 - 2014-01-24 22:10 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-24 22:10 - 2014-01-24 22:10 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-24 22:06 - 2014-01-30 16:42 - 00000000 ____D () C:\ProgramData\Uniblue
2014-01-24 21:56 - 2014-01-24 21:56 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\AVAST Software
2014-01-24 21:48 - 2014-01-24 21:51 - 00000000 ____D () C:\Users\Desktop\Dragon NaturallySpeaking 11 Home
2014-01-24 21:48 - 2013-03-04 11:09 - 00005757 _____ () C:\Users\Desktop\ADMIN-Aktionen ab 28-01-13.doc - Verknüpfung.lnk
2014-01-24 21:48 - 2013-02-04 18:21 - 00001042 _____ () C:\Users\Desktop\ProjectX.jar - Verknüpfung.lnk
2014-01-24 21:48 - 2013-02-04 18:11 - 00208384 _____ (Imago) C:\Users\Desktop\ImagoMPEG-Muxer.exe
2014-01-24 21:48 - 2012-10-09 13:55 - 00001014 _____ () C:\Users\Desktop\kreawi Prüfungstrainer (Demo).lnk
2014-01-24 21:48 - 2012-05-05 20:14 - 00001380 _____ () C:\Users\Desktop\CopyTrans Control Center.lnk
2014-01-24 21:48 - 2011-09-22 10:05 - 00001172 _____ () C:\Users\Desktop\WavePad Sound Editor.lnk
2014-01-24 21:48 - 2011-09-01 07:08 - 00000977 _____ () C:\Users\Desktop\Juice.lnk
2014-01-24 21:48 - 2011-05-16 06:41 - 00006332 _____ () C:\Users\Desktop\Router_Setup.html
2014-01-24 21:48 - 2011-04-07 13:35 - 00001304 _____ () C:\Users\Desktop\Audio Converter.lnk
2014-01-24 21:48 - 2011-03-26 12:29 - 00001402 _____ () C:\Users\Desktop\YouTube to MP3 Converter.lnk
2014-01-24 21:48 - 2011-03-26 12:29 - 00001243 _____ () C:\Users\Desktop\DVDVideoSoft Studio.lnk
2014-01-24 21:48 - 2009-05-20 22:32 - 00000172 ____R () C:\Users\Desktop\Router Login.url
2014-01-24 21:42 - 2014-01-24 21:42 - 00000667 _____ () C:\Besitz übernehmen.reg
2014-01-24 21:36 - 2014-01-24 21:36 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-23 12:44 - 2014-01-23 12:44 - 00001781 _____ () C:\Users\Public\Desktop\f4.lnk
2014-01-23 12:43 - 2014-01-23 12:43 - 00006906 _____ () C:\Windows\SysWOW64\jupdate-1.6.0_07-b06.log
2014-01-23 12:42 - 2014-01-23 12:44 - 00000000 ____D () C:\Program Files (x86)\f4
2014-01-15 14:26 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 14:26 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 14:26 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 14:26 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 14:26 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 14:26 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 14:26 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 14:26 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 14:26 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-09 15:09 - 2014-01-09 18:12 - 00000000 ____D () C:\Users\****\Documents\Family Tree Maker
2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\IsolatedStorage
2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\Ancestry.com
2014-01-09 14:49 - 2014-01-09 14:49 - 00000000 ____D () C:\IExp1.tmp
2014-01-09 14:48 - 2014-01-09 14:49 - 00000000 ___HD () C:\Windows\msdownld.tmp
2014-01-09 14:48 - 2014-01-09 14:48 - 00002043 _____ () C:\Users\Public\Desktop\Family Tree Maker 2010 (DE).lnk
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Windows\RegisteredPackages
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft WSE 3.0
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\IExp0.tmp
2014-01-09 14:43 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\Family Tree Maker 2010 (DE)
2014-01-09 14:43 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\BCL Technologies
2014-01-09 14:34 - 2014-01-09 14:34 - 00000000 ____D () C:\Users\****\AppData\Roaming\YORAKO
2014-01-09 14:31 - 2014-01-09 14:31 - 00000000 ____D () C:\Program Files (x86)\Namenslexikon

