Hallo, ich habe seit langer Zeit ein Problem mit IE11 und vorher auch IE10. Habe schon alles versucht, was ich im Web so finden konnte. Nun seid Ihr meine letzte Hoffnung. Es lassen sich nicht immer Links öffnen, die beim FF keine Probleme machen. Hier ein Beispiel: Habe mal irgendeine Seite genommen. Von hier kann ich manche Links öffnen und manche nicht: hxxp://www.handy-faq.de/forum/samsung_galaxy_ace_3_forum/ Das ist natürlich nur ein Beispiel. Das Probl. habe ich auf fast allen Seiten mit mehreren Links. Beim Browsen bekommt man ein an die Klatsche. Ich hatte das Problem schon beim IE10 und gehofft, dass durch das Update auf IE11 das Problem gelöst ist. Ich habe, wie erwähnt alles versucht, was ich gefunden habe. Selbst FixIt. Habt Ihr ne`Idee?
![]() | #2 |
Hallo und
Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden?

Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520

Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten!
Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht!

Zudem bitte auch ein Log mit Farbars Tool machen:

Scan mit Farbar's Recovery Scan Tool (FRST)

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
![]() | #3 |
Hallo und danke für die Hilfe.
Ich habe das Problem ja schon lange. Ich habe in den letzten Wochen rout.- mäßig Malwarebytes laufen lassen. Der hatte nie was gefunden. Dann (von Euch empfohlen) auch mal Housecall. Auch der hatte nie was. Aber ich habe noch ein paar Logs vom AdwareCleaner von Ende 2013. Da hatte ich das Prob schon. Ich schicke jetzt mal, was ich habe:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 28/12/2013 um 15:14:10 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzername : Berthi - BERTHI-PC # Gestartet von : C:\Users\Berthi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CCX6R60V\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\ParetoLogic Ordner Gelöscht : C:\Users\Berthi\AppData\Roaming\DriverCure Ordner Gelöscht : C:\Users\Berthi\AppData\Roaming\ParetoLogic ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1 Schlüssel Gelöscht : HKCU\Software\ParetoLogic Schlüssel Gelöscht : HKLM\Software\ParetoLogic ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\5eet01au.default\prefs.js ] [ Datei : C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\p6zmczs1.Standard-Benutzer\prefs.js ] [ Datei : C:\Users\Eingechränkter Berth\AppData\Roaming\Mozilla\Firefox\Profiles\xpnmtxax.default\prefs.js ] ************************* AdwCleaner[R0].txt - [914 octets] - [13/10/2013 11:08:52] AdwCleaner[R10].txt - [2234 octets] - [28/12/2013 15:12:48] AdwCleaner[R1].txt - [973 octets] - [31/10/2013 16:28:28] AdwCleaner[R2].txt - [1032 octets] - [31/10/2013 18:20:38] AdwCleaner[R3].txt - [1093 octets] - [02/11/2013 14:29:39] AdwCleaner[R4].txt - [1154 octets] - [08/11/2013 14:47:07] AdwCleaner[R5].txt - [1214 octets] - [10/11/2013 11:54:40] AdwCleaner[R6].txt - [1274 octets] - [10/11/2013 14:10:57] AdwCleaner[R7].txt - [1450 octets] - [18/11/2013 10:02:43] AdwCleaner[R8].txt - [2115 octets] - [21/11/2013 19:26:07] AdwCleaner[R9].txt - [1958 octets] - [19/12/2013 14:24:29] AdwCleaner[S0].txt - [2176 octets] - [21/11/2013 19:27:43] AdwCleaner[S1].txt - [2019 octets] - [19/12/2013 14:26:04] AdwCleaner[S2].txt - [2160 octets] - [28/12/2013 15:14:10] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2220 octets] ########## --- --- --- AdwQuaratine: Code:
ATTFilter C:\Users\Berthi\AppData\Roaming\DriverCure\LogFile.txt->C:\AdwCleaner\Quarantine\C\Users\Berthi\AppData\Roaming\DriverCure\LogFile.txt.vir C:\Users\Berthi\AppData\Roaming\ParetoLogic\PC Health Advisor\Client.txt->C:\AdwCleaner\Quarantine\C\Users\Berthi\AppData\Roaming\ParetoLogic\PC Health Advisor\Client.txt.vir C:\Users\Berthi\AppData\Roaming\ParetoLogic\PC Health Advisor\Server.txt->C:\AdwCleaner\Quarantine\C\Users\Berthi\AppData\Roaming\ParetoLogic\PC Health Advisor\Server.txt.vir Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 28/12/2013 um 15:12:48 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzername : Berthi - BERTHI-PC # Gestartet von : C:\Users\Berthi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CCX6R60V\adwcleaner.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gefunden C:\ProgramData\ParetoLogic Ordner Gefunden C:\Users\Berthi\AppData\Roaming\DriverCure Ordner Gefunden C:\Users\Berthi\AppData\Roaming\ParetoLogic ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKCU\Software\ParetoLogic Schlüssel Gefunden : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager Schlüssel Gefunden : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1 Schlüssel Gefunden : HKLM\Software\ParetoLogic ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\5eet01au.default\prefs.js ] [ Datei : C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\p6zmczs1.Standard-Benutzer\prefs.js ] [ Datei : C:\Users\Eingechränkter Berth\AppData\Roaming\Mozilla\Firefox\Profiles\xpnmtxax.default\prefs.js ] ************************* AdwCleaner[R0].txt - [914 octets] - [13/10/2013 11:08:52] AdwCleaner[R10].txt - [1433 octets] - [28/12/2013 15:12:48] AdwCleaner[R1].txt - [973 octets] - [31/10/2013 16:28:28] AdwCleaner[R2].txt - [1032 octets] - [31/10/2013 18:20:38] AdwCleaner[R3].txt - [1093 octets] - [02/11/2013 14:29:39] AdwCleaner[R4].txt - [1154 octets] - [08/11/2013 14:47:07] AdwCleaner[R5].txt - [1214 octets] - [10/11/2013 11:54:40] AdwCleaner[R6].txt - [1274 octets] - [10/11/2013 14:10:57] AdwCleaner[R7].txt - [1450 octets] - [18/11/2013 10:02:43] AdwCleaner[R8].txt - [2115 octets] - [21/11/2013 19:26:07] AdwCleaner[R9].txt - [1958 octets] - [19/12/2013 14:24:29] AdwCleaner[S0].txt - [2176 octets] - [21/11/2013 19:27:43] AdwCleaner[S1].txt - [2019 octets] - [19/12/2013 14:26:04] ########## EOF - C:\AdwCleaner\AdwCleaner[R10].txt - [2153 octets] ########## AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 30/12/2013 um 17:23:04 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzername : Berthi - BERTHI-PC # Gestartet von : C:\Users\Berthi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OZFPRANY\adwcleaner.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\5eet01au.default\prefs.js ] [ Datei : C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\p6zmczs1.Standard-Benutzer\prefs.js ] [ Datei : C:\Users\Eingechränkter Berth\AppData\Roaming\Mozilla\Firefox\Profiles\xpnmtxax.default\prefs.js ] ************************* AdwCleaner[R0].txt - [914 octets] - [13/10/2013 11:08:52] AdwCleaner[R10].txt - [3256 octets] - [28/12/2013 15:12:48] AdwCleaner[R11].txt - [1876 octets] - [28/12/2013 15:28:12] AdwCleaner[R12].txt - [1937 octets] - [29/12/2013 11:47:56] AdwCleaner[R1].txt - [973 octets] - [31/10/2013 16:28:28] AdwCleaner[R2].txt - [1032 octets] - [31/10/2013 18:20:38] AdwCleaner[R3].txt - [1093 octets] - [02/11/2013 14:29:39] AdwCleaner[R4].txt - [1154 octets] - [08/11/2013 14:47:07] AdwCleaner[R5].txt - [1214 octets] - [10/11/2013 11:54:40] AdwCleaner[R6].txt - [1274 octets] - [10/11/2013 14:10:57] AdwCleaner[R7].txt - [1450 octets] - [18/11/2013 10:02:43] AdwCleaner[R8].txt - [2115 octets] - [21/11/2013 19:26:07] AdwCleaner[R9].txt - [4439 octets] - [19/12/2013 14:24:29] AdwCleaner[S0].txt - [2176 octets] - [21/11/2013 19:27:43] AdwCleaner[S1].txt - [4501 octets] - [19/12/2013 14:26:04] AdwCleaner[S2].txt - [2300 octets] - [28/12/2013 15:14:10] ########## EOF - C:\AdwCleaner\AdwCleaner[R10].txt - [4158 octets] ########## --- --- --- AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.015 - Bericht erstellt am 19/12/2013 um 14:24:29 # Updated 10/12/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzername : Berthi - BERTHI-PC # Gestartet von : C:\Users\Berthi\Downloads\adwcleaner(1).exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A86782D8-7B41-452F-A217-1854F72DBA54} Schlüssel Gefunden : HKCU\Software\Myfree Codec Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\updateWebConnect_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\updateWebConnect_RASMANCS ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\5eet01au.default\prefs.js ] [ Datei : C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\p6zmczs1.Standard-Benutzer\prefs.js ] [ Datei : C:\Users\Eingechränkter Berth\AppData\Roaming\Mozilla\Firefox\Profiles\xpnmtxax.default\prefs.js ] ************************* AdwCleaner[R0].txt - [914 octets] - [13/10/2013 11:08:52] AdwCleaner[R1].txt - [973 octets] - [31/10/2013 16:28:28] AdwCleaner[R2].txt - [1032 octets] - [31/10/2013 18:20:38] AdwCleaner[R3].txt - [1093 octets] - [02/11/2013 14:29:39] AdwCleaner[R4].txt - [1154 octets] - [08/11/2013 14:47:07] AdwCleaner[R5].txt - [1214 octets] - [10/11/2013 11:54:40] AdwCleaner[R6].txt - [1274 octets] - [10/11/2013 14:10:57] AdwCleaner[R7].txt - [1450 octets] - [18/11/2013 10:02:43] AdwCleaner[R8].txt - [2115 octets] - [21/11/2013 19:26:07] AdwCleaner[R9].txt - [1758 octets] - [19/12/2013 14:24:29] AdwCleaner[S0].txt - [2176 octets] - [21/11/2013 19:27:43] ########## EOF - C:\AdwCleaner\AdwCleaner[R9].txt - [1878 octets] ########## AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 29/12/2013 um 20:45:25 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzername : Berthi - BERTHI-PC # Gestartet von : C:\Users\Berthi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YDPVPOMX\adwcleaner.