|
Log-Analyse und Auswertung: Windows 7 warnung von avast bzgl e-mailsWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
29.03.2014, 11:21 | #1 |
| Windows 7 warnung von avast bzgl e-mails avast meldet mir regelmäßig beim abrufen meiner e-mails mit thunderbird das "eine bedrohung gefunden wurde" das problem ist, diese adressen gehören zu einem verein, und sind öffentlich einsehbar, demenstrpechend viel spam kommt rein. ein auszug der neusten einträge der quarantäne. ich habe keine ! der anhänge geöfnet und rufe die e-mails mit "nur text" ab. |
29.03.2014, 11:23 | #2 |
Ruhe in Frieden † 2019 | Windows 7 warnung von avast bzgl e-mailsMein Name ist Sandra und ich werde Dir bei Deinem Problem behilflich sein.
Hinweis: Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist meist der schnellere und immer der sicherste Weg. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Dir jemand vom Team sagt, dass Du clean bist. Posten in Code Tags Bitte füge die Logs immer in Code-Tags ein. Wenn Du das nicht machst, erschwert es mir sehr das Auswerten. Danke. Dazu:
Lass uns mal schauen Schritt 1 Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
29.03.2014, 11:33 | #3 |
| Windows 7 warnung von avast bzgl e-mails FRST Logfile:
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by **** (administrator) on ****-PC on 29-03-2014 11:26:04 Running from C:\Users\****\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) c:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe ( ) C:\Windows\system32\lxdxcoms.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe () c:\Program Files (x86)\Hotkey\PowerBiosServer.exe (Syntek America Inc.) C:\Windows\System32\StkCSrv.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Windows\system32\UI0Detect.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe () C:\Program Files (x86)\Hotkey\Hotkey.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe (Dropbox, Inc.) C:\Users\****\AppData\Roaming\Dropbox\bin\Dropbox.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\netzmanager.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Microsoft Corporation) C:\Windows\system32\SnippingTool.exe (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (Farbar) C:\Users\****\Downloads\FRST64(1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2776360 2011-12-05] (ELAN Microelectronics Corp.) HKLM\...\Run: [THXCfg64] - C:\Windows\system32\THXCfg64.dll [25600 2010-09-14] (Creative Technology Ltd.) HKLM\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5299320 2012-10-25] (VIA) HKLM\...\Run: [Creative SB Monitoring Utility] - C:\Windows\system32\sbavmon.dll [109056 2010-01-12] (Creative Technology Ltd.) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-26] (Intel Corporation) HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5299320 2012-10-25] (VIA) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation) HKLM-x32\...\Run: [THX Audio Control Panel] - C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe [1374720 2010-11-01] (Creative Technology Ltd) HKLM-x32\...\Run: [UpdReg] - C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-01-27] (AVAST Software) HKLM-x32\...\Run: [VolPanel] - C:\Program Files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe [241757 2010-12-08] (Creative Technology Ltd) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\RunOnce: [20131224] - C:\Program Files\AVAST Software\Avast\setup\emupdate\ee30858d-332a-40e6-8031-c6d17b9afd9e.exe /check [181136 2014-03-29] (AVAST Software) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKU\S-1-5-21-3599633619-3631945756-2897069935-1001\...\MountPoints2: {0eed03e9-ca73-11e2-acd1-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1001\...\MountPoints2: {7f8d2670-3e41-11e3-98a3-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1001\...\MountPoints2: {808b27ea-25f7-11e3-b56e-0090f5d6799f} - E:\windows\Data\setup.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1001\...\MountPoints2: {9934ee6a-baeb-11e2-84c8-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1001\...\MountPoints2: {9934ee84-baeb-11e2-84c8-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1001\...\MountPoints2: {a6b3942a-4e00-11e3-808c-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1004\...\RunOnce: [InetReg] - "C:\Program Files (x86)\Creative\Produktregistrierung\German\InetReg.exe" /PreProcess=RegFlash.exe /Delay=6 HKU\S-1-5-21-3599633619-3631945756-2897069935-1004\...\MountPoints2: {0eed03e9-ca73-11e2-acd1-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1004\...\MountPoints2: {7f8d2670-3e41-11e3-98a3-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1004\...\MountPoints2: {808b27ea-25f7-11e3-b56e-0090f5d6799f} - E:\windows\Data\setup.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1004\...\MountPoints2: {829b83c6-85de-11e2-b972-806e6f6e6963} - D:\Ctrun\Start.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1004\...\MountPoints2: {9934ee6a-baeb-11e2-84c8-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1004\...\MountPoints2: {9934ee84-baeb-11e2-84c8-0090f5d6799f} - E:\AutoRun.exe AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [168616 2013-09-05] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-09-05] (NVIDIA Corporation) Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://localoem.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com SearchScopes: HKLM - DefaultScope {D159B063-779F-469B-92D2-E910F86D4038} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MASBJS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {D159B063-779F-469B-92D2-E910F86D4038} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MASBJS SearchScopes: HKLM-x32 - DefaultScope {F2EF9F70-55D1-4162-BB26-EDA7F642D1AA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MASBJS SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {F2EF9F70-55D1-4162-BB26-EDA7F642D1AA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MASBJS SearchScopes: HKCU - DefaultScope {D159B063-779F-469B-92D2-E910F86D4038} URL = SearchScopes: HKCU - {D159B063-779F-469B-92D2-E910F86D4038} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{1319BCB8-068A-4688-A8EB-AEA0FE3AE0E0}: [NameServer]10.74.210.210 10.74.210.211 Tcpip\..\Interfaces\{8413CD7B-C547-4B28-A003-9465EF87492A}: [NameServer]10.74.210.210 10.74.210.211 Tcpip\..\Interfaces\{AF5513AB-1E81-42AB-8638-14983C05ACCD}: [NameServer]10.74.210.210 10.74.210.211 Tcpip\..\Interfaces\{EE63B9E6-457B-40B3-B54B-77CA28D667DA}: [NameServer]10.74.210.210 10.74.210.211 FireFox: ======== FF ProfilePath: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default FF user.js: detected! => C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default\user.js FF NewTab: hxxp://www.google.com/firefox FF SearchEngineOrder.1: Google FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.com/firefox FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Flash Video Downloader - Full HD Download - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default\Extensions\artur.dubovoy@gmail.com [2014-03-12] FF Extension: ProxTube - Unblock YouTube - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default\Extensions\ich@maltegoetz.de [2014-03-01] FF Extension: No Name - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default\Extensions\staged [2014-03-29] FF Extension: DownloadHelper - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013-10-23] FF Extension: Firebug - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default\Extensions\firebug@software.joehewitt.com.xpi [2014-01-29] FF Extension: NoScript - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-05-17] FF Extension: Adblock Plus - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-05-04] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013-03-19] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-03-08] FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon Chrome: ======= CHR HomePage: hxxp://www.google.com CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Intel00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll No File CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Extension: (YouTube) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-08] CHR Extension: (AdBlock) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-03-08] CHR Extension: (avast! Online Security) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-05-16] CHR Extension: (TweetDeck by Twitter) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl [2013-03-08] CHR Extension: (Auto HD For YouTube™) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2013-11-02] CHR Extension: (Google Wallet) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR HKLM-x32\...\Chrome\Extension: [edaibbiobngpbmeonadpbfafbkimjbdd] - C:\ProgramData\Logitech\LogiSmoothChromeExt.crx [2013-03-19] CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-27] (AVAST Software) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [224096 2013-05-12] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-01-20] (Intel Corporation) R2 lxdx_device; C:\Windows\system32\lxdxcoms.exe [1039872 2009-10-16] ( ) R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) R2 PowerBiosServer; c:\Program Files (x86)\Hotkey\PowerBiosServer.exe [35328 2011-02-18] () R2 StkSSrv; C:\Windows\System32\StkCSrv.exe [24576 2007-02-12] (Syntek America Inc.) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2012-10-22] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-01-27] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-25] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-25] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-01-27] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-01-27] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-01-27] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-31] () R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2013-05-12] (Bytemobile, Inc.) S3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [111104 2012-05-21] (Motorola Solutions, Inc.) S3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [849408 2012-06-09] (Motorola Solutions, Inc.) S3 btmlehid; C:\Windows\system32\drivers\btmlehid.sys [66560 2012-06-21] (Motorola Solutions, Inc.) R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [304784 2010-03-23] () S3 Huawei; C:\Windows\System32\DRIVERS\ewdcsc.sys [32768 2013-05-12] (Huawei Tech. Co., Ltd.) S3 ksaud; C:\Windows\System32\drivers\ksaud.sys [1558656 2010-07-14] (Creative Technology Ltd.) S3 SMIGrabber3C; C:\Windows\System32\Drivers\SmiUsbGrabber3C.sys [827040 2013-09-14] (Windows (R) Win 7 DDK provider) S3 StkCMini; C:\Windows\System32\Drivers\StkCMini.sys [632704 2007-06-28] (Syntek) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2013-05-12] (Bytemobile, Inc.) R3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) S3 X86BDA; C:\Windows\System32\DRIVERS\OEMDrv.sys [268416 2011-06-08] ( ) S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X] S3 GPU-Z; \??