==================== One Month Modified Files and Folders =======

2014-02-05 10:44 - 2014-02-01 00:30 - 00018001 _____ () C:\Users\****\Downloads\FRST.txt
2014-02-05 10:44 - 2014-01-29 10:06 - 00000000 ____D () C:\FRST
2014-02-05 10:43 - 2010-04-05 13:46 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-05 10:14 - 2013-01-28 11:45 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-05 10:14 - 2013-01-28 11:45 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-05 10:14 - 2013-01-28 11:45 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-05 10:14 - 2013-01-28 11:45 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-05 09:18 - 2010-05-14 22:04 - 00000432 _____ () C:\Windows\BRWMARK.INI
2014-02-05 08:42 - 2009-09-08 05:37 - 01641959 _____ () C:\Windows\WindowsUpdate.log
2014-02-05 08:32 - 2010-05-14 22:01 - 00000418 _____ () C:\Windows\Brownie.ini
2014-02-05 08:31 - 2014-02-05 08:31 - 00113513 _____ () C:\Users\****\Downloads\S_20140205_083134_Kontoauszuege.zip
2014-02-04 17:25 - 2010-08-02 08:10 - 00000000 ____D () C:\Users\****\.gimp-2.6
2014-02-04 13:43 - 2010-04-05 13:37 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-04 13:43 - 2009-09-08 15:27 - 00754068 _____ () C:\Windows\system32\perfh007.dat
2014-02-04 13:43 - 2009-09-08 15:27 - 00171888 _____ () C:\Windows\system32\perfc007.dat
2014-02-04 13:43 - 2009-07-14 06:13 - 01760852 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-04 13:03 - 2011-09-22 18:24 - 00044773 _____ () C:\Windows\setupact.log
2014-02-04 11:47 - 2013-02-03 14:02 - 00000000 ____D () C:\Users\****\AppData\Roaming\FreeFileSync
2014-02-04 10:08 - 2014-02-04 10:08 - 00000000 ____D () C:\Users\****\Downloads\FRST-OlderVersion
2014-02-04 10:08 - 2014-01-29 09:23 - 02080256 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe
2014-02-04 09:58 - 2010-06-20 22:32 - 00000000 ____D () C:\Users\Admin
2014-02-04 08:09 - 2009-07-14 05:45 - 00017600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-04 08:09 - 2009-07-14 05:45 - 00017600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-04 08:01 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-04 05:55 - 2014-02-04 05:54 - 01331205 _____ () C:\Users\****\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_es.exe
2014-02-04 04:57 - 2010-06-06 09:45 - 00000000 ____D () C:\Program Files\Avast5
2014-02-04 04:56 - 2011-11-13 17:03 - 00098946 _____ () C:\Windows\PFRO.log
2014-02-04 04:53 - 2013-12-27 08:46 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-02-04 04:53 - 2013-10-23 08:24 - 00001836 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk
2014-02-04 04:53 - 2013-03-27 21:43 - 00001776 _____ () C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
2014-02-04 04:53 - 2012-07-08 15:26 - 00003896 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-02-04 04:53 - 2011-04-25 10:51 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-02-04 04:53 - 2011-01-16 11:42 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-02-04 04:53 - 2010-06-29 12:27 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-02-04 04:53 - 2010-06-06 09:46 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-02-04 04:53 - 2010-06-06 09:46 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-02-03 21:58 - 2010-10-11 12:25 - 00000000 ___RD () C:\Users\****\Documents\hp
2014-02-03 16:22 - 2014-02-03 16:22 - 00000936 _____ () C:\Users\Public\Desktop\FreeFileSync.lnk
2014-02-03 16:14 - 2014-02-03 16:14 - 10389616 _____ () C:\Users\****\Downloads\FreeFileSync_6.2_Windows_Setup.exe
2014-02-03 16:12 - 2014-02-03 16:12 - 05329480 _____ (Secunia) C:\Users\****\Downloads\PSISetup_3.0.0.9016.exe
2014-02-03 16:05 - 2014-02-03 16:05 - 00707006 _____ () C:\Users\****\Downloads\delfix.exe
2014-02-02 10:20 - 2013-05-22 20:58 - 00000244 _____ () C:\Users\****\Downloads\defogger_enable.log
2014-02-02 04:17 - 2013-08-01 11:34 - 00000000 ____D () C:\pending
2014-01-31 23:23 - 2014-01-31 23:23 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-01-31 21:32 - 2014-01-31 21:32 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-01-30 18:11 - 2014-01-30 18:11 - 00000000 ____D () C:\Windows\system32\%LOCALAPPDATA%
2014-01-30 17:52 - 2013-03-10 18:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-01-30 17:52 - 2010-09-10 12:01 - 00000000 ____D () C:\Users\Admin\AppData\Local\Thunderbird
2014-01-30 17:18 - 2014-01-30 17:18 - 00000893 _____ () C:\Users\Admin\Desktop\JRT.txt
2014-01-30 17:06 - 2014-01-30 17:06 - 00000000 ____D () C:\Windows\ERUNT
2014-01-30 16:42 - 2014-01-30 16:14 - 00000000 ____D () C:\AdwCleaner
2014-01-30 16:42 - 2014-01-24 22:06 - 00000000 ____D () C:\ProgramData\Uniblue
2014-01-30 16:42 - 2011-11-30 17:44 - 00000000 ____D () C:\Users\****\AppData\Roaming\Babylon