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A86782D8-7B41-452F-A217-1854F72DBA54} Schlüssel Gefunden : HKCU\Software\Myfree Codec Schlüssel Gefunden : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager Schlüssel Gefunden : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\updateWebConnect_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\updateWebConnect_RASMANCS ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\5eet01au.default\prefs.js ] [ Datei : C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\p6zmczs1.Standard-Benutzer\prefs.js ] [ Datei : C:\Users\Eingechränkter Berth\AppData\Roaming\Mozilla\Firefox\Profiles\xpnmtxax.default\prefs.js ] ************************* AdwCleaner[R0].txt - [914 octets] - [13/10/2013 11:08:52] AdwCleaner[R10].txt - [2234 octets] - [28/12/2013 15:12:48] AdwCleaner[R11].txt - [1876 octets] - [28/12/2013 15:28:12] AdwCleaner[R12].txt - [1937 octets] - [29/12/2013 11:47:56] AdwCleaner[R1].txt - [973 octets] - [31/10/2013 16:28:28] AdwCleaner[R2].txt - [1032 octets] - [31/10/2013 18:20:38] AdwCleaner[R3].txt - [1093 octets] - [02/11/2013 14:29:39] AdwCleaner[R4].txt - [1154 octets] - [08/11/2013 14:47:07] AdwCleaner[R5].txt - [1214 octets] - [10/11/2013 11:54:40] AdwCleaner[R6].txt - [1274 octets] - [10/11/2013 14:10:57] AdwCleaner[R7].txt - [1450 octets] - [18/11/2013 10:02:43] AdwCleaner[R8].txt - [2115 octets] - [21/11/2013 19:26:07] AdwCleaner[R9].txt - [4119 octets] - [19/12/2013 14:24:29] AdwCleaner[S0].txt - [2176 octets] - [21/11/2013 19:27:43] AdwCleaner[S1].txt - [2019 octets] - [19/12/2013 14:26:04] AdwCleaner[S2].txt - [2300 octets] - [28/12/2013 15:14:10] ########## EOF - C:\AdwCleaner\AdwCleaner[R9].txt - [4359 octets] ########## So jetzt FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-02-2014 02 Ran by Berthi (administrator) on BERTHI-PC on 09-02-2014 16:51:46 Running from C:\Users\Berthi\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\STacSV.exe (AMD) C:\Windows\system32\atieclxx.exe (Hewlett-Packard Company) C:\Windows\system32\Hpservice.exe (SurfRight B.V.) C:\Program Files\HitmanPro.Alert\hmpalert.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\aestsrv.exe (AVM Berlin) C:\Program Files\avmwlanstick\WlanNetService.exe (Teruten) C:\Windows\system32\FsUsbExService.Exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe ( ) C:\Windows\system32\lxdecoms.exe () C:\Program Files\SMINST\BLService.exe () C:\Program Files\CyberLink\Shared files\RichVideo.exe (Secunia) C:\Program Files\Secunia\PSI\PSIA.exe () C:\Program Files\Twonky\TwonkyServer\twonkyproxy.exe (PacketVideo) C:\Program Files\Twonky\TwonkyServer\twonkystarter.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe () C:\Program Files\Twonky\TwonkyServer\TwonkyServer.exe (Secunia) C:\Program Files\Secunia\PSI\sua.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe (BillP Studios) C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe () C:\Program Files\Rainlendar2\Rainlendar2.exe (Samsung) C:\Program Files\Samsung\Kies\Kies.exe (Samsung Electronics) C:\Program Files\Samsung\Kies\KiesAirMessage.exe (Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe (Dropbox, Inc.) C:\Users\Berthi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Renier Crause) C:\Program Files\PopTray\PopTray.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2299176 2011-10-14] (Synaptics Incorporated) HKLM\...\Run: [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [320056 2009-06-24] ( Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [SmartMenu] - C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [914224 2008-11-18] (Hewlett-Packard) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-08-04] (Advanced Micro Devices, Inc.) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray.exe [495708 2010-03-23] (IDT, Inc.) HKLM\...\Run: [WinPatrol] - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [404712 2013-01-04] (BillP Studios) HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-11-02] (AVAST Software) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-11-06] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [280576 2013-08-28] (Microsoft Corporation) HKU\S-1-5-21-4257371682-175156657-2477090228-1000\...\Run: [Rainlendar2] - C:\Program Files\Rainlendar2\Rainlendar2.exe [2598496 2013-03-10] () HKU\S-1-5-21-4257371682-175156657-2477090228-1000\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1564528 2013-11-06] (Samsung) HKU\S-1-5-21-4257371682-175156657-2477090228-1000\...\Run: [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe [578560 2013-10-30] (Samsung Electronics) HKU\S-1-5-21-4257371682-175156657-2477090228-1000\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-11-06] (Samsung) HKU\S-1-5-21-4257371682-175156657-2477090228-1000\...\Run: [9A87959D23204A7BF17AEC2C1CD713A48B5E9D92._service_run] - C:\Program Files\Google\Chrome\Application\chrome.exe [866632 2014-02-02] (Google Inc.) HKU\S-1-5-21-4257371682-175156657-2477090228-1000\...\MountPoints2: {6df45532-358e-11e3-9a49-00238b9e33ce} - F:\pushinst.exe HKU\S-1-5-21-4257371682-175156657-2477090228-1000\...\MountPoints2: {a5b42469-26a0-11e3-adae-00238b9e33ce} - F:\pushinst.exe Startup: C:\Users\Berthi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Berthi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Berthi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PopTray.lnk ShortcutTarget: PopTray.lnk -> C:\Program Files\PopTray\PopTray.exe (Renier Crause) ==================== Internet (Whitelisted) ==================== SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {186B55E9-E01B-4F88-8EEC-A6216AA2803D} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008 SearchScopes: HKCU - {186B55E9-E01B-4F88-8EEC-A6216AA2803D} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\vmo61pzk.Berthi FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: WOT - C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\vmo61pzk.Berthi\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-01-19] FF Extension: Adblock Plus - C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\vmo61pzk.Berthi\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-08] FF Extension: Tab Mix Plus - C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\vmo61pzk.Berthi\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2014-01-23] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-09-19] Chrome: ======= CHR Extension: (Google Docs) - C:\Users\Berthi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-05] CHR Extension: (Google Drive) - C:\Users\Berthi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-05] CHR Extension: (YouTube) - C:\Users\Berthi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-05] CHR Extension: (Google-Suche) - C:\Users\Berthi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-05] CHR Extension: (avast! Online Security) - C:\Users\Berthi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-01-09] CHR Extension: (Google Wallet) - C:\Users\Berthi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-05] CHR Extension: (Google Mail) - C:\Users\Berthi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-05] CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-11-02] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ========================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-11-02] (AVAST Software) R2 AVM WLAN Connection Service; C:\Program Files\avmwlanstick\WlanNetService.exe [364544 2008-02-25] (AVM Berlin) R2 hmpalertsvc; C:\Program Files\HitmanPro.Alert\hmpalert.exe [1830768 2013-09-28] (SurfRight B.V.) S2 lxdeCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdeserv.exe [99248 2007-05-29] (Lexmark International, Inc.) R2 lxde_device; C:\Windows\system32\lxdecoms.exe [598960 2007-05-29] ( ) R2 Recovery Service for Windows; C:\Program Files\SMINST\BLService.exe [365952 2008-12-17] () R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [241734 2008-09-15] () R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\STacSV.exe [229458 2010-03-23] (IDT, Inc.) R2 TwonkyProxy; C:\Program Files\Twonky\TwonkyServer\twonkyproxy.exe [885576 2013-05-23] () R2 TwonkyServer; C:\Program Files\Twonky\TwonkyServer\twonkystarter.exe [586568 2013-05-23] (PacketVideo) S2 TVCapSvc; "C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe" [X] S2 TVSched; "C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe" [X] ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [35656 2013-11-02] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [70384 2013-11-02] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [79720 2013-11-02] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2013-11-02] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [774392 2013-11-02] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [403440 2013-12-29] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2013-11-02] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [178304 2013-11-02] () R3 athr; C:\Windows\System32\DRIVERS\athr.sys [2957312 2012-06-20] (Qualcomm Atheros Communications, Inc.) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2007-11-07] (AVM Berlin) R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [37344 2013-10-30] () S3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [401920 2007-12-19] (AVM GmbH) R2 hmpalert; C:\Windows\system32\drivers\hmpalert.sys [14376 2013-09-28] () R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-07-03] (Secunia) S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [89256 2008-05-16] (MCCI Corporation) S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [15016 2008-05-16] (MCCI Corporation) S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [120744 2008-05-16] (MCCI Corporation) S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [114216 2008-05-16] (MCCI Corporation) S3 s0016nd5; C:\Windows\System32\DRIVERS\s0016nd5.sys [25512 2008-05-16] (MCCI Corporation) S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [110632 2008-05-16] (MCCI Corporation) S3 s0016unic; C:\Windows\System32\DRIVERS\s0016unic.sys [115752 2008-05-16] (MCCI Corporation) S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [182680 2013-08-21] (DEVGURU Co., LTD.(www.devguru.co.kr)) R1 ui11rdr; C:\Windows\System32\DRIVERS\ui11rdr.sys [144896 2011-11-21] (1&1 Internet AG) R2 {55662437-DA8C-40c0-AADA-2C816A897A49}; C:\Program Files\Hewlett-Packard\Media\DVD\000.fcl [87536 2008-11-28] (CyberLink Corp.) U4 eabfiltr; Code:
ATTFilter ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-09 16:51 - 2014-02-09 16:52 - 00015299 _____ () C:\Users\Berthi\Desktop\FRST.txt 2014-02-09 16:51 - 2014-02-09 16:51 - 00000000 ____D () C:\FRST 2014-02-09 16:49 - 2014-02-09 16:49 - 01138688 _____ (Farbar) C:\Users\Berthi\Desktop\FRST.exe 2014-02-08 15:43 - 2014-02-08 15:43 - 00084775 _____ () C:\Users\Berthi\Downloads\search 2014-02-08 11:13 - 2014-02-08 11:13 - 00000000 ____D () C:\Users\Berthi\Desktop\horizon 2014-02-08 11:07 - 2014-02-08 11:07 - 00000000 ____D () C:\Users\Eingechränkter Berth\AppData\Roaming\Windows Live Writer 2014-02-08 11:07 - 2014-02-08 11:07 - 00000000 ____D () C:\Users\Eingechränkter Berth\AppData\Local\Windows Live Writer 2014-02-08 11:04 - 2014-02-08 11:04 - 00000000 ____D () C:\Users\Eingechränkter Berth\AppData\Roaming\vlc 2014-02-08 10:52 - 2014-02-08 10:52 - 00002153 _____ () C:\Users\Eingechränkter Berth\Desktop\Google Chrome.lnk 2014-02-07 17:21 - 2014-02-09 16:20 - 00041956 _____ () C:\Windows\setupact.log 2014-02-07 17:21 - 2014-02-07 17:21 - 00000000 _____ () C:\Windows\setuperr.log 2014-01-31 18:08 - 2014-01-31 18:08 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\dvdcss 2014-01-31 15:56 - 2014-01-31 15:56 - 01166132 _____ () C:\Users\Berthi\Downloads\adwcleaner-3.018.exe 2014-01-31 15:00 - 2014-01-31 15:00 - 04721920 _____ (Piriform Ltd) C:\Users\Berthi\Downloads\ccsetup410.exe 2014-01-31 14:41 - 2014-01-31 14:42 - 01071000 _____ (Solid State Networks) C:\Users\Berthi\Downloads\install_flashplayer12x32_mssa_aaa_aih.exe 2014-01-31 09:03 - 2014-02-09 16:24 - 00000000 ____D () C:\ProgramData\TwonkyServer 2014-01-31 09:03 - 2014-01-31 09:03 - 00001078 _____ () C:\Users\Public\Desktop\Twonky Server.lnk 2014-01-31 09:03 - 2014-01-31 09:03 - 00000011 _____ () C:\ProgramData\.tv7 2014-01-31 09:03 - 2014-01-31 09:03 - 00000000 ____D () C:\Program Files\Twonky 2014-01-31 08:59 - 2014-01-31 09:00 - 05534360 _____ (PacketVideo) C:\Users\Berthi\Downloads\TwonkyServer-7.2.3.exe 2014-01-23 13:56 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-23 13:56 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-23 13:56 - 2013-11-26 10:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-01-23 13:56 - 2013-11-26 09:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-01-23 13:56 - 2013-11-26 09:52 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-01-23 13:56 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-23 13:56 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-23 13:56 - 2013-11-26 09:36 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-01-23 13:56 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-23 13:56 - 2013-11-26 09:29 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-01-23 13:56 - 2013-11-26 09:29 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-01-23 13:56 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-01-23 13:56 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-23 13:56 - 2013-11-26 09:13 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-01-23 13:56 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-23 13:56 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-23 13:56 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-01-23 13:56 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-23 13:56 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-19 14:24 - 2014-01-19 14:24 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-19 14:24 - 2014-01-19 14:24 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-19 14:24 - 2014-01-19 14:24 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-19 14:04 - 2014-01-31 15:01 - 00000000 ____D () C:\Windows\Panther 2014-01-19 13:28 - 2014-01-19 13:29 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\Mozilla 2014-01-19 13:28 - 2014-01-19 13:28 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-01-19 13:28 - 2014-01-19 13:28 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-01-19 12:57 - 2014-01-19 12:57 - 00283096 _____ (Mozilla) C:\Users\Berthi\Downloads\Firefox Setup Stub 26.0.exe 2014-01-15 15:40 - 2014-01-15 15:40 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-01-15 15:40 - 2014-01-15 15:39 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-15 15:40 - 2014-01-15 15:39 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-15 15:40 - 2014-01-15 15:39 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-15 15:40 - 2014-01-15 15:39 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-01-15 15:39 - 2014-01-15 15:39 - 00000000 ____D () C:\Program Files\Java 2014-01-15 15:35 - 2014-01-15 15:35 - 00921000 _____ (Oracle Corporation) C:\Users\Berthi\Downloads\jxpiinstall(1).exe 2014-01-15 14:21 - 2013-11-27 02:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 14:21 - 2013-11-27 02:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 14:21 - 2013-11-27 02:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 14:21 - 2013-11-27 02:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 14:21 - 2013-11-27 02:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 14:21 - 2013-11-27 02:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 14:21 - 2013-11-27 02:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 14:21 - 2013-11-26 12:11 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 14:21 - 2013-11-26 11:10 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-12 17:41 - 2014-01-12 17:41 - 00742622 _____ () C:\Users\Berthi\Downloads\PopTrayPlugins_beta6.exe ==================== One Month Modified Files and Folders ======= 2014-02-09 16:52 - 2014-02-09 16:51 - 00015299 _____ () C:\Users\Berthi\Desktop\FRST.txt 2014-02-09 16:51 - 2014-02-09 16:51 - 00000000 ____D () C:\FRST 2014-02-09 16:49 - 2014-02-09 16:49 - 01138688 _____ (Farbar) C:\Users\Berthi\Desktop\FRST.exe 2014-02-09 16:47 - 2013-09-01 13:05 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-09 16:37 - 2013-09-09 20:31 - 00000000 ____D () C:\Users\Berthi\Documents\Scribble Papers 2014-02-09 16:32 - 2013-08-27 22:13 - 00019456 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-09 16:32 - 2013-08-27 22:13 - 00019456 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-09 16:26 - 2013-08-27 22:58 - 01664115 _____ () C:\Windows\WindowsUpdate.log 2014-02-09 16:24 - 2014-01-31 09:03 - 00000000 ____D () C:\ProgramData\TwonkyServer 2014-02-09 16:23 - 2013-12-30 15:08 - 00000000 ___RD () C:\Users\Berthi\Dropbox 2014-02-09 16:23 - 2013-12-30 14:55 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\Dropbox 2014-02-09 16:22 - 2013-09-03 17:04 - 00000000 ____D () C:\Users\Berthi\.rainlendar2 2014-02-09 16:20 - 2014-02-07 17:21 - 00041956 _____ () C:\Windows\setupact.log 2014-02-09 16:20 - 2014-01-05 13:54 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-09 16:20 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-08 16:52 - 2013-08-28 21:33 - 00000000 ____D () C:\Users\Berthi\AppData\Local\FRITZ! 2014-02-08 16:06 - 2014-01-05 13:54 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-08 15:58 - 2013-09-08 10:28 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\TV-Browser 2014-02-08 15:43 - 2014-02-08 15:43 - 00084775 _____ () C:\Users\Berthi\Downloads\search 2014-02-08 11:13 - 2014-02-08 11:13 - 00000000 ____D () C:\Users\Berthi\Desktop\horizon 2014-02-08 11:07 - 2014-02-08 11:07 - 00000000 ____D () C:\Users\Eingechränkter Berth\AppData\Roaming\Windows Live Writer 2014-02-08 11:07 - 2014-02-08 11:07 - 00000000 ____D () C:\Users\Eingechränkter Berth\AppData\Local\Windows Live Writer 2014-02-08 11:04 - 2014-02-08 11:04 - 00000000 ____D () C:\Users\Eingechränkter Berth\AppData\Roaming\vlc 2014-02-08 10:56 - 2013-11-10 17:50 - 00000000 ____D () C:\Users\Eingechränkter Berth\AppData\Roaming\WinPatrol 2014-02-08 10:52 - 2014-02-08 10:52 - 00002153 _____ () C:\Users\Eingechränkter Berth\Desktop\Google Chrome.lnk 2014-02-08 10:51 - 2009-07-14 05:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-07 17:21 - 2014-02-07 17:21 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-07 12:57 - 2013-09-01 13:05 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-02-07 12:57 - 2013-09-01 13:05 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-02-07 12:57 - 2013-08-28 13:14 - 00000000 ____D () C:\Users\Berthi\AppData\Local\Adobe 2014-01-31 18:08 - 2014-01-31 18:08 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\dvdcss 2014-01-31 15:57 - 2013-10-13 11:08 - 00000000 ____D () C:\AdwCleaner 2014-01-31 15:56 - 2014-01-31 15:56 - 01166132 _____ () C:\Users\Berthi\Downloads\adwcleaner-3.018.exe 2014-01-31 15:46 - 2013-09-29 19:07 - 00480867 _____ () C:\Users\Berthi\AppData\Local\census.cache 2014-01-31 15:46 - 2013-09-29 19:06 - 00162420 _____ () C:\Users\Berthi\AppData\Local\ars.cache 2014-01-31 15:05 - 2013-09-03 14:59 - 00000000 ____D () C:\Program Files\SpywareBlaster 2014-01-31 15:01 - 2014-01-19 14:04 - 00000000 ____D () C:\Windows\Panther 2014-01-31 15:01 - 2013-08-28 09:51 - 00000000 ____D () C:\Program Files\CCleaner 2014-01-31 15:00 - 2014-01-31 15:00 - 04721920 _____ (Piriform Ltd) C:\Users\Berthi\Downloads\ccsetup410.exe 2014-01-31 14:42 - 2014-01-31 14:41 - 01071000 _____ (Solid State Networks) C:\Users\Berthi\Downloads\install_flashplayer12x32_mssa_aaa_aih.exe 2014-01-31 09:03 - 2014-01-31 09:03 - 00001078 _____ () C:\Users\Public\Desktop\Twonky Server.lnk 2014-01-31 09:03 - 2014-01-31 09:03 - 00000011 _____ () C:\ProgramData\.tv7 2014-01-31 09:03 - 2014-01-31 09:03 - 00000000 ____D () C:\Program Files\Twonky 2014-01-31 09:00 - 2014-01-31 08:59 - 05534360 _____ (PacketVideo) C:\Users\Berthi\Downloads\TwonkyServer-7.2.3.exe 2014-01-23 16:14 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Public\Libraries 2014-01-19 14:30 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\nl-NL 2014-01-19 14:30 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\it-IT 2014-01-19 14:30 