\C:\Users\****\AppData\Local\Temp\GPU-Z.sys [X] S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-29 11:25 - 2014-03-29 11:25 - 02157056 _____ (Farbar) C:\Users\****\Downloads\FRST64(1).exe 2014-03-19 11:51 - 2014-03-19 11:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-18 23:21 - 2014-03-19 09:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-03-18 20:42 - 2014-03-18 23:01 - 00000000 ____D () C:\Users\****\AppData\Roaming\X-Chat 2 2014-03-18 20:40 - 2014-03-18 20:40 - 00000974 _____ () C:\Users\****\Desktop\X-Chat 2.lnk 2014-03-18 20:40 - 2014-03-18 20:40 - 00000000 ____D () C:\Program Files (x86)\X-Chat 2 2014-03-18 20:38 - 2014-03-18 20:39 - 08549657 _____ (SilvereX ) C:\Users\****\Downloads\xchat-2.8.6-2.exe 2014-03-18 08:17 - 2014-03-18 08:17 - 00020613 _____ () C:\Users\****\Downloads\gmer.zip 2014-03-17 20:16 - 2014-03-17 20:16 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-17 20:16 - 2014-03-17 20:16 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-17 20:16 - 2014-03-17 20:16 - 00000000 ____D () C:\Users\****\AppData\Local\Skype 2014-03-17 19:52 - 2014-03-17 19:52 - 00499774 _____ () C:\Users\****\Downloads\gmer.log 2014-03-17 19:47 - 2014-03-17 19:47 - 00380416 _____ () C:\Users\****\Downloads\Gmer-19357.exe 2014-03-17 19:39 - 2014-03-29 11:26 - 00023381 _____ () C:\Users\****\Downloads\FRST.txt 2014-03-17 19:39 - 2014-03-29 11:26 - 00000000 ____D () C:\FRST 2014-03-17 19:39 - 2014-03-17 19:41 - 00039227 _____ () C:\Users\****\Downloads\Addition.txt 2014-03-17 19:38 - 2014-03-17 19:39 - 02157056 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe 2014-03-17 19:29 - 2014-03-17 19:35 - 00081120 _____ () C:\Users\****\Downloads\Extras.Txt 2014-03-17 19:28 - 2014-03-17 19:35 - 00130992 _____ () C:\Users\****\Downloads\OTL.Txt 2014-03-17 19:23 - 2014-03-17 19:23 - 00602112 _____ (OldTimer Tools) C:\Users\****\Downloads\OTL.exe 2014-03-17 19:19 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-03-17 19:19 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-03-17 19:19 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-03-17 19:19 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-03-17 19:19 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-03-17 19:19 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-03-17 19:19 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-03-17 19:19 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-03-17 19:19 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2014-03-17 19:19 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2014-03-17 19:19 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-03-17 19:19 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-03-17 19:19 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-03-17 19:19 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-03-17 19:19 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2014-03-17 19:19 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-03-17 19:19 - 2013-10-01 21:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-03-17 19:19 - 2013-10-01 21:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-03-17 19:15 - 2014-03-01 07:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-17 19:15 - 2014-03-01 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-17 19:15 - 2014-03-01 06:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-17 19:15 - 2014-03-01 05:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-17 19:15 - 2014-03-01 05:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-17 19:15 - 2014-03-01 05:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-17 19:15 - 2014-03-01 05:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-17 19:15 - 2014-03-01 05:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-17 19:15 - 2014-03-01 05:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-17 19:15 - 2014-03-01 05:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-17 19:15 - 2014-03-01 05:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-17 19:15 - 2014-03-01 05:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-17 19:15 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-17 19:15 - 2014-03-01 05:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-17 19:15 - 2014-03-01 05:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-17 19:15 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-17 19:15 - 2014-03-01 05:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-17 19:15 - 2014-03-01 04:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-17 19:15 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-17 19:15 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-17 19:15 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-17 19:15 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-17 19:15 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-17 19:15 - 2014-03-01 04:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-17 19:15 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-17 19:15 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-17 19:15 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-17 19:15 - 2014-03-01 04:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-17 19:15 - 2014-03-01 04:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-17 19:15 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-17 19:15 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-17 19:15 - 2014-03-01 04:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-17 19:15 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-17 19:15 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-17 19:15 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-17 19:15 - 2014-03-01 03:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-17 19:15 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-17 19:15 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-17 19:15 - 2014-03-01 03:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-17 19:15 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-17 19:15 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-17 19:15 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-17 19:15 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-17 19:15 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-03-17 19:15 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-03-17 19:15 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-03-17 19:15 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-03-17 19:15 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-03-17 19:15 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-03-17 19:15 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-03-17 19:15 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-03-17 19:15 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-03-17 19:15 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-03-17 19:15 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-03-17 19:15 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-03-17 19:15 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-03-17 19:15 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-03-17 19:15 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-03-17 19:15 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-03-17 19:15 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-03-17 19:15 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-03-17 19:15 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-03-17 19:15 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-03-17 19:15 - 2013-09-25 03:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-03-17 19:15 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-03-17 19:14 - 2014-02-07 02:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-17 19:14 - 2014-02-04 03:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-17 19:14 - 2014-02-04 03:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-17 19:14 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-17 19:14 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-17 19:14 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-03-17 18:42 - 2014-03-17 18:42 - 00550208 _____ () C:\Users\****\Documents\66.xps 2014-03-13 11:35 - 2014-03-13 11:35 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-03-13 10:06 - 2014-03-13 10:06 - 00001594 _____ () C:\Windows\VPNInstall.MIF 2014-03-13 10:06 - 2014-03-13 10:06 - 00000000 ____D () C:\Program Files\Common Files\Deterministic Networks 2014-03-13 10:03 - 2014-03-17 12:56 - 00000000 ____D () C:\ProgramData\Netzmanager 2014-03-13 10:03 - 2014-03-13 10:03 - 04217148 _____ () C:\Users\****\Documents\Telekom_Hotspot_VPN_Client_64Bit.exe 2014-03-13 10:03 - 2014-03-13 10:03 - 00001003 _____ () C:\Users\Public\Desktop\Netzmanager.lnk 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 __HDC () C:\ProgramData\{BA58D0EE-89D1-4191-9F19-B6AD920B04F7} 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 ____D () C:\Users\****\AppData\Local\PackageAware 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 ____D () C:\Program Files\Netzmanager 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE 2014-03-13 10:02 - 2014-03-13 10:02 - 00000000 ____D () C:\Windows\B0BF705768694E4B920CEA2A58DA07F0.TMP 2014-03-13 10:02 - 2014-03-13 10:02 - 00000000 ____D () C:\Program Files (x86)\Cisco Systems 2014-03-13 10:01 - 2014-03-13 10:03 - 10995296 _____ (Deutsche Telekom AG, Marmiko IT-Solutions GmbH ) C:\Users\****\Documents\netzmanager_setup.exe 2014-03-13 10:01 - 2014-03-13 10:02 - 06705446 _____ () C:\Users\****\Documents\Telekom_Hotspot_VPN_Client_32Bit.exe 2014-03-12 06:53 - 2014-03-12 06:53 - 00026472 _____ () C:\Users\****\Desktop\12_3_14.vmix ==================== One Month Modified Files and Folders ======= 2014-03-29 11:26 - 2014-03-17 19:39 - 00023381 _____ () C:\Users\****\Downloads\FRST.txt 2014-03-29 11:26 - 2014-03-17 19:39 - 00000000 ____D () C:\FRST 2014-03-29 11:25 - 2014-03-29 11:25 - 02157056 _____ (Farbar) C:\Users\****\Downloads\FRST64(1).exe 