2014-01-30 15:37 - 2014-01-30 15:37 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Malwarebytes
2014-01-30 15:34 - 2014-01-30 15:34 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-01-30 15:34 - 2014-01-30 15:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-30 15:25 - 2014-01-30 15:25 - 01037068 _____ (Thisisu) C:\Users\****\Downloads\JRT.exe
2014-01-30 15:19 - 2014-01-30 15:19 - 01166132 _____ () C:\Users\****\Downloads\adwcleaner.exe
2014-01-30 15:18 - 2014-01-30 15:17 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\****\Downloads\mbam-setup-
2014-01-30 11:38 - 2010-03-30 15:51 - 00088479 _____ () C:\Windows\Run32A50.mch
2014-01-30 09:58 - 2010-03-31 16:16 - 00000131 _____ () C:\Windows\Star.ini
2014-01-30 09:58 - 2010-03-30 15:59 - 00000000 ____D () C:\Program Files (x86)\Transit XV
2014-01-30 09:58 - 2010-03-30 15:28 - 00000035 _____ () C:\Windows\A5W.INI
2014-01-30 09:58 - 2010-03-30 15:28 - 00000000 ____D () C:\Windows\A5W_DATA
2014-01-29 15:06 - 2011-10-28 20:16 - 00002035 _____ () C:\Users\****\AppData\Roaming\SAS7_000.DAT
2014-01-29 14:39 - 2010-10-13 14:13 - 00000000 ____D () C:\Users\Admin\AppData\Local\Adobe
2014-01-29 14:35 - 2014-01-29 14:35 - 00000000 ____D () C:\Users\****\AppData\Roaming\AVAST Software
2014-01-29 14:35 - 2011-06-21 08:31 - 00115976 _____ () C:\Users\****\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-29 14:35 - 2011-06-21 08:31 - 00001425 _____ () C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-29 14:35 - 2011-06-21 08:31 - 00000000 ___RD () C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-29 14:35 - 2011-06-21 08:31 - 00000000 ___RD () C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-01-29 14:35 - 2011-06-21 08:30 - 00000680 __RSH () C:\Users\****\ntuser.pol
2014-01-29 14:35 - 2011-06-21 08:30 - 00000000 ____D () C:\Users\****
2014-01-29 14:30 - 2010-05-08 09:32 - 00000000 ____D () C:\Users\****\AppData\Local\Mozilla
2014-01-29 14:28 - 2014-01-29 14:28 - 00000000 ____D () C:\Users\****\AppData\Roaming\AVAST Software
2014-01-29 14:28 - 2013-05-09 09:07 - 00001425 _____ () C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-29 14:28 - 2010-04-06 16:56 - 00115976 _____ () C:\Users\****\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-29 13:24 - 2014-01-29 13:17 - 00462752 _____ () C:\Users\****\Desktop\Gmer.txt
2014-01-29 13:16 - 2014-01-29 13:16 - 00462761 _____ () C:\Users\Admin\Desktop\Gmer.log
2014-01-29 12:08 - 2014-01-29 12:08 - 00658328 _____ () C:\Users\Admin\Desktop\Gmer.txt
2014-01-29 11:07 - 2014-01-29 10:26 - 00029581 _____ () C:\Users\****\Desktop\Addition.txt
2014-01-29 10:55 - 2014-01-29 10:24 - 00034881 _____ () C:\Users\****\Desktop\FRST.txt
2014-01-29 09:33 - 2013-05-07 18:29 - 00000472 _____ () C:\Users\****\Desktop\defogger_disable.log
2014-01-29 09:29 - 2014-01-29 09:29 - 00370971 _____ () C:\Users\****\Desktop\gmer_2.1.19355.zip
2014-01-29 09:23 - 2014-01-29 09:23 - 00050477 _____ () C:\Users\****\Downloads\Defogger(1).exe
2014-01-29 07:14 - 2012-02-17 20:49 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-01-28 23:40 - 2014-01-28 23:39 - 00002210 _____ () C:\Windows\wininit.ini
2014-01-28 23:11 - 2012-02-17 20:49 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy
2014-01-28 23:10 - 2011-10-28 02:28 - 00000000 ____D () C:\Program Files (x86)\Power Translator 12
2014-01-28 22:54 - 2014-01-28 20:39 - 00359656 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\msicuu2.exe
2014-01-28 22:03 - 2013-06-11 12:23 - 00000000 ____D () C:\Program Files\WinRAR
2014-01-28 20:17 - 2013-11-17 21:07 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-28 20:17 - 2012-05-05 21:43 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-01-28 20:14 - 2011-11-13 15:37 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-01-28 20:11 - 2011-01-02 21:41 - 00000000 ____D () C:\ProgramData\Apple
2014-01-28 19:44 - 2009-08-26 06:16 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-01-28 19:44 - 2009-08-22 11:23 - 00000000 ____D () C:\Windows\ShellNew
2014-01-28 19:27 - 2009-08-26 06:16 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-01-28 19:27 - 2009-07-14 03:34 - 00000449 _____ () C:\Windows\win.ini
2014-01-28 18:12 - 2011-10-29 23:34 - 00000000 ____D () C:\Program Files (x86)\ABBYY FineReader 11
2014-01-28 14:23 - 2014-01-28 14:23 - 00283096 _____ (Mozilla) C:\Users\****\Downloads\Firefox Setup Stub 26.0.exe
2014-01-28 11:34 - 2009-08-22 10:33 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-01-28 11:32 - 2013-10-22 10:58 - 00000000 ____D () C:\ProgramData\SYSTRAN
2014-01-27 16:48 - 2014-01-27 16:46 - 90578216 _____ (AVAST Software) C:\Users\****\Downloads\avast_free_antivirus_setup.exe