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\fr-FR 2014-01-19 14:30 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-01-19 14:30 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\ar-SA 2014-01-19 14:24 - 2014-01-19 14:24 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-19 14:24 - 2014-01-19 14:24 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-19 14:24 - 2014-01-19 14:24 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-19 14:24 - 2014-01-19 14:24 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-19 13:29 - 2014-01-19 13:28 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\Mozilla 2014-01-19 13:28 - 2014-01-19 13:28 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-01-19 13:28 - 2014-01-19 13:28 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-01-19 12:57 - 2014-01-19 12:57 - 00283096 _____ (Mozilla) C:\Users\Berthi\Downloads\Firefox Setup Stub 26.0.exe 2014-01-19 11:33 - 2013-12-30 15:08 - 00000982 _____ () C:\Users\Berthi\Desktop\Dropbox.lnk 2014-01-19 11:33 - 2013-12-30 14:59 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-15 15:40 - 2014-01-15 15:40 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-01-15 15:40 - 2013-09-11 19:41 - 00000000 ____D () C:\ProgramData\Oracle 2014-01-15 15:39 - 2014-01-15 15:40 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-15 15:39 - 2014-01-15 15:40 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-15 15:39 - 2014-01-15 15:40 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-15 15:39 - 2014-01-15 15:40 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-01-15 15:39 - 2014-01-15 15:39 - 00000000 ____D () C:\Program Files\Java 2014-01-15 15:35 - 2014-01-15 15:35 - 00921000 _____ (Oracle Corporation) C:\Users\Berthi\Downloads\jxpiinstall(1).exe 2014-01-15 14:48 - 2009-07-14 05:33 - 00348704 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-15 14:34 - 2009-02-21 06:54 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-01-15 14:33 - 2013-08-28 02:31 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-15 14:29 - 2013-08-28 02:31 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-12 17:42 - 2013-08-28 20:12 - 00000000 ____D () C:\Program Files\PopTray 2014-01-12 17:41 - 2014-01-12 17:41 - 00742622 _____ () C:\Users\Berthi\Downloads\PopTrayPlugins_beta6.exe 2014-01-12 12:19 - 2013-09-06 21:45 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\Skype 2014-01-10 19:23 - 2013-09-01 12:20 - 00000000 ____D () C:\Users\Berthi\Documents\My Kindle Content ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-07 15:18 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 09-02-2014 02 Ran by Berthi at 2014-02-09 16:52:29 Running from C:\Users\Berthi\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== 1&1 Upload-Manager (Version: 2.0.676 - 1&1 Internet AG) 7-Zip 9.20 (Version: - ) ABBYY FineReader 6.0 Sprint (Version: 6.00.1990.41618 - ABBYY Software House) Activation Assistant for the 2007 Microsoft Office suites (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 12 ActiveX (Version: - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (Version: - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (Version: 11.0.06 - Adobe Systems Incorporated) Adobe Shockwave Player (Version: 11.0 - Adobe Systems, Inc.) Adobe Shockwave Player 12.0 (Version: - Adobe Systems, Inc.) Amazon Kindle (HKCU Version: - Amazon) AMD USB Filter Driver (Version: - Advanced Micro Devices, Inc.) Hidden Atheros Driver Installation Program (Version: 5.0 - Atheros) ATI Catalyst Install Manager (Version: 3.0.708.0 - ATI Technologies, Inc.) avast! Free Antivirus (Version: 9.0.2007 - Avast Software) AVM FRITZ!fax für FRITZ!Box (Version: - AVM Berlin) AVM FRITZ!WLAN (Version: - AVM Berlin) Catalyst Control Center - Branding (Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Core Implementation (Version: 2009.0804.2223.38385 - ATI) Hidden Catalyst Control Center Graphics Full Existing (Version: 2009.0804.2223.38385 - ATI) Hidden Catalyst Control Center Graphics Full New (Version: 2009.0804.2223.38385 - ATI) Hidden Catalyst Control Center Graphics Light (Version: 2009.0804.2223.38385 - ATI) Hidden Catalyst Control Center Graphics Previews Common (Version: 2009.0804.2223.38385 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (Version: 2009.0804.2223.38385 - ATI) Hidden Catalyst Control Center InstallProxy (Version: 2009.0122.1.43106 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (Version: 2009.0804.2223.38385 - ATI) Hidden CCC Help Chinese Standard (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Chinese Traditional (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Czech (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Danish (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Dutch (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help English (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Finnish (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help French (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help German (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Greek (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Hungarian (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Italian (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Japanese (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Korean (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Norwegian (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Polish (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Portuguese (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Russian (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Spanish (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Swedish (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Thai (Version: 2009.0804.2222.38385 - ATI) Hidden CCC Help Turkish (Version: 2009.0804.2222.38385 - ATI) Hidden ccc-core-static (Version: 2009.0804.2223.38385 - Ihr Firmenname) Hidden ccc-utility (Version: 2009.0804.2223.38385 - ATI) Hidden CCleaner (Version: 4.10 - Piriform) Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000 - Microsoft Corporation) D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKCU Version: 2.4.11 - Dropbox, Inc.) ESU for Microsoft Vista (Version: 1.0.0 - Hewlett-Packard) Folderico 4.0 RC12 (Version: 4.0 RC12 - Shedko ( www.softq.org )) Free Audio Converter version (Version: - DVDVideoSoft Ltd.) Google Chrome (Version: 32.0.1700.107 - Google Inc.) Google Update Helper (Version: - Google Inc.) Hidden HitmanPro.Alert (Version: - SurfRight B.V.) HP 3D DriveGuard (Version: - Hewlett-Packard) HP Common Access Service Library (Version: 2.00 E6 - Hewlett-Packard) Hidden HP Customer Experience Enhancements (Version: - Hewlett-Packard) HP MediaSmart DVD (Version: 2.1.2328 - Hewlett-Packard) HP MediaSmart DVD (Version: 2.1.2328 - Hewlett-Packard) Hidden HP MediaSmart Music/Photo/Video (Version: 2.1.2425 - Hewlett-Packard) HP MediaSmart Music/Photo/Video (Version: 2.1.2425 - Hewlett-Packard) Hidden HP MediaSmart SmartMenu (Version: 2.1.7 - Hewlett-Packard) HP MediaSmart Webcam (Version: 2.1.1124 - Hewlett-Packard) HP MediaSmart Webcam (Version: 2.1.1124 - Hewlett-Packard) Hidden HP Product Detection (Version: 11.15.0009 - HP) HP Quick Launch Buttons (Version: - Hewlett-Packard) HP Total Care Setup (Version: 1.1.2413.2876 - Hewlett-Packard Company) HP User Guides 0134 (Version: 1.01.0000 - Hewlett-Packard) HP Wireless Assistant (Version: - Hewlett-Packard) IDT Audio (Version: 1.0.6225.0 - IDT) Internet Explorer (Enable DEP) (Version: - ) IrfanView (remove only) (Version: 4.37 - Irfan Skiljan) Java 7 Update 51 (Version: 7.0.510 - Oracle) Java Auto Updater (Version: - Sun Microsystems, Inc.) Hidden JMicron Flash Media Controller Driver (Version: - JMicron Technology Corp.) Junk Mail filter update (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden LabelPrint (Version: 2.5.1118 - CyberLink Corp.) LabelPrint (Version: 2.5.1118 - CyberLink Corp.) Hidden Lexmark 4800 Series (Version: - Lexmark International, Inc.) Lexmark Fax-Lösungen (Version: - ) LightScribe System Software (Version: - LightScribe) Malwarebytes Anti-Malware Version (Version: - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint Viewer 2007 (German) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 26.0 (x86 de) (Version: 26.0 - Mozilla) Mozilla Maintenance Service (Version: 26.0 - Mozilla) MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (Version: 16.4.1108.0727 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (Version: 4.30.2100.0 - Microsoft Corporation) muvee Reveal (Version: - muvee Technologies Pte Ltd) MyDriveConnect (Version: - TomTom) Photo Common (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden PopTray 3.20 (Version: 3.20 - Renier Crause) PopTray Plug-ins (beta 6) (Version: (beta 6) - Renier Crause) Power2Go (Version: 6.0.2325 - CyberLink Corp.) Power2Go (Version: 6.0.2325 - CyberLink Corp.) Hidden PowerDirector (Version: 7.0.2317 - CyberLink Corp.) PowerDirector (Version: 7.0.2317 - CyberLink Corp.) Hidden QLBCASL (Version: - Hewlett-Packard) Hidden Rainlendar2 (remove only) (Version: - ) Realtek 8169 8168 8101E 8102E Ethernet Driver (Version: 1.00.0001 - Realtek) Revo Uninstaller 1.95 (Version: 1.95 - VS Revo Group) Samsung Kies (Version: - Samsung Electronics Co., Ltd.) Samsung Kies (Version: - Samsung Electronics Co., Ltd.) Hidden Samsung Story Album Viewer (Version: - Samsung Electronics Co., Ltd.) Samsung Story Album Viewer (Version: - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (Version: - SAMSUNG Electronics Co., Ltd.) Scribble Papers 2.7.1 (Version: - Jens Hoetger) Secunia PSI ( (Version: - Secunia) SIW 2013 Home Edition (Version: 2013.05.14 - Topala Software Solutions) Skat24sv (Version: - ) Skype™ 6.11 (Version: 6.11.102 - Skype Technologies S.A.) Sony PC Companion 2.10.181 (Version: 2.10.181 - Sony) SpywareBlaster 5.0 (Version: 5.0.0 - BrightFort LLC) swMSM (Version: - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (Version: - Synaptics Incorporated) TV-Browser 3.3.2 (Version: 3.3.2 - TV-Browser Team) Twonky Server (Version: - PacketVideo) Update for 2007 Microsoft Office System (KB967642) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (Version: - Microsoft) Visual Studio C++ 10.0 Runtime (Version: 10.0.0 - TomTom International B.V.) VLC media player 2.1.2 (Version: 2.1.2 - VideoLAN) Windows Live Communications Platform (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Essentials (Version: 16.4.3508.0205 - Microsoft Corporation) Windows Live Essentials (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Mail (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Photo Common (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live PIMT Platform (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Writer (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Writer Resources (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows-Treiberpaket - ENE (enecir) HIDClass (09/04/2008 (Version: 09/04/2008 - ENE) WinPatrol (Version: 26.1.2013.0 - BillP Studios) Code:
ATTFilter ==================== Restore Points ========================= 03-01-2014 20:28:31 Windows Update 09-01-2014 09:48:58 Windows Update 15-01-2014 13:21:28 Windows Update 15-01-2014 13:28:52 Windows Update 15-01-2014 14:39:21 Installed Java 7 Update 51 19-01-2014 10:35:59 Windows Update 19-01-2014 12:59:55 Windows Modules Installer 19-01-2014 13:22:42 Windows Modules Installer 19-01-2014 17:03:17 Installed Microsoft Fix it 50191 23-01-2014 12:54:33 Windows Update 31-01-2014 07:13:18 Windows Update 07-02-2014 11:50:41 Windows Update 08-02-2014 12:37:35 Installed Microsoft Fix it 50195 08-02-2014 12:44:51 Installed Microsoft Fix it 50195 ==================== Hosts content: ========================== 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {7AE12353-2628-452A-8332-5956975CA6DF} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {89240378-F0D9-412D-BBD3-487E612776C2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-01-05] (Google Inc.) Task: {A857EAB3-E1B4-4FBC-986F-DFE7B81770CF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-07] (Adobe Systems Incorporated) Task: {B92B2DD9-F6F5-4EF5-81CF-C4C56C944F7F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd) Task: {CAE8A63E-6E04-4934-BDC5-2D2A2D7D28C5} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-11-02] (AVAST Software) Task: {DC71F4F2-4A10-461E-8EAF-94FEFA5AF795} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-01-05] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-09-03 14:52 - 2012-12-10 02:46 - 00600868 ____N () C:\Program Files\BillP Studios\WinPatrol\sqlite3.dll 2013-11-02 14:13 - 2013-11-02 14:13 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2013-03-10 18:58 - 2013-03-10 18:58 - 02598496 _____ () C:\Program Files\Rainlendar2\Rainlendar2.exe 2012-05-16 20:01 - 2012-05-16 20:01 - 00140800 _____ () C:\Program Files\Rainlendar2\lua52.dll 2013-03-10 18:59 - 2013-03-10 18:59 - 00215648 _____ () C:\Program Files\Rainlendar2\plugins\iCalendarPlugin.dll 2012-06-17 14:22 - 2012-06-17 14:22 - 00012800 _____ () C:\Program Files\Rainlendar2\lfs.dll 2013-12-04 13:49 - 2013-12-04 13:49 - 00186368 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Commonc65c5a95#\cedcb35769c76a8e594cc133c28b2d0a\Kies.Common.DeviceServiceLib.Interface.ni.dll 2013-12-04 13:50 - 2013-12-04 13:50 - 14971904 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Theme\08808dd76f9ca2da6ddf5cf4d1c6cf0a\Kies.Theme.ni.dll 2013-12-04 13:48 - 2013-12-04 13:48 - 01842688 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.UI\4e84dcae55245a67ecf225a4c8eb6f01\Kies.UI.ni.dll 2013-12-04 13:48 - 2013-12-04 13:48 - 00081920 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.MVVM\de718a146963d74594e70aed8a9fed39\Kies.MVVM.ni.dll 2013-12-04 13:49 - 2013-12-04 13:49 - 00236032 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ASF_cSharpAPI\1f0027391b7dd5a510bbe91b94f9836d\ASF_cSharpAPI.ni.dll 2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\Berthi\AppData\Roaming\Dropbox\bin\libcef.dll 2003-09-20 12:36 - 2003-09-20 12:36 - 00040960 _____ () C:\Program Files\PopTray\plugins\NotifyKeyboardLights.dll 2003-10-09 19:17 - 2003-10-09 19:17 - 00287232 _____ () C:\Program Files\PopTray\plugins\ProtocolIMAP4.dll 2003-09-27 17:29 - 2003-09-27 17:29 - 00257536 _____ () C:\Program Files\PopTray\plugins\ProtocolPOP3SSL.dll 2009-07-07 10:56 - 2009-07-07 10:56 - 00016384 ____R () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll 2013-08-27 23:24 - 2013-08-27 23:24 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2014-01-19 13:28 - 2013-12-05 20:36 - 03559024 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2014-02-07 12:55 - 2014-02-07 12:57 - 16287624 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:5C321E34 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (02/09/2014 04:30:36 PM) (Source: Windows Backup) (User: ) Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "F:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)" Error: (02/09/2014 04:21:17 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/08/2014 03:47:14 PM) (Source: Application Hang) (User: ) Description: Programm PopTray.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 8ec Startzeit: 01cf24d5b5b20693 Endzeit: 20 Anwendungspfad: C:\Program Files\PopTray\PopTray.exe Berichts-ID: d94a774a-90cf-11e3-81e8-00238b9e33ce Error: (02/08/2014 02:54:48 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/08/2014 01:49:41 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/08/2014 00:54:03 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/08/2014 10:52:28 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/08/2014 10:52:19 AM) (Source: Windows Search Service) (User: ) Description: Der Index kann nicht initialisiert werden. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (02/08/2014 10:52:19 AM) (Source: Windows Search Service) (User: ) Description: Die Anwendung kann nicht initialisiert werden. Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (02/08/2014 10:52:19 AM) (Source: Windows Search Service) (User: ) Description: Das Gatherer-Objekt kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) System errors: ============= Error: (02/09/2014 04:20:35 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "TV Task Scheduler (TVTS)" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (02/09/2014 04:20:35 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "TV Background Capture Service (TVBCS)" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (02/09/2014 04:20:34 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "lxdeCATSCustConnectService" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (02/09/2014 04:20:34 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst lxdeCATSCustConnectService erreicht. Error: (02/09/2014 04:20:28 PM) (Source: atikmdag) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (02/08/2014 03:19:30 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (02/08/2014 03:19:30 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (02/08/2014 02:53:40 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "TV Task Scheduler (TVTS)" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (02/08/2014 02:53:40 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "TV Background Capture Service (TVBCS)" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (02/08/2014 02:53:39 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "lxdeCATSCustConnectService" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2014-02-08 16:56:12.034 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 16:34:04.876 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 16:19:53.941 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 15:34:44.999 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 14:46:58.409 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 14:25:36.086 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 14:16:09.762 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 14:01:38.067 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 13:06:53.429 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-08 12:33:13.252 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 48% Total physical RAM: 3069.84 MB Available physical RAM: 1578.42 MB Total Pagefile: 6137.96 MB Available Pagefile: 4340.43 MB Total Virtual: 2047.88 MB Available Virtual: 1897.54 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:287.45 GB) (Free:230.77 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (RECOVERY) (Fixed) (Total:10.64 GB) (Free:1.7 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 298 GB) (Disk ID: 068571AB) Partition 1: (Active) - (Size=287 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=11 GB) - (Type=07 NTFS) ==================== End Of Log ============================
Malwarebytes Anti-Rootkit (MBAR)

Downloade dir bitte
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
Hallo, habe ich gemacht. Der Scan hat ca. 20 Minuten gedauert und dann kam: "Scan finished: No Malware found!" Clean lässt sich nicht anklicken (Logisch) Soll ich mit EXIT rausgehen??? Hier mal die Log. Aber ist, glaube ich quarsch, dass ich die schicke, oder!?
ATTFilter Malwarebytes Anti-Rootkit BETA www.malwarebytes.org Database version: v2014.02.11.04 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 11.0.9600.16476 Berthi :: BERTHI-PC [administrator] 11.02.2014 10:59:28 mbar-log-2014-02-11 (10-59-28).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 237501 Time elapsed: 14 minute(s), 43 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end)
Adware/Junkware/Toolbars entfernen

(adwCleaner und JRT falls vorhanden neu runterladen!!)