2014-03-29 11:24 - 2013-05-17 09:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-29 11:22 - 2013-03-08 16:35 - 00000000 ____D () C:\Users\****\AppData\Local\Paint.NET 2014-03-29 11:19 - 2013-03-08 16:53 - 00000000 ____D () C:\Users\****\AppData\Roaming\Skype 2014-03-29 11:11 - 2013-03-08 15:37 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-29 10:18 - 2009-07-14 05:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-29 10:18 - 2009-07-14 05:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-29 10:14 - 2011-02-23 13:59 - 00701560 _____ () C:\Windows\system32\perfh007.dat 2014-03-29 10:14 - 2011-02-23 13:59 - 00150428 _____ () C:\Windows\system32\perfc007.dat 2014-03-29 10:14 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-29 10:11 - 2013-06-29 11:43 - 00000000 ____D () C:\Windows\pss 2014-03-29 10:11 - 2013-03-08 12:21 - 00000000 ___RD () C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-29 10:10 - 2013-10-25 17:02 - 00000000 ___RD () C:\Users\****\Dropbox 2014-03-29 10:10 - 2013-10-25 16:59 - 00000000 ____D () C:\Users\****\AppData\Roaming\Dropbox 2014-03-29 10:10 - 2013-03-08 15:37 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-03-29 10:10 - 2013-03-08 15:37 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-29 10:10 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-29 10:10 - 2009-07-14 05:51 - 00081988 _____ () C:\Windows\setupact.log 2014-03-22 16:48 - 2013-03-08 12:20 - 01523106 _____ () C:\Windows\WindowsUpdate.log 2014-03-20 17:05 - 2013-04-07 17:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-20 17:05 - 2010-11-21 04:47 - 00264680 _____ () C:\Windows\PFRO.log 2014-03-19 20:46 - 2013-03-09 22:36 - 00000000 ____D () C:\Users\****\AppData\Roaming\vlc 2014-03-19 11:51 - 2014-03-19 11:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-19 09:40 - 2014-03-18 23:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-03-19 09:22 - 2013-03-08 12:21 - 00118520 _____ () C:\Users\****\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-19 09:22 - 2009-07-14 05:45 - 00432904 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-18 23:01 - 2014-03-18 20:42 - 00000000 ____D () C:\Users\****\AppData\Roaming\X-Chat 2 2014-03-18 20:40 - 2014-03-18 20:40 - 00000974 _____ () C:\Users\****\Desktop\X-Chat 2.lnk 2014-03-18 20:40 - 2014-03-18 20:40 - 00000000 ____D () C:\Program Files (x86)\X-Chat 2 2014-03-18 20:39 - 2014-03-18 20:38 - 08549657 _____ (SilvereX ) C:\Users\****\Downloads\xchat-2.8.6-2.exe 2014-03-18 12:54 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-03-18 08:17 - 2014-03-18 08:17 - 00020613 _____ () C:\Users\****\Downloads\gmer.zip 2014-03-17 20:16 - 2014-03-17 20:16 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-17 20:16 - 2014-03-17 20:16 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-17 20:16 - 2014-03-17 20:16 - 00000000 ____D () C:\Users\****\AppData\Local\Skype 2014-03-17 20:16 - 2013-03-08 16:53 - 00000000 ____D () C:\ProgramData\Skype 2014-03-17 19:52 - 2014-03-17 19:52 - 00499774 _____ () C:\Users\****\Downloads\gmer.log 2014-03-17 19:47 - 2014-03-17 19:47 - 00380416 _____ () C:\Users\****\Downloads\Gmer-19357.exe 2014-03-17 19:41 - 2014-03-17 19:39 - 00039227 _____ () C:\Users\****\Downloads\Addition.txt 2014-03-17 19:39 - 2014-03-17 19:38 - 02157056 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe 2014-03-17 19:35 - 2014-03-17 19:29 - 00081120 _____ () C:\Users\****\Downloads\Extras.Txt 2014-03-17 19:35 - 2014-03-17 19:28 - 00130992 _____ () C:\Users\****\Downloads\OTL.Txt 2014-03-17 19:23 - 2014-03-17 19:23 - 00602112 _____ (OldTimer Tools) C:\Users\****\Downloads\OTL.exe 2014-03-17 19:21 - 2013-03-08 21:22 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-17 19:21 - 2013-03-08 21:22 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-17 19:18 - 2013-08-20 09:34 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-17 19:17 - 2013-03-08 13:49 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-17 18:42 - 2014-03-17 18:42 - 00550208 _____ () C:\Users\****\Documents\66.xps 2014-03-17 12:56 - 2014-03-13 10:03 - 00000000 ____D () C:\ProgramData\Netzmanager 2014-03-17 09:24 - 2013-05-17 09:42 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-17 09:24 - 2013-03-08 12:40 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-17 09:24 - 2013-03-08 12:40 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-17 09:13 - 2013-03-08 15:39 - 00002135 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-03-13 11:44 - 2013-03-08 15:46 - 00007600 _____ () C:\Users\****\AppData\Local\Resmon.ResmonCfg 2014-03-13 11:35 - 2014-03-13 11:35 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-03-13 10:06 - 2014-03-13 10:06 - 00001594 _____ () C:\Windows\VPNInstall.MIF 2014-03-13 10:06 - 2014-03-13 10:06 - 00000000 ____D () C:\Program Files\Common Files\Deterministic Networks 2014-03-13 10:03 - 2014-03-13 10:03 - 04217148 _____ () C:\Users\****\Documents\Telekom_Hotspot_VPN_Client_64Bit.exe 2014-03-13 10:03 - 2014-03-13 10:03 - 00001003 _____ () C:\Users\Public\Desktop\Netzmanager.lnk 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 __HDC () C:\ProgramData\{BA58D0EE-89D1-4191-9F19-B6AD920B04F7} 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 ____D () C:\Users\****\AppData\Local\PackageAware 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 ____D () C:\Program Files\Netzmanager 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE 2014-03-13 10:03 - 2014-03-13 10:01 - 10995296 _____ (Deutsche Telekom AG, Marmiko IT-Solutions GmbH ) C:\Users\****\Documents\netzmanager_setup.exe 2014-03-13 10:02 - 2014-03-13 10:02 - 00000000 ____D () C:\Windows\B0BF705768694E4B920CEA2A58DA07F0.TMP 2014-03-13 10:02 - 2014-03-13 10:02 - 00000000 ____D () C:\Program Files (x86)\Cisco Systems 2014-03-13 10:02 - 2014-03-13 10:01 - 06705446 _____ () C:\Users\****\Documents\Telekom_Hotspot_VPN_Client_32Bit.exe 2014-03-12 21:44 - 2013-03-08 16:08 - 00044499 _____ () C:\Users\****\AppData\Roaming\last.vmix 2014-03-12 06:53 - 2014-03-12 06:53 - 00026472 _____ () C:\Users\****\Desktop\12_3_14.vmix 2014-03-12 06:46 - 2013-03-08 15:53 - 00000000 ____D () C:\Users\****\Documents\vMixStorage 2014-03-01 07:05 - 2014-03-17 19:15 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-01 06:17 - 2014-03-17 19:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-01 06:16 - 2014-03-17 19:15 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-01 05:58 - 2014-03-17 19:15 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-01 05:52 - 2014-03-17 19:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-01 05:51 - 2014-03-17 19:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-01 05:42 - 2014-03-17 19:15 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-01 05:40 - 2014-03-17 19:15 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-01 05:37 - 2014-03-17 19:15 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-01 05:33 - 2014-03-17 19:15 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-01 05:33 - 2014-03-17 19:15 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-01 05:32 - 2014-03-17 19:15 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-01 05:30 - 2014-03-17 19:15 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-01 05:23 - 2014-03-17 19:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-01 05:17 - 2014-03-17 19:15 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-01 05:11 - 2014-03-17 19:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-01 05:02 - 2014-03-17 19:15 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-01 04:54 - 2014-03-17 19:15 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-01 04:52 - 2014-03-17 19:15 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-01 04:51 - 2014-03-17 19:15 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-01 04:47 - 2014-03-17 19:15 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-01 04:43 - 2014-03-17 19:15 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-01 04:43 - 2014-03-17 19:15 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-01 04:42 - 2014-03-17 19:15 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-01 04:40 - 2014-03-17 19:15 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-01 04:38 - 2014-03-17 19:15 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-01 04:37 - 2014-03-17 19:15 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-01 04:35 - 2014-03-17 19:15 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-01 04:18 - 2014-03-17 19:15 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-01 04:16 - 2014-03-17 19:15 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-01 04:14 - 2014-03-17 19:15 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-01 04:10 - 2014-03-17 19:15 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-01 04:03 - 2014-03-17 19:15 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-01 04:00 - 2014-03-17 19:15 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-01 03:57 - 2014-03-17 19:15 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-01 03:38 - 2014-03-17 19:15 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-01 03:32 - 2014-03-17 19:15 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-01 03:27 - 2014-03-17 19:15 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-01 03:25 - 2014-03-17 19:15 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-01 03:25 - 2014-03-17 19:15 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll Files to move or delete: ==================== C:\Users\****\AppData\Roaming\Camdata.ini C:\Users\****\AppData\Roaming\CamLayout.ini C:\Users\****\AppData\Roaming\CamShapes.ini Some content of TEMP: ==================== C:\Users\****\AppData\Local\Temp\CTPBSeq.exe C:\Users\****\AppData\Local\Temp\DelayInst.exe C:\Users\****\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\****\AppData\Local\Temp\ICReinstall_CamStudio2.7r316-Setup.exe C:\Users\****\AppData\Local\Temp\installservice.exe C:\Users\****\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\****\AppData\Local\Temp\LMkRstPt.exe C:\Users\****\AppData\Local\Temp\ose00000.exe C:\Users\****\AppData\Local\Temp\Profiles.exe C:\Users\****\AppData\Local\Temp\SkypeSetup.exe C:\Users\****\AppData\Local\Temp\swt-win32-3740.dll C:\Users\****\AppData\Local\Temp\vlc-2.0.6-win32.exe C:\Users\****\AppData\Local\Temp\vlc-2.0.8-win32.exe C:\Users\****\AppData\Local\Temp\vlc-2.1.2-win32.exe C:\Users\****\AppData\Local\Temp\vlc-2.1.3-win32.exe C:\Users\****\AppData\Local\Temp\vpnclient_setup.exe C:\Users\****\AppData\Local\Temp\xmlUpdater.exe C:\Users\****\AppData\Local\Temp\_is62D8.