2014-01-26 19:15 - 2010-08-05 10:27 - 00000000 ____D () C:\Users\****\AppData\Roaming\FileZilla
2014-01-26 13:57 - 2009-11-16 20:36 - 00115976 _____ () C:\Users\****\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-26 13:55 - 2009-07-14 05:45 - 00453088 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-01-26 13:48 - 2010-07-06 09:38 - 00115976 _____ () C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-26 12:50 - 2009-11-29 16:01 - 00000633 _____ () C:\Windows\ODBC.INI
2014-01-26 12:49 - 2010-07-06 09:38 - 00000000 ___RD () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-26 12:49 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system
2014-01-26 12:43 - 2014-01-26 12:43 - 00000000 ____D () C:\.jes
2014-01-25 10:46 - 2011-11-05 14:56 - 00000000 ____D () C:\Users\****\Downloads\F4 installationsordner
2014-01-25 10:19 - 2014-01-25 10:19 - 00002990 _____ () C:\Windows\System32\Tasks\{0D62AA74-773C-46F2-8D73-5A27790ADB3C}
2014-01-25 10:18 - 2014-01-25 10:18 - 00002990 _____ () C:\Windows\System32\Tasks\{B23F0548-59D2-45AD-ABA2-4A3298638B83}
2014-01-24 23:52 - 2013-10-22 13:47 - 00000000 ____D () C:\Users\****\AppData\Roaming\SYSTRAN
2014-01-24 23:52 - 2013-10-22 13:47 - 00000000 ____D () C:\Users\****\AppData\Local\SYSTRAN
2014-01-24 23:40 - 2014-01-24 23:40 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih(1).exe
2014-01-24 22:13 - 2010-07-06 09:39 - 00000000 ____D () C:\Users\Admin\AppData\Local\Mozilla
2014-01-24 22:11 - 2014-01-24 22:11 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-24 22:10 - 2014-01-24 22:10 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-24 22:10 - 2014-01-24 22:10 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-24 22:10 - 2014-01-24 22:10 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-24 22:10 - 2014-01-24 22:10 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-24 22:10 - 2010-06-29 13:48 - 00000000 ____D () C:\Program Files (x86)\Java
2014-01-24 21:56 - 2014-01-24 21:56 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\AVAST Software
2014-01-24 21:56 - 2010-07-06 09:38 - 00001425 _____ () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-24 21:56 - 2010-07-06 09:38 - 00000000 ___RD () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-01-24 21:56 - 2010-07-06 09:37 - 00000000 ____D () C:\Users\Admin\AppData\Local\VirtualStore
2014-01-24 21:51 - 2014-01-24 21:48 - 00000000 ____D () C:\Users\Desktop\Dragon NaturallySpeaking 11 Home
2014-01-24 21:42 - 2014-01-24 21:42 - 00000667 _____ () C:\Besitz übernehmen.reg
2014-01-24 21:36 - 2014-01-24 21:36 - 01069512 _____ (Solid State Networks) C:\Users\****\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-24 04:39 - 2011-12-18 18:23 - 00000000 ____D () C:\Users\****\AppData\Local\.elfohilfe
2014-01-23 12:44 - 2014-01-23 12:44 - 00001781 _____ () C:\Users\Public\Desktop\f4.lnk
2014-01-23 12:44 - 2014-01-23 12:42 - 00000000 ____D () C:\Program Files (x86)\f4
2014-01-23 12:43 - 2014-01-23 12:43 - 00006906 _____ () C:\Windows\SysWOW64\jupdate-1.6.0_07-b06.log
2014-01-23 01:17 - 2010-08-04 21:37 - 00000000 ____D () C:\Users\****\AppData\Roaming\vlc
2014-01-23 01:12 - 2012-04-19 18:52 - 00000000 ____D () C:\Users\****\AppData\Roaming\dvdcss
2014-01-22 15:22 - 2013-03-27 19:49 - 00030863 _____ () C:\Users\****\Downloads\Feiertage_2009-2013_DE.ics
2014-01-21 15:22 - 2011-09-22 10:05 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-01-15 18:11 - 2013-07-27 10:08 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-15 18:07 - 2010-05-09 20:43 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-09 18:12 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\Documents\Family Tree Maker
2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\IsolatedStorage
2014-01-09 15:09 - 2014-01-09 15:09 - 00000000 ____D () C:\Users\****\AppData\Local\Ancestry.com
2014-01-09 14:49 - 2014-01-09 14:49 - 00000000 ____D () C:\IExp1.tmp
2014-01-09 14:49 - 2014-01-09 14:48 - 00000000 ___HD () C:\Windows\msdownld.tmp
2014-01-09 14:48 - 2014-01-09 14:48 - 00002043 _____ () C:\Users\Public\Desktop\Family Tree Maker 2010 (DE).lnk
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Windows\RegisteredPackages
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft WSE 3.0
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE
2014-01-09 14:48 - 2014-01-09 14:48 - 00000000 ____D () C:\IExp0.tmp
2014-01-09 14:48 - 2014-01-09 14:43 - 00000000 ____D () C:\Program Files (x86)\Family Tree Maker 2010 (DE)
2014-01-09 14:48 - 2014-01-09 14:43 - 00000000 ____D () C:\Program Files (x86)\BCL Technologies
2014-01-09 14:34 - 2014-01-09 14:34 - 00000000 ____D () C:\Users\****\AppData\Roaming\YORAKO
2014-01-09 14:31 - 2014-01-09 14:31 - 00000000 ____D () C:\Program Files (x86)\Namenslexikon