1. Schritt: adwCleaner

Downloade Dir bitte
2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
![]() ![]() | ![]() IE 11 öffnet nicht alle Links Adware AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 28/12/2013 um 15:14:10 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzername : Berthi - BERTHI-PC # Gestartet von : C:\Users\Berthi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CCX6R60V\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\ParetoLogic Ordner Gelöscht : C:\Users\Berthi\AppData\Roaming\DriverCure Ordner Gelöscht : C:\Users\Berthi\AppData\Roaming\ParetoLogic ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1 Schlüssel Gelöscht : HKCU\Software\ParetoLogic Schlüssel Gelöscht : HKLM\Software\ParetoLogic ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\5eet01au.default\prefs.js ] [ Datei : C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\p6zmczs1.Standard-Benutzer\prefs.js ] [ Datei : C:\Users\Eingechränkter Berth\AppData\Roaming\Mozilla\Firefox\Profiles\xpnmtxax.default\prefs.js ] ************************* AdwCleaner[R0].txt - [914 octets] - [13/10/2013 11:08:52] AdwCleaner[R10].txt - [2234 octets] - [28/12/2013 15:12:48] AdwCleaner[R1].txt - [973 octets] - [31/10/2013 16:28:28] AdwCleaner[R2].txt - [1032 octets] - [31/10/2013 18:20:38] AdwCleaner[R3].txt - [1093 octets] - [02/11/2013 14:29:39] AdwCleaner[R4].txt - [1154 octets] - [08/11/2013 14:47:07] AdwCleaner[R5].txt - [1214 octets] - [10/11/2013 11:54:40] AdwCleaner[R6].txt - [1274 octets] - [10/11/2013 14:10:57] AdwCleaner[R7].txt - [1450 octets] - [18/11/2013 10:02:43] AdwCleaner[R8].txt - [2115 octets] - [21/11/2013 19:26:07] AdwCleaner[R9].txt - [1958 octets] - [19/12/2013 14:24:29] AdwCleaner[S0].txt - [2176 octets] - [21/11/2013 19:27:43] AdwCleaner[S1].txt - [2019 octets] - [19/12/2013 14:26:04] AdwCleaner[S2].txt - [2160 octets] - [28/12/2013 15:14:10] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2220 octets] ########## AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.018 - Bericht erstellt am 11/02/2014 um 13:30:53 # Updated 28/01/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzername : Berthi - BERTHI-PC # Gestartet von : C:\Users\Berthi\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v27.0 (de) [ Datei : C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\vmo61pzk.Berthi\prefs.js ] [ Datei : C:\Users\Eingechränkter Berth\AppData\Roaming\Mozilla\Firefox\Profiles\xpnmtxax.default\prefs.js ] -\\ Google Chrome v32.0.1700.107 [ Datei : C:\Users\Berthi\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [914 octets] - [13/10/2013 11:08:52] AdwCleaner[R10].txt - [4239 octets] - [28/12/2013 15:12:48] AdwCleaner[R11].txt - [3939 octets] - [28/12/2013 15:28:12] AdwCleaner[R12].txt - [4000 octets] - [29/12/2013 11:47:56] AdwCleaner[R13].txt - [2192 octets] - [19/01/2014 12:15:51] AdwCleaner[R14].txt - [2176 octets] - [31/01/2014 15:57:09] AdwCleaner[R15].txt - [2129 octets] - [11/02/2014 13:29:44] AdwCleaner[R1].txt - [973 octets] - [31/10/2013 16:28:28] AdwCleaner[R2].txt - [1032 octets] - [31/10/2013 18:20:38] AdwCleaner[R3].txt - [1093 octets] - [02/11/2013 14:29:39] AdwCleaner[R4].txt - [1154 octets] - [08/11/2013 14:47:07] AdwCleaner[R5].txt - [1214 octets] - [10/11/2013 11:54:40] AdwCleaner[R6].txt - [1274 octets] - [10/11/2013 14:10:57] AdwCleaner[R7].txt - [1450 octets] - [18/11/2013 10:02:43] AdwCleaner[R8].txt - [2115 octets] - [21/11/2013 19:26:07] AdwCleaner[R9].txt - [4439 octets] - [19/12/2013 14:24:29] AdwCleaner[S0].txt - [2176 octets] - [21/11/2013 19:27:43] AdwCleaner[S1].txt - [4501 octets] - [19/12/2013 14:26:04] AdwCleaner[S2].txt - [4289 octets] - [28/12/2013 15:14:10] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [4349 octets] ########## JRT (BEI REGISTRY STAND: FEHLER! ZUGRIFF VERWEIGERT) Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.1 (02.04.2014:1) OS: Windows 7 Home Premium x86 Ran by Berthi on 11.02.2014 at 14:15:42,95 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 11.02.2014 at 14:22:15,77 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-02-2014 01 Ran by Berthi (administrator) on BERTHI-PC on 11-02-2014 14:32:04 Running from C:\Users\Berthi\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\STacSV.exe (Hewlett-Packard Company) C:\Windows\system32\Hpservice.exe (SurfRight B.V.) C:\Program Files\HitmanPro.Alert\hmpalert.exe (AMD) C:\Windows\system32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\aestsrv.exe (AVM Berlin) C:\Program Files\avmwlanstick\WlanNetService.exe (Teruten) C:\Windows\system32\FsUsbExService.Exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe ( ) C:\Windows\system32\lxdecoms.exe () C:\Program Files\SMINST\BLService.exe () C:\Program Files\CyberLink\Shared files\RichVideo.exe (Secunia) C:\Program Files\Secunia\PSI\PSIA.exe () C:\Program Files\Twonky\TwonkyServer\twonkyproxy.exe (PacketVideo) C:\Program Files\Twonky\TwonkyServer\twonkystarter.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE () C:\Program Files\Twonky\TwonkyServer\TwonkyServer.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (BillP Studios) C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe () C:\Program Files\Rainlendar2\Rainlendar2.exe (Samsung) C:\Program Files\Samsung\Kies\Kies.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Samsung Electronics) C:\Program Files\Samsung\Kies\KiesAirMessage.exe (Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe (Dropbox, Inc.) C:\Users\Berthi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Renier Crause) C:\Program Files\PopTray\PopTray.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2299176 2011-10-14] (Synaptics Incorporated) HKLM\...\Run: [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [320056 2009-06-24] ( Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [SmartMenu] - C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [914224 2008-11-18] (Hewlett-Packard) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-08-04] (Advanced Micro Devices, Inc.) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray.exe [495708 2010-03-23] (IDT, Inc.) HKLM\...\Run: [WinPatrol] - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [404712 2013-01-04] (BillP Studios) HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-11-02] (AVAST Software) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-11-06] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [280576 2013-08-28] (Microsoft Corporation) HKU\S-1-5-21-4257371682-175156657-2477090228-1000\...\Run: [Rainlendar2] - C:\Program Files\Rainlendar2\Rainlendar2.exe [2598496 2013-03-10] () HKU\S-1-5-21-4257371682-175156657-2477090228-1000\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1564528 2013-11-06] (Samsung) HKU\S-1-5-21-4257371682-175156657-2477090228-1000\...\Run: [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe [578560 2013-10-30] (Samsung Electronics) HKU\S-1-5-21-4257371682-175156657-2477090228-1000\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-11-06] (Samsung) HKU\S-1-5-21-4257371682-175156657-2477090228-1000\...\Run: [9A87959D23204A7BF17AEC2C1CD713A48B5E9D92._service_run] - C:\Program Files\Google\Chrome\Application\chrome.exe [866632 2014-02-02] (Google Inc.) HKU\S-1-5-21-4257371682-175156657-2477090228-1000\...\MountPoints2: {6df45532-358e-11e3-9a49-00238b9e33ce} - F:\pushinst.exe HKU\S-1-5-21-4257371682-175156657-2477090228-1000\...\MountPoints2: {a5b42469-26a0-11e3-adae-00238b9e33ce} - F:\pushinst.exe Startup: C:\Users\Berthi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Berthi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Berthi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PopTray.lnk ShortcutTarget: PopTray.lnk -> C:\Program Files\PopTray\PopTray.exe (Renier Crause) ==================== Internet (Whitelisted) ==================== SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {186B55E9-E01B-4F88-8EEC-A6216AA2803D} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008 SearchScopes: HKCU - {186B55E9-E01B-4F88-8EEC-A6216AA2803D} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\vmo61pzk.Berthi FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: WOT - C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\vmo61pzk.Berthi\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-01-19] FF Extension: Adblock Plus - C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\vmo61pzk.Berthi\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-08] FF Extension: Tab Mix Plus - C:\Users\Berthi\AppData\Roaming\Mozilla\Firefox\Profiles\vmo61pzk.Berthi\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2014-01-23] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-09-19] Chrome: ======= CHR Extension: (Google Docs) - C:\Users\Berthi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-05] CHR Extension: (Google Drive) - C:\Users\Berthi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-05] CHR Extension: (YouTube) - C:\Users\Berthi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-05] CHR Extension: (Google-Suche) - C:\Users\Berthi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-05] CHR Extension: (avast! Online Security) - C:\Users\Berthi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-01-09] CHR Extension: (Google Wallet) - C:\Users\Berthi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-05] CHR Extension: (Google Mail) - C:\Users\Berthi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-05] CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-11-02] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ========================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-11-02] (AVAST Software) R2 AVM WLAN Connection Service; C:\Program Files\avmwlanstick\WlanNetService.exe [364544 2008-02-25] (AVM Berlin) R2 hmpalertsvc; C:\Program Files\HitmanPro.Alert\hmpalert.exe [1830768 2013-09-28] (SurfRight B.V.) S2 lxdeCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdeserv.exe [99248 2007-05-29] (Lexmark International, Inc.) R2 lxde_device; C:\Windows\system32\lxdecoms.exe [598960 2007-05-29] ( ) R2 Recovery Service for Windows; C:\Program Files\SMINST\BLService.exe [365952 2008-12-17] () R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [241734 2008-09-15] () R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) S2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\STacSV.exe [229458 2010-03-23] (IDT, Inc.) R2 TwonkyProxy; C:\Program Files\Twonky\TwonkyServer\twonkyproxy.exe [885576 2013-05-23] () R2 TwonkyServer; C:\Program Files\Twonky\TwonkyServer\twonkystarter.exe [586568 2013-05-23] (PacketVideo) S2 TVCapSvc; "C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe" [X] S2 TVSched; "C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe" [X] ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-02-11] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [79720 2013-11-02] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2013-11-02] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2014-02-11] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410784 2014-02-11] (AVAST Software) S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [64168 2014-02-11] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180248 2014-02-11] () R3 athr; C:\Windows\System32\DRIVERS\athr.sys [2957312 2012-06-20] (Qualcomm Atheros Communications, Inc.) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2007-11-07] (AVM Berlin) R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [37344 2013-10-30] () S3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [401920 2007-12-19] (AVM GmbH) R2 hmpalert; C:\Windows\system32\drivers\hmpalert.sys [14376 2013-09-28] () R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-07-03] (Secunia) S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [89256 2008-05-16] (MCCI Corporation) S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [15016 2008-05-16] (MCCI Corporation) S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [120744 2008-05-16] (MCCI Corporation) S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [114216 2008-05-16] (MCCI Corporation) S3 s0016nd5; C:\Windows\System32\DRIVERS\s0016nd5.sys [25512 2008-05-16] (MCCI Corporation) S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [110632 2008-05-16] (MCCI Corporation) S3 s0016unic; C:\Windows\System32\DRIVERS\s0016unic.sys [115752 2008-05-16] (MCCI Corporation) S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [182680 2013-08-21] (DEVGURU Co., LTD.(www.devguru.co.kr)) R1 ui11rdr; C:\Windows\System32\DRIVERS\ui11rdr.sys [144896 2011-11-21] (1&1 Internet AG) R2 {55662437-DA8C-40c0-AADA-2C816A897A49}; C:\Program Files\Hewlett-Packard\Media\DVD\000.fcl [87536 2008-11-28] (CyberLink Corp.) U4 eabfiltr; Code:
ATTFilter ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-11 14:31 - 2014-02-11 14:31 - 00000000 ____D () C:\Users\Berthi\Desktop\FRST-OlderVersion 2014-02-11 14:30 - 2014-02-11 14:30 - 00064168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2014-02-11 14:30 - 2014-02-11 14:30 - 00002007 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-02-11 14:22 - 2014-02-11 14:22 - 00000626 _____ () C:\Users\Berthi\Desktop\JRT.txt 2014-02-11 13:43 - 2014-02-11 13:43 - 01037530 _____ (Thisisu) C:\Users\Berthi\Desktop\JRT.exe 2014-02-11 13:24 - 2014-02-11 13:24 - 01166132 _____ () C:\Users\Berthi\Desktop\adwcleaner.exe 2014-02-11 11:38 - 2014-02-11 11:38 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-02-11 10:59 - 2014-02-11 11:24 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-02-11 10:59 - 2014-02-11 10:59 - 00107224 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-02-11 10:52 - 2014-02-11 10:52 - 00000000 ____D () C:\Users\Berthi\Desktop\mbar- 2014-02-11 10:45 - 2014-02-11 10:57 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-02-11 10:44 - 2014-02-11 11:24 - 00000000 ____D () C:\Users\Berthi\Desktop\mbar 2014-02-11 10:43 - 2014-02-11 10:43 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Berthi\Desktop\mbar- 2014-02-09 16:52 - 2014-02-09 16:52 - 00027318 _____ () C:\Users\Berthi\Desktop\Addition.txt 2014-02-09 16:51 - 2014-02-11 14:32 - 00014537 _____ () C:\Users\Berthi\Desktop\FRST.txt 2014-02-09 16:51 - 2014-02-11 14:32 - 00000000 ____D () C:\FRST 2014-02-09 16:49 - 2014-02-11 14:31 - 01139712 _____ (Farbar) C:\Users\Berthi\Desktop\FRST.exe 2014-02-08 15:43 - 2014-02-08 15:43 - 00084775 _____ () C:\Users\Berthi\Downloads\search 2014-02-08 11:13 - 2014-02-08 11:13 - 00000000 ____D () C:\Users\Berthi\Desktop\horizon 2014-02-08 11:07 - 2014-02-08 11:07 - 00000000 ____D () C:\Users\Eingechränkter Berth\AppData\Roaming\Windows Live Writer 2014-02-08 11:07 - 2014-02-08 11:07 - 00000000 ____D () C:\Users\Eingechränkter Berth\AppData\Local\Windows Live Writer 2014-02-08 11:04 - 2014-02-08 11:04 - 00000000 ____D () C:\Users\Eingechränkter Berth\AppData\Roaming\vlc 2014-02-08 10:52 - 2014-02-08 10:52 - 00002153 _____ () C:\Users\Eingechränkter Berth\Desktop\Google Chrome.lnk 2014-02-07 17:21 - 2014-02-11 13:32 - 00068840 _____ () C:\Windows\setupact.log 2014-02-07 17:21 - 2014-02-07 17:21 - 00000000 _____ () C:\Windows\setuperr.log 2014-01-31 18:08 - 2014-01-31 18:08 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\dvdcss 2014-01-31 15:56 - 2014-01-31 15:56 - 01166132 _____ () C:\Users\Berthi\Downloads\adwcleaner-3.018.exe 2014-01-31 15:00 - 2014-01-31 15:00 - 04721920 _____ (Piriform Ltd) C:\Users\Berthi\Downloads\ccsetup410.exe 2014-01-31 14:41 - 2014-01-31 14:42 - 01071000 _____ (Solid State Networks) C:\Users\Berthi\Downloads\install_flashplayer12x32_mssa_aaa_aih.exe 2014-01-31 09:03 - 2014-02-11 14:10 - 00000000 ____D () C:\ProgramData\TwonkyServer 2014-01-31 09:03 - 2014-01-31 09:03 - 00001078 _____ () C:\Users\Public\Desktop\Twonky Server.lnk 2014-01-31 09:03 - 2014-01-31 09:03 - 00000011 _____ () C:\ProgramData\.tv7 2014-01-31 09:03 - 2014-01-31 09:03 - 00000000 ____D () C:\Program Files\Twonky 2014-01-31 08:59 - 2014-01-31 09:00 - 05534360 _____ (PacketVideo) C:\Users\Berthi\Downloads\TwonkyServer-7.2.3.exe 2014-01-23 13:56 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-23 13:56 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-23 13:56 - 2013-11-26 10:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-01-23 13:56 - 2013-11-26 09:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-01-23 13:56 - 2013-11-26 09:52 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-01-23 13:56 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-23 13:56 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-23 13:56 - 2013-11-26 09:36 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-01-23 13:56 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-23 13:56 - 2013-11-26 09:29 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-01-23 13:56 - 2013-11-26 09:29 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-01-23 13:56 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-01-23 13:56 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-23 13:56 - 2013-11-26 09:13 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-01-23 13:56 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-23 13:56 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-23 13:56 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-01-23 13:56 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-23 13:56 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-19 14:24 - 2014-01-19 14:24 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-19 14:24 - 2014-01-19 14:24 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-19 14:24 - 2014-01-19 14:24 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-19 14:04 - 2014-01-31 15:01 - 00000000 ____D () C:\Windows\Panther 2014-01-19 13:28 - 2014-02-11 13:08 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-01-19 13:28 - 2014-01-19 13:29 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\Mozilla 2014-01-19 12:57 - 2014-01-19 12:57 - 00283096 _____ (Mozilla) C:\Users\Berthi\Downloads\Firefox Setup Stub 26.0.exe 2014-01-15 15:40 - 2014-01-15 15:40 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-01-15 15:40 - 2014-01-15 15:39 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-15 15:40 - 2014-01-15 15:39 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-15 15:40 - 2014-01-15 15:39 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-15 15:40 - 2014-01-15 15:39 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-01-15 15:39 - 2014-01-15 15:39 - 00000000 ____D () C:\Program Files\Java 2014-01-15 15:35 - 2014-01-15 15:35 - 00921000 _____ (Oracle Corporation) C:\Users\Berthi\Downloads\jxpiinstall(1).exe 2014-01-15 14:21 - 2013-11-27 02:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 14:21 - 2013-11-27 02:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 14:21 - 2013-11-27 02:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 14:21 - 2013-11-27 02:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 14:21 - 2013-11-27 02:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 14:21 - 2013-11-27 02:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 14:21 - 2013-11-27 02:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 14:21 - 2013-11-26 12:11 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 14:21 - 2013-11-26 11:10 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-12 17:41 - 2014-01-12 17:41 - 00742622 _____ () C:\Users\Berthi\Downloads\PopTrayPlugins_beta6.exe ==================== One Month Modified Files and Folders ======= 2014-02-11 14:32 - 2014-02-09 16:51 - 00014537 _____ () C:\Users\Berthi\Desktop\FRST.txt 2014-02-11 14:32 - 2014-02-09 16:51 - 00000000 ____D () C:\FRST 2014-02-11 14:31 - 2014-02-11 14:31 - 00000000 ____D () C:\Users\Berthi\Desktop\FRST-OlderVersion 2014-02-11 14:31 - 2014-02-09 16:49 - 01139712 _____ (Farbar) C:\Users\Berthi\Desktop\FRST.exe 2014-02-11 14:30 - 2014-02-11 14:30 - 00064168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2014-02-11 14:30 - 2014-02-11 14:30 - 00002007 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-02-11 14:30 - 2013-12-29 20:35 - 00410784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2014-02-11 14:30 - 2013-09-19 14:46 - 00775952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-02-11 14:30 - 2013-09-19 14:46 - 00270240 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-02-11 14:30 - 2013-09-19 14:46 - 00180248 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-02-11 