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-20 18:21 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014 Ran by **** at 2014-03-29 11:31:51 Running from C:\Users\****\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Flash Media Live Encoder 3.2 (HKLM-x32\...\{0659E943-DDF4-44FC-9FEE-A13B09F8BB08}) (Version: 3.2.0 - Adobe Systems Incorporated) Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) AMP WinOFF 5.0.1 (HKLM-x32\...\AMP WinOFF) (Version: 5.0.1 - Alberto Martinez Perez) ANNO 1503 GOLD (HKLM-x32\...\{DB833EF9-A198-49BE-970A-BD46F30BFBB4}) (Version: 1.05.00 - ) Audacity 2.0.3 (HKLM-x32\...\Audacity_is1) (Version: 2.0.3 - Audacity Team) avast! Free Antivirus (HKLM-x32\...\avast) (Version: 9.0.2013 - Avast Software) BisonCam (HKLM-x32\...\{5BBC4803-C96E-4D3E-9D1D-2E43774C4062}) (Version: 9.2.1.71.53 - BisonCam) CamStudio Lossless Codec v1.5 (HKLM-x32\...\camcodec) (Version: 1.5 - CamStudio) CamStudio version 2.7 (HKLM-x32\...\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7 - CamStudio Open Source) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.1.3868 - CDBurnerXP) ChiconyCam (HKLM-x32\...\{A2201542-DA80-457F-8BD9-6C9C90196481}) (Version: 1.0.47.0819 - Chicony Electronics Co.,Ltd.) Cisco Systems VPN Client 5.0.07.0290 (HKLM\...\{467D5E81-8349-4892-9E81-C3674ED8E451}) (Version: 5.0.7 - Cisco Systems, Inc.) CPUID CPU-Z 1.68 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) CPUID HWMonitor 1.24 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.41 - Creative Technology Limited) Creative Systeminformationen (HKLM-x32\...\SysInfo) (Version: 1.10 - Creative Technology Limited) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Digieffects Phenomena Particle Effects (HKLM-x32\...\MAGIX_{B2D05F0A-841B-459F-8D2B-1802DB6449C8}) (Version: 1.0.0.1 - MAGIX AG) Digieffects Phenomena Particle Effects (Version: 1.0.0.1 - MAGIX AG) Hidden Dropbox (HKCU\...\Dropbox) (Version: 2.4.11 - Dropbox, Inc.) Elsword_DE (HKLM-x32\...\Elsword_DE_is1) (Version: - ) eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden ETDWare PS/2-X64 10.5.2.0 (HKLM\...\Elantech) (Version: 10.5.2.0 - ELAN Microelectronic Corp.) Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{6C5F8503-55D2-4398-858C-362B7A7AF51C}) (Version: 2.1.31.0 - MAGIX AG) foobar2000 v1.2.9 (HKLM-x32\...\foobar2000) (Version: 1.2.9 - Peter Pawlowski) Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.154 - Google Inc.) Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden Grabby Driver Installation (64 Bit) (HKLM-x32\...\{90CA4931-4A1F-4D30-A60B-C2BBFD53D30F}) (Version: 5.09.1202.00 - TERRATEC Electronic GmbH) Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version: - ) Hotkey 6.0027 (HKLM-x32\...\InstallShield_{164714B6-46BC-4649-9A30-A6ED32F03B5A}) (Version: 6.0027 - NoteBook) Hotkey 6.0027 (x32 Version: 6.0027 - NoteBook) Hidden inSSIDer 3 (HKLM-x32\...\{A80CEA4E-74C1-4F9F-806B-E1D9AFC01768}) (Version: 3.0.7.48 - MetaGeek, LLC) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.1.1399 - Intel Corporation) Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2932 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{A10B1524-63B5-40F2-B272-D841CF671C16}) (Version: 2.2.0.0266 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation) Intel® Trusted Connect Service Client (HKLM\...\{538B98C3-773F-4F20-9C66-802D104DCBE2}) (Version: 1.23.219.2 - Intel Corporation) Internet Manager (HKLM-x32\...\Internet Manager) (Version: 22.001.18.42.55 - Huawei Technologies Co.,Ltd) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan) Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden League of Legends (HKLM-x32\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games) Logitech SetPoint 6.52 (HKLM\...\sp6) (Version: 6.52.74 - Logitech) Logitech Unifying-Software 2.10 (HKLM\...\Logitech Unifying) (Version: 2.10.37 - Logitech) MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{F115C413-A7CE-4E9C-8E6F-881A940CDBB8}) (Version: 7.0.2.6 - MAGIX AG) MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden MAGIX Video deluxe 2013 Premium (HKLM-x32\...\MAGIX_{1B5AC129-F6CC-491E-84DE-1FF2996A0367}) (Version: 12.0.0.30 - MAGIX AG) MAGIX Video deluxe 2013 Premium (Version: 12.0.0.30 - MAGIX AG) Hidden MAGIX Video deluxe Premium 2013 Update (Version: 12.0.2.2 - MAGIX AG) Hidden MAGIX Video deluxe Premium 2013 Update (Version: 12.0.4.2 - MAGIX AG) Hidden MediaInfo Lite 0.7.61 (HKLM-x32\...\mediainfolite_is1) (Version: 0.7.61 - ) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 17.0.2003.1112 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Mobile Partner (HKLM-x32\...\Mobile Partner) (Version: 13.001.08.04.538 - Huawei Technologies Co.,Ltd) Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) Mozilla Thunderbird 24.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.4.0 (x86 de)) (Version: 24.4.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Mumble 1.2.3 (HKLM-x32\...\{C3E9887A-23BA-4777-8080-191A5AFCAB74}) (Version: 1.2.3 - Thorvald Natvig) NetSpeedMonitor 2.5.4.0 x64 (HKLM\...\{88F41EE2-949B-4B52-933D-C7F8F67BC1D2}) (Version: 2.5.4.0 - Florian Gilles) Netzmanager (HKLM-x32\...\Netzmanager) (Version: 1.081 - Deutsche Telekom AG) Netzmanager (Version: 1.081 - Deutsche Telekom AG, Marmiko IT-Solutions GmbH) Hidden Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.5.2 - Notepad++ Team) NVIDIA Grafiktreiber 327.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 327.02 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden NVIDIA Optimus 1.14.17 (Version: 1.14.17 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.12.1031 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.12.1031 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.1031 - NVIDIA Corporation) NVIDIA Systemsteuerung 327.02 (Version: 327.02 - NVIDIA Corporation) Hidden NVIDIA Update 1.14.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.14.17 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.14.17 - NVIDIA Corporation) Hidden Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41418}) (Version: 3.61.0 - dotPDN LLC) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.8 - Pando Networks Inc.) Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.49.927.2011 - Realtek) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.27012 - Realtek Semiconductor Corp.) Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.1.0 - Samsung Electronics) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.10.1 - TeamSpeak Systems GmbH) TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.22298 - TeamViewer) TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp) TERRATEC GRABSTER AV 300 MX (64 Bit) (HKLM-x32\...\{D2496882-4944-4E17-8292-371F7C560544}) (Version: 1.0.8.30 - TERRATEC) TERRATEC GRABSTER AV 300 MX (HKLM-x32\...\{AF2E0639-F692-4281-910D-8357C3430488}) (Version: 1.0.8.30 - ) THX TruStudio Pro (HKLM-x32\...\{82F99DC9-389A-4528-940C-88248731A620}) (Version: TAMB-CVS1D-1-LB R07 - Creative Technology Limited) TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) USB Sound Blaster HD (HKLM-x32\...\{3BE06146-8ADC-47D7-9AD5-E5CABF1FF90C}) (Version: 1.0 - Creative Technology Limited) USB2.0 ATV (HKLM-x32\...\USB2.0 ATV) (Version: - ) Vasco da Gama 6 HD MAGIX Edition (HKLM-x32\...\{9432F8D1-09C7-4C78-8F68-B163206698CD}) (Version: 6.50.0000 - MotionStudios) VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.) Video Essentials IV for Magix (HKLM-x32\...\NewBlue Video Essentials IV for Magix) (Version: 3.0 - NewBlue) VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) vMix (HKLM-x32\...\{93D664E9-E81E-4277-9E90-6CDABAC7208F}_is1) (Version: - StudioCoast) WebCam Installer (HKLM-x32\...\InstallShield_{2A14D7BC-1876-4B38-830B-18856C27F550}) (Version: 4.00 - WebCam) WebCam Installer (x32 Version: 4.00 - WebCam) Hidden Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Family Safety (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows-Treiberpaket - Intel (NETwLv64) net (10/07/2010 13.4.0.139) (HKLM\...\EA1C8ECD4E416637C38F0079F98C8C7B0A112265) (Version: 10/07/2010 13.4.0.139 - Intel) Windows-Treiberpaket - Intel (NETwNs64) net (01/22/2012 14.3.2.1) (HKLM\...\CD88F0FADE1395C9F91302912FD35B13CF75C196) (Version: 01/22/2012 14.3.2.1 - Intel) Windows-Treiberpaket - Intel (NETwNs64) net (09/30/2012 15.3.1.2) (HKLM\...\C4A0B98BB9B3537BFB45B8BA6177991FD0CADD3A) (Version: 09/30/2012 15.3.1.2 - Intel) Windows-Treiberpaket - Intel net (01/22/2012 14.3.2.1) (HKLM\...\4795C4A805590BF1276BCED3EB2478E5BF545E83) (Version: 01/22/2012 14.3.2.1 - Intel) Windows-Treiberpaket - Intel net (09/30/2012 15.3.1.2) (HKLM\...\751A99B9D25B1127E0849AAA30110607FE2C6C32) (Version: 09/30/2012 15.3.1.2 - Intel) Windows-Treiberpaket - Intel net (10/07/2010 13.4.0.139) (HKLM\...\695CFD288064D5B9D072C610E63BDD3D3E4DE666) (Version: 10/07/2010 13.4.0.139 - Intel) Windows-Treiberpaket - TERRATEC (SMIGrabber3C) Media (02/23/2013 1.0.8.30) (HKLM\...\7E9494FD65A61C4AF6762FC49C6917408E9D230E) (Version: 02/23/2013 1.0.8.30 - TERRATEC ) Windows-Treiberpaket - TERRATEC (USB28xxBGA) Media (03/16/2010 5.09.1202.00) (HKLM\...\22B1739EAEA711117281C678C9005F17A0D9D420) (Version: 03/16/2010 5.09.1202.00 - TERRATEC ) Windows-Treiberpaket - TERRATEC (emAudio) Media (03/16/2010 5.09.1202.00) (HKLM\...\0812DA72EAD4FBFA883430ED6EC04AC1F88DBBAD) (Version: 03/16/2010 5.09.1202.00 - TERRATEC) WinSCP 5.5 (HKLM-x32\...\winscp3_is1) (Version: 5.5 - Martin Prikryl) X-Chat 2.8.6-2 (HKLM-x32\...