Files to move or delete:

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2014-01-29 02:44

==================== End Of Log ============================
--- --- ---

Alt 06.02.2014, 09:13   #22
/// the machine
/// TB-Ausbilder

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Macht Thunderbird immer noch solche Scherze?

Alt 06.02.2014, 15:27   #23
Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Nein, ist nur einmal vorgekommen. Thunderbird inklusive Mails wurde auch bereits nach Eset und Security Check wieder vollständig angezeigt. Seltsam ist nur, dass zwischendurch auch bei den Dateien im Profilordner die Mails der letzten Monate fehlten, und dann wieder da waren. Jetzt ist aber alles gesichert

Delfix ausgeführt, alles ok.
Secunia lokal ausgeführt, plötzlich war wieder 100% CPU-Auslastung (auch nach Neustart ohne laufende Prozesse)
Von Delfix gesetzten Wiederherstellungspunkt genutzt, alles wieder ok.
Secunia erzeugt beim Laden eine Fehlermeldung...siehe Grafik

Miniaturansicht angehängter Grafiken
Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??-secunia-meldung.jpg  

Alt 07.02.2014, 09:51   #24
/// the machine
/// TB-Ausbilder

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Deinstalliere Secunia, und teste mal den FileHippo UpdateChecker.

Proud Member of UNITE and ASAP since 2009

Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 08.02.2014, 11:34   #25
Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

FileHippo ist besser. Alles ok.
Vielen Dank.

Alt 09.02.2014, 08:47   #26
/// the machine
/// TB-Ausbilder

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

Smartpcfixer mit Spybot so gut es ging bereinigt.. bitte Restekontrolle??