14:30 - 2013-09-19 14:46 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-02-11 14:30 - 2013-09-19 14:46 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-02-11 14:22 - 2014-02-11 14:22 - 00000626 _____ () C:\Users\Berthi\Desktop\JRT.txt 2014-02-11 14:10 - 2014-01-31 09:03 - 00000000 ____D () C:\ProgramData\TwonkyServer 2014-02-11 14:05 - 2014-01-05 13:54 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-11 14:05 - 2014-01-05 13:54 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-11 13:47 - 2013-09-01 13:05 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-11 13:44 - 2013-08-27 22:13 - 00019456 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-11 13:44 - 2013-08-27 22:13 - 00019456 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-11 13:43 - 2014-02-11 13:43 - 01037530 _____ (Thisisu) C:\Users\Berthi\Desktop\JRT.exe 2014-02-11 13:34 - 2013-12-30 15:08 - 00000000 ___RD () C:\Users\Berthi\Dropbox 2014-02-11 13:34 - 2013-12-30 14:55 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\Dropbox 2014-02-11 13:33 - 2013-09-03 17:04 - 00000000 ____D () C:\Users\Berthi\.rainlendar2 2014-02-11 13:32 - 2014-02-07 17:21 - 00068840 _____ () C:\Windows\setupact.log 2014-02-11 13:32 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-11 13:31 - 2013-10-13 11:08 - 00000000 ____D () C:\AdwCleaner 2014-02-11 13:31 - 2013-08-27 22:58 - 01725063 _____ () C:\Windows\WindowsUpdate.log 2014-02-11 13:24 - 2014-02-11 13:24 - 01166132 _____ () C:\Users\Berthi\Desktop\adwcleaner.exe 2014-02-11 13:08 - 2014-01-19 13:28 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-02-11 11:40 - 2013-09-09 20:31 - 00000000 ____D () C:\Users\Berthi\Documents\Scribble Papers 2014-02-11 11:38 - 2014-02-11 11:38 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-02-11 11:24 - 2014-02-11 10:59 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-02-11 11:24 - 2014-02-11 10:44 - 00000000 ____D () C:\Users\Berthi\Desktop\mbar 2014-02-11 10:59 - 2014-02-11 10:59 - 00107224 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-02-11 10:57 - 2014-02-11 10:45 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-02-11 10:52 - 2014-02-11 10:52 - 00000000 ____D () C:\Users\Berthi\Desktop\mbar- 2014-02-11 10:43 - 2014-02-11 10:43 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Berthi\Desktop\mbar- 2014-02-09 16:52 - 2014-02-09 16:52 - 00027318 _____ () C:\Users\Berthi\Desktop\Addition.txt 2014-02-08 16:52 - 2013-08-28 21:33 - 00000000 ____D () C:\Users\Berthi\AppData\Local\FRITZ! 2014-02-08 15:58 - 2013-09-08 10:28 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\TV-Browser 2014-02-08 15:43 - 2014-02-08 15:43 - 00084775 _____ () C:\Users\Berthi\Downloads\search 2014-02-08 11:13 - 2014-02-08 11:13 - 00000000 ____D () C:\Users\Berthi\Desktop\horizon 2014-02-08 11:07 - 2014-02-08 11:07 - 00000000 ____D () C:\Users\Eingechränkter Berth\AppData\Roaming\Windows Live Writer 2014-02-08 11:07 - 2014-02-08 11:07 - 00000000 ____D () C:\Users\Eingechränkter Berth\AppData\Local\Windows Live Writer 2014-02-08 11:04 - 2014-02-08 11:04 - 00000000 ____D () C:\Users\Eingechränkter Berth\AppData\Roaming\vlc 2014-02-08 10:56 - 2013-11-10 17:50 - 00000000 ____D () C:\Users\Eingechränkter Berth\AppData\Roaming\WinPatrol 2014-02-08 10:52 - 2014-02-08 10:52 - 00002153 _____ () C:\Users\Eingechränkter Berth\Desktop\Google Chrome.lnk 2014-02-08 10:51 - 2009-07-14 05:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-07 17:21 - 2014-02-07 17:21 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-07 12:57 - 2013-09-01 13:05 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-02-07 12:57 - 2013-09-01 13:05 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-02-07 12:57 - 2013-08-28 13:14 - 00000000 ____D () C:\Users\Berthi\AppData\Local\Adobe 2014-01-31 18:08 - 2014-01-31 18:08 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\dvdcss 2014-01-31 15:56 - 2014-01-31 15:56 - 01166132 _____ () C:\Users\Berthi\Downloads\adwcleaner-3.018.exe 2014-01-31 15:46 - 2013-09-29 19:07 - 00480867 _____ () C:\Users\Berthi\AppData\Local\census.cache 2014-01-31 15:46 - 2013-09-29 19:06 - 00162420 _____ () C:\Users\Berthi\AppData\Local\ars.cache 2014-01-31 15:05 - 2013-09-03 14:59 - 00000000 ____D () C:\Program Files\SpywareBlaster 2014-01-31 15:01 - 2014-01-19 14:04 - 00000000 ____D () C:\Windows\Panther 2014-01-31 15:01 - 2013-08-28 09:51 - 00000000 ____D () C:\Program Files\CCleaner 2014-01-31 15:00 - 2014-01-31 15:00 - 04721920 _____ (Piriform Ltd) C:\Users\Berthi\Downloads\ccsetup410.exe 2014-01-31 14:42 - 2014-01-31 14:41 - 01071000 _____ (Solid State Networks) C:\Users\Berthi\Downloads\install_flashplayer12x32_mssa_aaa_aih.exe 2014-01-31 09:03 - 2014-01-31 09:03 - 00001078 _____ () C:\Users\Public\Desktop\Twonky Server.lnk 2014-01-31 09:03 - 2014-01-31 09:03 - 00000011 _____ () C:\ProgramData\.tv7 2014-01-31 09:03 - 2014-01-31 09:03 - 00000000 ____D () C:\Program Files\Twonky 2014-01-31 09:00 - 2014-01-31 08:59 - 05534360 _____ (PacketVideo) C:\Users\Berthi\Downloads\TwonkyServer-7.2.3.exe 2014-01-23 16:14 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Public\Libraries 2014-01-19 14:30 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\nl-NL 2014-01-19 14:30 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\it-IT 2014-01-19 14:30 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\fr-FR 2014-01-19 14:30 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-01-19 14:30 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\ar-SA 2014-01-19 14:24 - 2014-01-19 14:24 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-19 14:24 - 2014-01-19 14:24 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-19 14:24 - 2014-01-19 14:24 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-19 14:24 - 2014-01-19 14:24 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-19 14:24 - 2014-01-19 14:24 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-19 14:24 - 2014-01-19 14:24 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-19 13:29 - 2014-01-19 13:28 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\Mozilla 2014-01-19 12:57 - 2014-01-19 12:57 - 00283096 _____ (Mozilla) C:\Users\Berthi\Downloads\Firefox Setup Stub 26.0.exe 2014-01-19 11:33 - 2013-12-30 15:08 - 00000982 _____ () C:\Users\Berthi\Desktop\Dropbox.lnk 2014-01-19 11:33 - 2013-12-30 14:59 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-15 15:40 - 2014-01-15 15:40 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-01-15 15:40 - 2013-09-11 19:41 - 00000000 ____D () C:\ProgramData\Oracle 2014-01-15 15:39 - 2014-01-15 15:40 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-15 15:39 - 2014-01-15 15:40 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-15 15:39 - 2014-01-15 15:40 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-15 15:39 - 2014-01-15 15:40 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-01-15 15:39 - 2014-01-15 15:39 - 00000000 ____D () C:\Program Files\Java 2014-01-15 15:35 - 2014-01-15 15:35 - 00921000 _____ (Oracle Corporation) C:\Users\Berthi\Downloads\jxpiinstall(1).exe 2014-01-15 14:48 - 2009-07-14 05:33 - 00348704 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-15 14:34 - 2009-02-21 06:54 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-01-15 14:33 - 2013-08-28 02:31 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-15 14:29 - 2013-08-28 02:31 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-12 17:42 - 2013-08-28 20:12 - 00000000 ____D () C:\Program Files\PopTray 2014-01-12 17:41 - 2014-01-12 17:41 - 00742622 _____ () C:\Users\Berthi\Downloads\PopTrayPlugins_beta6.exe 2014-01-12 12:19 - 2013-09-06 21:45 - 00000000 ____D () C:\Users\Berthi\AppData\Roaming\Skype Some content of TEMP: ==================== C:\Users\Berthi\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-07 15:18 ==================== End Of Log ============================
Bei JRT stand bei Registry: Fehler! Zugriff verweigert
Genauso hab ich es gemacht! Zwei mal sogar. Jedesmal bei Registry diese Meldung. Es spielt sich dabei doch alles in einem Editor ab, oder? Ich meine so ein kleines schwarzes Fenster. Bitte entschuldige, aber ich habe nicht soviel Ahnung. Soll ich JRT nochmal ganz neu installieren und es nochmal machen?
Neu starten, JRT neu runterladen und nochmal probieren
Genau das Gleiche. Er läuft durch, aber bei Registry kommt sieben mal "Fehler:Zugriff verweigert" und dann geht`s weiter. Kann das sein, dass meine Registry, wie auch immer "zerschossen" wurde und daher auch der Fehler mit den IE Links?
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.1 (02.04.2014:1) OS: Windows 7 Home Premium x86 Ran by Berthi on 11.02.2014 at 16:09:56,87 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 11.02.2014 at 16:17:31,02 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Wäre möglich. Egal. Sieht ok aus.

Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM)

Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren!

Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:

ESET Online Scanner
![]() ![]() | ![]() IE 11 öffnet nicht alle LinksCode:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2014.02.11.07 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 11.0.9600.16476 Berthi :: BERTHI-PC [Administrator] 11.02.2014 16:37:00 mbam-log-2014-02-11 (16-37-00).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 228436 Laufzeit: 13 Minute(n), 23 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=6265acc6cc296e4781dadbf0694a7974 # engine=17030 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-02-11 07:20:08 # local_time=2014-02-11 08:20:08 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 74 23603 8948092 0 0 # compatibility_mode=5893 16776573 100 94 38123 143777599 0 0 # scanned=151393 # found=0 # cleaned=0 # scan_time=11867
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() IE 11 öffnet nicht alle Links TFC - Temp File Cleaner Lade dir ![]()
![]() | #15 |
Mahlzeit und Hallo, TFC mache ich sofort, aber soll ich wirklich nochmal Malwarebytes und ESET machen? Hatte ich doch gestern erst gemacht. ESET hat über drei Std. gedauert. Oder ist die Anweisung versehentlich mit "reingerutscht" Ich meine ja bloß. ;-)