\X-Chat 2_is1) (Version: 2.8.6-2 - SilvereX) ==================== Restore Points ========================= 26-02-2014 23:07:50 Geplanter Prüfpunkt 13-03-2014 09:06:06 Installed Cisco Systems VPN Client 5.0.07.0290 17-03-2014 18:16:03 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {1659BA59-2E84-46C1-9ED7-3E383D4E3D51} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-01-27] (AVAST Software) Task: {83823CDB-535A-4B27-9EE0-03E440C0C3DD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-08] (Google Inc.) Task: {E6CD90F1-1C66-4788-B84C-4A08C67DFA8C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-17] (Adobe Systems Incorporated) Task: {F9F3583C-B575-4D79-B7BB-06946521C95D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-08] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-04-23 18:14 - 2013-08-29 23:43 - 00097568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2013-08-30 16:39 - 2009-10-16 12:12 - 00177664 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxdxdrpp.dll 2011-03-14 16:27 - 2011-03-14 16:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2013-05-12 11:10 - 2013-05-12 11:09 - 00224096 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe 2010-10-19 08:31 - 2010-10-19 08:31 - 00205312 _____ () C:\Program Files\Netzmanager\NMInfraIS2\driver64\SoftplugLib.DLL 2011-02-18 15:57 - 2011-02-18 15:57 - 00035328 _____ () c:\Program Files (x86)\Hotkey\PowerBiosServer.exe 2013-03-05 11:58 - 2013-09-05 02:36 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2013-03-05 11:57 - 2010-11-12 12:38 - 00241152 _____ () C:\Windows\SYSTEM32\APOMgr64.DLL 2013-03-08 13:17 - 2012-10-25 17:26 - 00078456 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll 2013-03-08 13:17 - 2012-10-25 17:26 - 00386168 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll 2012-06-18 11:22 - 2012-01-05 10:24 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-03-05 11:57 - 2009-12-29 16:53 - 00089088 _____ () C:\Windows\SYSTEM32\CmdRtr64.DLL 2012-02-09 15:21 - 2012-02-09 15:21 - 04727296 _____ () C:\Program Files (x86)\Hotkey\Hotkey.exe ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^vpngui.exe.lnk => C:\Windows\pss\vpngui.exe.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^****^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Netzmanager.lnk => C:\Windows\pss\Netzmanager.lnk.Startup MSCONFIG\startupfolder: C:^Users^****^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Samsung Magician.lnk => C:\Windows\pss\Samsung Magician.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: BLEServicesCtrl => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe MSCONFIG\startupreg: BTMTrayAgent => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp MSCONFIG\startupreg: CECAPLF => C:\Program Files (x86)\ChiconyCam\CECAPLF.exe MSCONFIG\startupreg: EvtMgr6 => C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming MSCONFIG\startupreg: Logitech Download Assistant => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch MSCONFIG\startupreg: Pando Media Booster => C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: Yontoo Desktop => "C:\Users\****\AppData\Roaming\Yontoo\YontooDesktop.exe" ==================== Faulty Device Manager Devices ============= Name: Cisco Systems VPN Adapter for 64-bit Windows Description: Cisco Systems VPN Adapter for 64-bit Windows Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: CVirtA Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (03/29/2014 10:10:19 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/22/2014 00:37:57 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/21/2014 03:09:22 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/20/2014 05:58:27 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/20/2014 05:05:57 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/19/2014 10:24:17 AM) (Source: Application Hang) (User: ) Description: Programm IEXPLORE.EXE, Version 11.0.9600.16521 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 12cc Startzeit: 01cf4354afeeab59 Endzeit: 0 Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Berichts-ID: Error: (03/19/2014 09:22:40 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/18/2014 09:59:20 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/18/2014 08:09:40 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/17/2014 07:21:43 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (03/29/2014 10:10:07 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/29/2014 10:10:07 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht. Error: (03/22/2014 00:37:14 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/22/2014 00:37:14 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht. Error: (03/21/2014 03:12:16 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (03/21/2014 03:12:15 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (03/21/2014 03:12:14 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (03/21/2014 03:09:13 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/21/2014 03:09:13 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht. Error: (03/20/2014 05:58:18 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 78% Total physical RAM: 3989.22 MB Available physical RAM: 872.96 MB Total Pagefile: 4127.4 MB Available Pagefile: 746.53 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:209.68 GB) (Free:135.89 GB) NTFS ==>[Drive with boot components (obtained from BCD)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: CC86D53D) Partition: GPT Partition Type. ==================== End Of Log ============================ |
29.03.2014, 12:02 | #4 |
Ruhe in Frieden † 2019 | Windows 7 warnung von avast bzgl e-mails Hallo nagisa-chan, deine Logs sehen soweit unauffälllig aus. Du bekommst die Meldungen von Avast, weil dieses auch deinen InboxOrdner von Thunderbird scannt, den darfst du keinesfalls löschen, sonst sind alle deine Mails weg . Wenn du diese Mails in Thunderbird löschst, dann gehe danach mit rechtsklick Maus auf den Thunderbird Papierkorb und wähle dann Ordner komprimieren. Damit dürfte das Problem verschwunden sein. Wir sollten vorsichtshalber trotzdem die Kontrollscans machen. Schritt 1 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 2 Da der Scan mit Eset sehr gründlich ist, kann er unter Umständen mehrere Stunden dauern ESET Online Scanner
Schritt 3 Starte noch einmal FRST.
|
29.03.2014, 13:22 | #5 |
| Windows 7 warnung von avast bzgl e-mails malewarebytes Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 29.03.2014 Suchlauf-Zeit: 12:19:01 Logdatei: mbam.txt Administrator: Ja Version: 2.00.0.1000 Malware Datenbank: v2014.03.29.01 Rootkit Datenbank: v2014.03.27.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: **** Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 280084 Verstrichene Zeit: 6 Min, 0 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 2 PUP.Optional.InstallCore.A, HKU\S-1-5-21-3599633619-3631945756-2897069935-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [eb1af514cfacb77fc35495d11ae8dd23], PUP.Optional.InstallCore.A, HKU\S-1-5-21-3599633619-3631945756-2897069935-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [74914abf3c3fa690fa62d7a5fa097b85], Registrierungswerte: 1 PUP.Optional.InstallCore.A, HKU\S-1-5-21-3599633619-3631945756-2897069935-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0G2Y1R2X0G1M2S1M0G1S1H, In Quarantäne, [74914abf3c3fa690fa62d7a5fa097b85] Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 1 PUP.Optional.Delta.A, C:\Users\****\AppData\Local\Temp\is1108708961\DeltaTB.exe, In Quarantäne, [db2a4bbec2b91e18d52b6798d9270ef2], Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=762eafabf3d51145b2457f831b6caec5 # engine=17672 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-03-29 12:17:54 # local_time=2014-03-29 01:17:54 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 77 3494 5261069 0 0 # compatibility_mode=5893 16776573 100 94 592181 147725324 0 0 # scanned=296611 # found=5 # cleaned=0 # scan_time=3096 sh=410B32FD3FE4642644AD91AC60C69B86EC2762DD ft=1 fh=0e378a435beab91a vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll" sh=410B32FD3FE4642644AD91AC60C69B86EC2762DD ft=1 fh=0e378a435beab91a vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\Users\All Users\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll" sh=B81C86D02DF1C73D13AD60A588B0F9B236EA3C70 ft=1 fh=86a2c950cdfa5ca9 vn="multiple threats" ac=I fn="C:\Users\****\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RVBZ9J2C\yontoosetup[1].exe" sh=5E3D00F752E784F67B862C69056EE1794AE907BA ft=1 fh=0b56e2b59008c539 vn="a variant of Win32/Kryptik.BWJC trojan" ac=I fn="C:\Users\****\AppData\Local\Temp\ICReinstall_CamStudio2.7r316-Setup.exe" sh=DA602313EC344E31F340105C29DF699267F73B84 ft=1 fh=34999f3f19837452 vn="multiple threats" ac=I fn="C:\Users\****\AppData\Local\Temp\is1108708961\yontoo-C4.exe" FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by **** (administrator) on ****-PC on 29-03-2014 13:21:39 Running from C:\Users\****\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) c:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe ( ) C:\Windows\system32\lxdxcoms.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe () c:\Program Files (x86)\Hotkey\PowerBiosServer.exe (Syntek America Inc.) C:\Windows\System32\StkCSrv.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe () C:\Program Files (x86)\Hotkey\Hotkey.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe (Dropbox, Inc.) C:\Users\****\AppData\Roaming\Dropbox\bin\Dropbox.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Don HO don.h@free.fr) C:\Program Files (x86)\Notepad++\notepad++.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2776360 2011-12-05] (ELAN Microelectronics Corp.) HKLM\...\Run: [THXCfg64] - C:\Windows\system32\THXCfg64.dll [25600 2010-09-14] (Creative Technology Ltd.) HKLM\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5299320 2012-10-25] (VIA) HKLM\...\Run: [Creative SB Monitoring Utility] - C:\Windows\system32\sbavmon.dll [109056 2010-01-12] (Creative Technology Ltd.) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-26] (Intel Corporation) HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5299320 2012-10-25] (VIA) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation) HKLM-x32\...\Run: [THX Audio Control Panel] - C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe [1374720 2010-11-01] (Creative Technology Ltd) HKLM-x32\...\Run: [UpdReg] - C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767608 2014-03-29] (AVAST Software) HKLM-x32\...\Run: [VolPanel] - C:\Program Files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe [241757 2010-12-08] (Creative Technology Ltd) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKU\S-1-5-21-3599633619-3631945756-2897069935-1001\...\MountPoints2: {0eed03e9-ca73-11e2-acd1-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1001\...\MountPoints2: {7f8d2670-3e41-11e3-98a3-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1001\...\MountPoints2: {808b27ea-25f7-11e3-b56e-0090f5d6799f} - E:\windows\Data\setup.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1001\...\MountPoints2: {9934ee6a-baeb-11e2-84c8-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1001\...\MountPoints2: {9934ee84-baeb-11e2-84c8-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1001\...\MountPoints2: {a6b3942a-4e00-11e3-808c-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1004\...\RunOnce: [InetReg] - "C:\Program Files (x86)\Creative\Produktregistrierung\German\InetReg.exe" /PreProcess=RegFlash.exe /Delay=6 HKU\S-1-5-21-3599633619-3631945756-2897069935-1004\...\MountPoints2: {0eed03e9-ca73-11e2-acd1-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1004\...\MountPoints2: {7f8d2670-3e41-11e3-98a3-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1004\...\MountPoints2: {808b27ea-25f7-11e3-b56e-0090f5d6799f} - E:\windows\Data\setup.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1004\...\MountPoints2: {829b83c6-85de-11e2-b972-806e6f6e6963} - D:\Ctrun\Start.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1004\...\MountPoints2: {9934ee6a-baeb-11e2-84c8-0090f5d6799f} - E:\AutoRun.exe HKU\S-1-5-21-3599633619-3631945756-2897069935-1004\...\MountPoints2: {9934ee84-baeb-11e2-84c8-0090f5d6799f} - E:\AutoRun.exe AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [168616 2013-09-05] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-09-05] (NVIDIA Corporation) Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://localoem.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com SearchScopes: HKLM - DefaultScope {D159B063-779F-469B-92D2-E910F86D4038} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MASBJS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {D159B063-779F-469B-92D2-E910F86D4038} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MASBJS SearchScopes: HKLM-x32 - DefaultScope {F2EF9F70-55D1-4162-BB26-EDA7F642D1AA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MASBJS SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {F2EF9F70-55D1-4162-BB26-EDA7F642D1AA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MASBJS SearchScopes: HKCU - DefaultScope {D159B063-779F-469B-92D2-E910F86D4038} URL = SearchScopes: HKCU - {D159B063-779F-469B-92D2-E910F86D4038} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{1319BCB8-068A-4688-A8EB-AEA0FE3AE0E0}: [NameServer]10.74.210.210 10.74.210.211 Tcpip\..\Interfaces\{8413CD7B-C547-4B28-A003-9465EF87492A}: [NameServer]10.74.210.210 10.74.210.211 Tcpip\..\Interfaces\{AF5513AB-1E81-42AB-8638-14983C05ACCD}: [NameServer]10.74.210.210 10.74.210.211 Tcpip\..\Interfaces\{EE63B9E6-457B-40B3-B54B-77CA28D667DA}: [NameServer]10.74.210.210 10.74.210.211 FireFox: ======== FF ProfilePath: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default FF user.js: detected! => C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default\user.js FF NewTab: hxxp://www.google.com/firefox FF SearchEngineOrder.1: Google FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.com/firefox FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Flash Video Downloader - Full HD Download - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default\Extensions\artur.dubovoy@gmail.com [2014-03-12] FF Extension: ProxTube - Unblock YouTube - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default\Extensions\ich@maltegoetz.de [2014-03-01] FF Extension: DownloadHelper - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-29] FF Extension: Firebug - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default\Extensions\firebug@software.joehewitt.com.xpi [2014-01-29] FF Extension: NoScript - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-05-17] FF Extension: Adblock Plus - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\045q6evy.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-05-04] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013-03-19] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-03-08] FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon Chrome: ======= CHR HomePage: hxxp://www.google.com CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Intel00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll No File CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Extension: (YouTube) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-08] CHR Extension: (AdBlock) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-03-08] CHR Extension: (avast! Online Security) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-05-16] CHR Extension: (TweetDeck by Twitter) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl [2013-03-08] CHR Extension: (Auto HD For YouTube™) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2013-11-02] CHR Extension: (Google Wallet) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR HKLM-x32\...\Chrome\Extension: [edaibbiobngpbmeonadpbfafbkimjbdd] - C:\ProgramData\Logitech\LogiSmoothChromeExt.crx [2013-03-19] CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-27] (AVAST Software) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [224096 2013-05-12] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-01-20] (Intel Corporation) R2 lxdx_device; C:\Windows\system32\lxdxcoms.exe [1039872 2009-10-16] ( ) R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) R2 PowerBiosServer; c:\Program Files (x86)\Hotkey\PowerBiosServer.exe [35328 2011-02-18] () R2 StkSSrv; C:\Windows\System32\StkCSrv.exe [24576 2007-02-12] (Syntek America Inc.) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2012-10-22] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-01-27] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-25] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-25] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-01-27] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-01-27] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-01-27] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-31] () R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2013-05-12] (Bytemobile, Inc.) S3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [111104 2012-05-21] (Motorola Solutions, Inc.) S3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [849408 2012-06-09] (Motorola Solutions, Inc.) S3 btmlehid; C:\Windows\system32\drivers\btmlehid.sys [66560 2012-06-21] (Motorola Solutions, Inc.) R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [304784 2010-03-23] () S3 Huawei; C:\Windows\System32\DRIVERS\ewdcsc.sys [32768 2013-05-12] (Huawei Tech. Co., Ltd.) S3 ksaud; C:\Windows\System32\drivers\ksaud.sys [1558656 2010-07-14] (Creative Technology Ltd.) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-03-29] (Malwarebytes Corporation) S3 SMIGrabber3C; C:\Windows\System32\Drivers\SmiUsbGrabber3C.sys [827040 2013-09-14] (Windows (R) Win 7 DDK provider) S3 StkCMini; C:\Windows\System32\Drivers\StkCMini.sys [632704 2007-06-28] (Syntek) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2013-05-12] (Bytemobile, Inc.) S3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) S3 X86BDA; C:\Windows\System32\DRIVERS\OEMDrv.sys [268416 2011-06-08] ( ) S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X] S3 GPU-Z; \??\C:\Users\****\AppData\Local\Temp\GPU-Z.sys [X] S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-29 12:24 - 2014-03-29 12:24 - 02347384 _____ (ESET) C:\Users\****\Downloads\esetsmartinstaller_enu.exe 2014-03-29 12:22 - 2014-03-29 12:22 - 00001812 _____ () C:\Users\****\Desktop\mbam.txt 2014-03-29 12:11 - 2014-03-29 12:21 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-03-29 12:11 - 2014-03-29 12:11 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\****\Downloads\mbam-setup-2.0.0.1000.exe 2014-03-29 12:11 - 2014-03-29 12:11 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-29 12:11 - 2014-03-29 12:11 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-29 12:11 - 2014-03-29 12:11 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-03-29 12:11 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-03-29 12:11 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-29 12:11 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-29 11:31 - 2014-03-29 11:33 - 00031222 _____ () C:\Users\****\Downloads\Addition.txt 2014-03-19 11:51 - 2014-03-19 11:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-18 23:21 - 2014-03-19 09:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-03-18 20:42 - 2014-03-18 23:01 - 00000000 ____D () C:\Users\****\AppData\Roaming\X-Chat 2 2014-03-18 20:40 - 2014-03-18 20:40 - 00000974 _____ () C:\Users\****\Desktop\X-Chat 2.lnk 2014-03-18 20:40 - 2014-03-18 20:40 - 00000000 ____D () C:\Program Files (x86)\X-Chat 2 2014-03-18 20:38 - 2014-03-18 20:39 - 08549657 _____ (SilvereX ) C:\Users\****\Downloads\xchat-2.8.6-2.exe 2014-03-18 08:17 - 2014-03-18 08:17 - 00020613 _____ () C:\Users\****\Downloads\gmer.zip 2014-03-17 20:16 - 2014-03-17 20:16 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-17 20:16 - 2014-03-17 20:16 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-17 20:16 - 2014-03-17 20:16 - 00000000 ____D () C:\Users\****\AppData\Local\Skype 2014-03-17 19:52 - 2014-03-17 19:52 - 00499774 _____ () C:\Users\****\Downloads\gmer.log 2014-03-17 19:47 - 2014-03-17 19:47 - 00380416 _____ () C:\Users\****\Downloads\Gmer-19357.exe 2014-03-17 19:39 - 2014-03-29 13:21 - 00022223 _____ () C:\Users\****\Downloads\FRST.txt 2014-03-17 19:39 - 2014-03-29 13:21 - 00000000 ____D () C:\FRST 2014-03-17 19:38 - 2014-03-17 19:39 - 02157056 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe 2014-03-17 19:29 - 2014-03-17 19:35 - 00081120 _____ () C:\Users\****\Downloads\Extras.Txt 2014-03-17 19:28 - 2014-03-17 19:35 - 00130992 _____ () C:\Users\****\Downloads\OTL.Txt 2014-03-17 19:23 - 2014-03-17 19:23 - 00602112 _____ (OldTimer Tools) C:\Users\****\Downloads\OTL.exe 2014-03-17 19:19 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-03-17 19:19 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-03-17 19:19 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-03-17 19:19 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-03-17 19:19 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-03-17 19:19 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-03-17 19:19 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-03-17 19:19 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-03-17 19:19 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2014-03-17 19:19 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2014-03-17 19:19 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-03-17 19:19 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-03-17 19:19 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-03-17 19:19 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-03-17 19:19 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2014-03-17 19:19 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-03-17 19:19 - 2013-10-01 21:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-03-17 19:19 - 2013-10-01 21:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-03-17 19:15 - 2014-03-01 07:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-17 19:15 - 2014-03-01 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-17 19:15 - 2014-03-01 06:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-17 19:15 - 2014-03-01 05:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-17 19:15 - 2014-03-01 05:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-17 19:15 - 2014-03-01 05:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-17 19:15 - 2014-03-01 05:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-17 19:15 - 2014-03-01 05:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-17 19:15 - 2014-03-01 05:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-17 19:15 - 2014-03-01 05:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-17 19:15 - 2014-03-01 05:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-17 19:15 - 2014-03-01 05:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-17 19:15 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-17 19:15 - 2014-03-01 05:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-17 19:15 - 2014-03-01 05:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-17 19:15 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-17 19:15 - 2014-03-01 05:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-17 19:15 - 2014-03-01 04:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-17 19:15 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-17 19:15 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-17 19:15 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-17 19:15 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-17 19:15 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-17 19:15 - 2014-03-01 04:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-17 19:15 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-17 19:15 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-17 19:15 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-17 19:15 - 2014-03-01 04:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-17 19:15 - 2014-03-01 04:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-17 19:15 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-17 19:15 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-17 19:15 - 2014-03-01 04:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-17 19:15 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-17 19:15 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-17 19:15 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-17 19:15 - 2014-03-01 03:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-17 19:15 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-17 19:15 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-17 19:15 - 2014-03-01 03:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-17 19:15 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-17 19:15 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-17 19:15 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-17 19:15 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-17 19:15 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-03-17 19:15 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-03-17 19:15 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-03-17 19:15 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-03-17 19:15 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-03-17 19:15 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-03-17 19:15 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-03-17 19:15 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-03-17 19:15 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-03-17 19:15 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-03-17 19:15 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-03-17 19:15 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-03-17 19:15 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-03-17 19:15 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-03-17 19:15 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-03-17 19:15 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-03-17 19:15 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-03-17 19:15 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-03-17 19:15 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-03-17 19:15 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-03-17 19:15 - 2013-09-25 03:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-03-17 19:15 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-03-17 19:14 - 2014-02-07 02:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-17 19:14 - 2014-02-04 03:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-17 19:14 - 2014-02-04 03:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-17 19:14 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-17 19:14 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-17 19:14 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-03-17 18:42 - 2014-03-17 18:42 - 00550208 _____ () C:\Users\****\Documents\66.xps 2014-03-13 11:35 - 2014-03-13 11:35 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-03-13 10:06 - 2014-03-13 10:06 - 00001594 _____ () C:\Windows\VPNInstall.MIF 2014-03-13 10:06 - 2014-03-13 10:06 - 00000000 ____D () C:\Program Files\Common Files\Deterministic Networks 2014-03-13 10:03 - 2014-03-17 12:56 - 00000000 ____D () C:\ProgramData\Netzmanager 2014-03-13 10:03 - 2014-03-13 10:03 - 04217148 _____ () C:\Users\****\Documents\Telekom_Hotspot_VPN_Client_64Bit.exe 2014-03-13 10:03 - 2014-03-13 10:03 - 00001003 _____ () C:\Users\Public\Desktop\Netzmanager.lnk 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 __HDC () C:\ProgramData\{BA58D0EE-89D1-4191-9F19-B6AD920B04F7} 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 ____D () C:\Users\****\AppData\Local\PackageAware 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 ____D () C:\Program Files\Netzmanager 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE 2014-03-13 10:02 - 2014-03-13 10:02 - 00000000 ____D () C:\Windows\B0BF705768694E4B920CEA2A58DA07F0.TMP 2014-03-13 10:02 - 2014-03-13 10:02 - 00000000 ____D () C:\Program Files (x86)\Cisco Systems 2014-03-13 10:01 - 2014-03-13 10:03 - 10995296 _____ (Deutsche Telekom AG, Marmiko IT-Solutions GmbH ) C:\Users\****\Documents\netzmanager_setup.exe 2014-03-13 10:01 - 2014-03-13 10:02 - 06705446 _____ () C:\Users\****\Documents\Telekom_Hotspot_VPN_Client_32Bit.exe 2014-03-12 06:53 - 2014-03-12 06:53 - 00026472 _____ () C:\Users\****\Desktop\12_3_14.vmix ==================== One Month Modified Files and Folders ======= 2014-03-29 13:21 - 2014-03-17 19:39 - 00022223 _____ () C:\Users\****\Downloads\FRST.txt 2014-03-29 13:21 - 2014-03-17 19:39 - 00000000 ____D () C:\FRST 2014-03-29 13:11 - 2013-03-08 15:37 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-29 12:49 - 2013-03-08 15:46 - 00007600 _____ () C:\Users\****\AppData\Local\Resmon.ResmonCfg 2014-03-29 12:26 - 2011-02-23 13:59 - 00701560 _____ () C:\Windows\system32\perfh007.dat 2014-03-29 12:26 - 2011-02-23 13:59 - 00150428 _____ () C:\Windows\system32\perfc007.dat 2014-03-29 12:26 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-29 12:26 - 2009-07-14 05:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-29 12:26 - 2009-07-14 05:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-29 12:24 - 2014-03-29 12:24 - 02347384 _____ (ESET) C:\Users\****\Downloads\esetsmartinstaller_enu.exe 2014-03-29 12:24 - 2013-05-17 09:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-29 12:22 - 2014-03-29 12:22 - 00001812 _____ () C:\Users\****\Desktop\mbam.txt 2014-03-29 12:22 - 2013-03-08 12:20 - 01530830 _____ () C:\Windows\WindowsUpdate.log 2014-03-29 12:21 - 2014-03-29 12:11 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-03-29 12:20 - 2013-10-25 17:02 - 00000000 ___RD () C:\Users\****\Dropbox 2014-03-29 12:20 - 2013-10-25 16:59 - 00000000 ____D () C:\Users\****\AppData\Roaming\Dropbox 2014-03-29 12:19 - 2013-03-08 16:53 - 00000000 ____D () C:\Users\****\AppData\Roaming\Skype 2014-03-29 12:19 - 2013-03-08 15:37 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-29 12:19 - 2010-11-21 04:47 - 00265046 _____ () C:\Windows\PFRO.log 2014-03-29 12:19 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-29 12:19 - 2009-07-14 05:51 - 00082044 _____ () C:\Windows\setupact.log 2014-03-29 12:11 - 2014-03-29 12:11 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\****\Downloads\mbam-setup-2.0.0.1000.exe 2014-03-29 12:11 - 2014-03-29 12:11 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-29 12:11 - 2014-03-29 12:11 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-29 12:11 - 2014-03-29 12:11 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-03-29 11:33 - 2014-03-29 11:31 - 00031222 _____ () C:\Users\****\Downloads\Addition.txt 2014-03-29 11:22 - 2013-03-08 16:35 - 00000000 ____D () C:\Users\****\AppData\Local\Paint.NET 2014-03-29 10:11 - 2013-06-29 11:43 - 00000000 ____D () C:\Windows\pss 2014-03-29 10:11 - 2013-03-08 12:21 - 00000000 ___RD () C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-29 10:10 - 2013-03-08 15:37 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-03-20 17:05 - 2013-04-07 17:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-19 20:46 - 2013-03-09 22:36 - 00000000 ____D () C:\Users\****\AppData\Roaming\vlc 2014-03-19 11:51 - 2014-03-19 11:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-19 09:40 - 2014-03-18 23:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-03-19 09:22 - 2013-03-08 12:21 - 00118520 _____ () C:\Users\****\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-19 09:22 - 2009-07-14 05:45 - 00432904 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-18 23:01 - 2014-03-18 20:42 - 00000000 ____D () C:\Users\****\AppData\Roaming\X-Chat 2 2014-03-18 20:40 - 2014-03-18 20:40 - 00000974 _____ () C:\Users\****\Desktop\X-Chat 2.lnk 2014-03-18 20:40 - 2014-03-18 20:40 - 00000000 ____D () C:\Program Files (x86)\X-Chat 2 2014-03-18 20:39 - 2014-03-18 20:38 - 08549657 _____ (SilvereX ) C:\Users\****\Downloads\xchat-2.8.6-2.exe 2014-03-18 12:54 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-03-18 08:17 - 2014-03-18 08:17 - 00020613 _____ () C:\Users\****\Downloads\gmer.zip 2014-03-17 20:16 - 2014-03-17 20:16 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-17 20:16 - 2014-03-17 20:16 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-17 20:16 - 2014-03-17 20:16 - 00000000 ____D () C:\Users\****\AppData\Local\Skype 2014-03-17 20:16 - 2013-03-08 16:53 - 00000000 ____D () C:\ProgramData\Skype 2014-03-17 19:52 - 2014-03-17 19:52 - 00499774 _____ () C:\Users\****\Downloads\gmer.log 2014-03-17 19:47 - 2014-03-17 19:47 - 00380416 _____ () C:\Users\****\Downloads\Gmer-19357.exe 2014-03-17 19:39 - 2014-03-17 19:38 - 02157056 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe 2014-03-17 19:35 - 2014-03-17 19:29 - 00081120 _____ () C:\Users\****\Downloads\Extras.Txt 2014-03-17 19:35 - 2014-03-17 19:28 - 00130992 _____ () C:\Users\****\Downloads\OTL.Txt 2014-03-17 19:23 - 2014-03-17 19:23 - 00602112 _____ (OldTimer Tools) C:\Users\****\Downloads\OTL.exe 2014-03-17 19:21 - 2013-03-08 21:22 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-17 19:21 - 2013-03-08 21:22 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-17 19:18 - 2013-08-20 09:34 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-17 19:17 - 2013-03-08 13:49 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-17 18:42 - 2014-03-17 18:42 - 00550208 _____ () C:\Users\****\Documents\66.xps 2014-03-17 12:56 - 2014-03-13 10:03 - 00000000 ____D () C:\ProgramData\Netzmanager 2014-03-17 09:24 - 2013-05-17 09:42 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-17 09:24 - 2013-03-08 12:40 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-17 09:24 - 2013-03-08 12:40 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-17 09:13 - 2013-03-08 15:39 - 00002135 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-03-13 11:35 - 2014-03-13 11:35 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-03-13 10:06 - 2014-03-13 10:06 - 00001594 _____ () C:\Windows\VPNInstall.MIF 2014-03-13 10:06 - 2014-03-13 10:06 - 00000000 ____D () C:\Program Files\Common Files\Deterministic Networks 2014-03-13 10:03 - 2014-03-13 10:03 - 04217148 _____ () C:\Users\****\Documents\Telekom_Hotspot_VPN_Client_64Bit.exe 2014-03-13 10:03 - 2014-03-13 10:03 - 00001003 _____ () C:\Users\Public\Desktop\Netzmanager.lnk 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 __HDC () C:\ProgramData\{BA58D0EE-89D1-4191-9F19-B6AD920B04F7} 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 ____D () C:\Users\****\AppData\Local\PackageAware 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 ____D () C:\Program Files\Netzmanager 2014-03-13 10:03 - 2014-03-13 10:03 - 00000000 ____D () C:\Program Files (x86)\Microsoft WSE 2014-03-13 10:03 - 2014-03-13 10:01 - 10995296 _____ (Deutsche Telekom AG, Marmiko IT-Solutions GmbH ) C:\Users\****\Documents\netzmanager_setup.exe 2014-03-13 10:02 - 2014-03-13 10:02 - 00000000 ____D () C:\Windows\B0BF705768694E4B920CEA2A58DA07F0.TMP 2014-03-13 10:02 - 2014-03-13 10:02 - 00000000 ____D () C:\Program Files (x86)\Cisco Systems 2014-03-13 10:02 - 2014-03-13 10:01 - 06705446 _____ () C:\Users\****\Documents\Telekom_Hotspot_VPN_Client_32Bit.exe 2014-03-12 21:44 - 2013-03-08 16:08 - 00044499 _____ () C:\Users\****\AppData\Roaming\last.vmix 2014-03-12 06:53 - 2014-03-12 06:53 - 00026472 _____ () C:\Users\****\Desktop\12_3_14.vmix 2014-03-12 06:46 - 2013-03-08 15:53 - 00000000 ____D () C:\Users\****\Documents\vMixStorage 2014-03-05 09:26 - 2014-03-29 12:11 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-03-05 09:26 - 2014-03-29 12:11 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-03-05 09:26 - 2014-03-29 12:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-01 07:05 - 2014-03-17 19:15 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-01 06:17 - 2014-03-17 19:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-01 06:16 - 2014-03-17 19:15 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-01 05:58 - 2014-03-17 19:15 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-01 05:52 - 2014-03-17 19:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-01 05:51 - 2014-03-17 19:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-01 05:42 - 2014-03-17 19:15 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-01 05:40 - 2014-03-17 19:15 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-01 05:37 - 2014-03-17 19:15 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-01 05:33 - 2014-03-17 19:15 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-01 05:33 - 2014-03-17 19:15 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-01 05:32 - 2014-03-17 19:15 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-01 05:30 - 2014-03-17 19:15 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-01 05:23 - 2014-03-17 19:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-01 05:17 - 2014-03-17 19:15 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-01 05:11 - 2014-03-17 19:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-01 05:02 - 2014-03-17 19:15 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-01 04:54 - 2014-03-17 19:15 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-01 04:52 - 2014-03-17 19:15 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-01 04:51 - 2014-03-17 19:15 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-01 04:47 - 2014-03-17 19:15 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-01 04:43 - 2014-03-17 19:15 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-01 04:43 - 2014-03-17 19:15 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-01 04:42 - 2014-03-17 19:15 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-01 04:40 - 2014-03-17 19:15 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-01 04:38 - 2014-03-17 19:15 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-01 04:37 - 2014-03-17 19:15 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-01 04:35 - 2014-03-17 19:15 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-01 04:18 - 2014-03-17 19:15 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-01 04:16 - 2014-03-17 19:15 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-01 04:14 - 2014-03-17 19:15 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-01 04:10 - 2014-03-17 19:15 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-01 04:03 - 2014-03-17 19:15 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-01 04:00 - 2014-03-17 19:15 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-01 03:57 - 2014-03-17 19:15 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-01 03:38 - 2014-03-17 19:15 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-01 03:32 - 2014-03-17 19:15 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-01 03:27 - 2014-03-17 19:15 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-01 03:25 - 2014-03-17 19:15 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-01 03:25 - 2014-03-17 19:15 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll Files to move or delete: ==================== C:\Users\****\AppData\Roaming\Camdata.ini C:\Users\****\AppData\Roaming\CamLayout.ini C:\Users\****\AppData\Roaming\CamShapes.ini Some content of TEMP: ==================== C:\Users\****\AppData\Local\Temp\CTPBSeq.exe C:\Users\****\AppData\Local\Temp\DelayInst.exe C:\Users\****\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\****\AppData\Local\Temp\ICReinstall_CamStudio2.7r316-Setup.exe C:\Users\****\AppData\Local\Temp\installservice.exe C:\Users\****\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\****\AppData\Local\Temp\LMkRstPt.exe C:\Users\****\AppData\Local\Temp\ose00000.exe C:\Users\****\AppData\Local\Temp\Profiles.exe C:\Users\****\AppData\Local\Temp\SkypeSetup.exe C:\Users\****\AppData\Local\Temp\swt-win32-3740.dll C:\Users\****\AppData\Local\Temp\vlc-2.0.6-win32.exe C:\Users\****\AppData\Local\Temp\vlc-2.0.8-win32.exe C:\Users\****\AppData\Local\Temp\vlc-2.1.2-win32.exe C:\Users\****\AppData\Local\Temp\vlc-2.1.3-win32.exe C:\Users\****\AppData\Local\Temp\vpnclient_setup.exe C:\Users\****\AppData\Local\Temp\xmlUpdater.exe C:\Users\****\AppData\Local\Temp\_is62D8.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-20 18:21 ==================== End Of Log ============================ --- --- --- |
29.03.2014, 22:45 | #6 |
Ruhe in Frieden † 2019 | Windows 7 warnung von avast bzgl e-mails Hallo nagisa-chan, die Funde sind nur Reste, beziehungsweise Setupdateien von potentiell unerwünschten Programmen /Adware, entfernen wir noch. Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\ProgramData\Tarma Installer CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
>OK< So wie ich es sehe, haben wir damit alles Schadhafte entfernt. Deine Logs sind sauber. Abschließend räumen wir noch etwas auf und dann bekommst du noch etwas Lesestoff von mir. Schritt 1 Falls Du Malwarebytes-Antimalware und den ESET-Onlinescan nicht mehr benötigst, kannst Du beide Programme einfach über die Programmdeinstallation deinstallieren. Ich empfehle Dir aber zumindest Malwarebytes zu behalten, und damit einmal die Woche einen Kontrollscan zu machen. Schritt 2 Downloade dir bitte delfix auf deinen Desktop.
Nun zum Schluss noch ein paar Tipps zur Absicherung deines Systems. Aktualität des Systems Es ist extrem wichtig, dass sowohl dein System als auch die darauf installierte sicherheitsrelevante Software (Flash Player, PDF-Reader und besonders Java, sofern vorhanden) aktuell sind.
Antivirensoftware
Zusätzlicher Schutz
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der Internet Explorer, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Systemleistung Lösche regelmäßig deine temporären Dateien. Ich empfehle hierzu TFC Halte dich fern von jeglichen Registry Cleanern. Diese schaden deinem System mehr als dass sie es schneller machen. Verhaltensregeln zum sichereren Surfen
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen. Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. Falls Du Lob oder Kritik abgeben möchtest, kannst Du das sehr gerne hier tun. Wenn Du etwas für das Forum und unsere Arbeit spenden möchtest, so kannst Du das hier tun.
__________________ --> Windows 7 warnung von avast bzgl e-mails |
Themen zu Windows 7 warnung von avast bzgl e-mails |
adresse, auszug, bedrohung gefunden, e-mail, einträge, hänge, neuste, pup.optional.delta.a, pup.optional.installcore.a, spam, thunderbird, warnung, win32/adware.yontoo.b, win32/kryptik.bwjc, windows 7, öffen |