|
Plagegeister aller Art und deren Bekämpfung: Wie kann ich Daten sichern da MusikTrojaner vermutetWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
08.04.2014, 14:14 | #16 |
| Wie kann ich Daten sichern da MusikTrojaner vermutet Fixlog: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014 Ran by Michaela at 2014-04-08 13:36:56 Run:1 Running from C:\Users\Michaela\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\...\Run: [sroli] - rundll32.exe ",HrEditPhonebookEntry ProxyServer: 172.16.10.1:8080 ***************** HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\sroli => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value deleted successfully. ==== End of Fixlog ==== Gerade lief mbam automatisch durch mit folgendem Fund: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 08.04.2014 Suchlauf-Zeit: 15:08:34 Logdatei: mbam2.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.08.03 Rootkit Datenbank: v2014.03.27.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Chameleon: Deaktiviert Betriebssystem: Windows Vista Service Pack 2 CPU: x64 Dateisystem: NTFS Benutzer: Michaela Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 249132 Verstrichene Zeit: 52 Min, 59 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 1 PUP.Optional.Snapdo.A, C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=97c644c5-ac6a-452e-b40f-ec9598ff936e&searchtype=hp&installDate=02/06/2013",), Ersetzt,[c02349de3744ff378f21c181907425db] Physische Sektoren: 0 (No malicious items detected) (end) Frage am Rande: Soll ich die Quarantäne einfach so lassen oder ist es sinnvoll die Dateien dort zu löschen? |
09.04.2014, 13:24 | #17 |
/// the machine /// TB-Ausbilder | Wie kann ich Daten sichern da MusikTrojaner vermutet Die kannste auch löschen. Bitte nochmal nen frischen Scan mit FRST machen. Bestehen noch Probleme mit dem System?
__________________
__________________ |
09.04.2014, 14:51 | #18 |
| Wie kann ich Daten sichern da MusikTrojaner vermutet FRST:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 (ATTENTION: ====> FRST version is 27 days old and could be outdated) Ran by Michaela (administrator) on MICHAELA-PC on 09-04-2014 15:43:28 Running from C:\Users\Michaela\Desktop Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe () C:\Windows\System32\WLTRYSVC.EXE (Dell Inc.) C:\Windows\System32\bcmwltry.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe (SoftThinks) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Microsoft Corporation) C:\Windows\system32\conime.exe () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Dell Inc.) C:\Windows\System32\WLTRAY.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe () C:\Users\Michaela\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe (CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (SupportSoft, Inc.) C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe (Dropbox, Inc.) C:\Users\Michaela\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe (SupportSoft, Inc.) C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [305664 2009-03-31] (Alps Electric Co., Ltd.) HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\Windows\system32\WLTRAY.exe [4119552 2008-12-21] (Dell Inc.) HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [178712 2008-06-15] (Intel Corporation) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [462848 2009-03-31] (IDT, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Dell DataSafe Online] - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe [1779952 2009-07-07] () HKLM-x32\...\Run: [Microsoft Default Manager] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [250192 2009-04-24] (Microsoft Corporation) HKLM-x32\...\Run: [PDVDDXSrv] - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [128232 2009-02-05] (CyberLink Corp.) HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [405639 2009-01-09] (Creative Technology Ltd) HKLM-x32\...\Run: [DellSupportCenter] - C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe [206064 2009-05-21] (SupportSoft, Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2012-02-20] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512 2013-09-19] (RealNetworks, Inc.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-03-29] (AVAST Software) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\RunOnce: [DSUpdateLauncher] - "c:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\runhstart.bat" [374 2009-03-09] () HKLM-x32\...\RunOnce: [Launcher] - "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe" [165104 2009-07-16] (Softthinks) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2157045702-3999625576-2718192899-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [138240 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-2157045702-3999625576-2718192899-1000\...\Run: [AmazonMP3DownloaderHelper] - C:\Users\Michaela\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] () Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Michaela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Michaela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Michaela\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank URLSearchHook: HKCU - YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File URLSearchHook: HKCU - YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: ProxTube - {0AA2810A-F009-4BD7-A10A-32F140A1B9F3} - C:\Users\Michaela\AppData\LocalLow\ProxTube\IE\ProxTube.dll (Malte Goetz) BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Michaela\AppData\Roaming\Mozilla\Firefox\Profiles\ighg0d3g.default FF NewTab: about:blank FF Homepage: about:home FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*'))%20%7B%20return%20'PROXY%20nq-us04.personalitycores.com%3A8000%3B%20PROXY%20nq-us05.personalitycores.com%3A8000%3B%20PROXY%20nq-us08.personalitycores.com%3A8000%3B%20PROXY%20nq-us09.personalitycores.com%3A8000%3B%20PROXY%20nq-us10.personalitycores.com%3A8000%3B%20PROXY%20nq-us11.personalitycores.com%3A8000%3B%20PROXY%20nq-us07.personalitycores.com%3A8000%3B%20PROXY%20nq-us12.personalitycores.com%3A8000%3B%20PROXY%20nq-us06.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF NetworkProxy: "type", 2 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Michaela\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Michaela\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - C:\Users\Michaela\AppData\Roaming\Mozilla\Firefox\Profiles\ighg0d3g.default\Extensions\maltegoetz@proxtube.com [2012-11-08] FF Extension: ProxMate - Proxy on steroids! - C:\Users\Michaela\AppData\Roaming\Mozilla\Firefox\Profiles\ighg0d3g.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-08-17] FF Extension: Adblock Plus - C:\Users\Michaela\AppData\Roaming\Mozilla\Firefox\Profiles\ighg0d3g.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-28] FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-03-29] Chrome: ======= CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=97c644c5-ac6a-452e-b40f-ec9598ff936e&searchtype=hp&installDate=02/06/2013 CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll () CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll () CHR Plugin: (Java(TM) Platform SE 6 U13) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll No File CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll No File CHR Plugin: (Adobe Acrobat) - c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer Download Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Plugin: (RealJukebox NS Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll No File CHR Extension: (Boa Mistura) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\alhbnbjlmhkpfeocomgpfkffnbncjjpn [2013-08-08] CHR Extension: (YouTube) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-10-10] CHR Extension: (Adblock Plus) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-12-28] CHR Extension: (Google-Suche) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-10-10] CHR Extension: (Google+) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm [2013-08-08] CHR Extension: (XKit) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpfgeeomkfdefkckijiabdbogjkdaecd [2014-01-11] CHR Extension: (avast! Online Security) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-03-29] CHR Extension: (ProxMate - Proxy on steroids!) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgjpnmnpjmabddgmjdiaggacbololbjm [2013-08-17] CHR Extension: (Google Keep) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2013-09-20] CHR Extension: (RealDownloader) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-09-20] CHR Extension: (Dropbox) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2013-08-08] CHR Extension: (Google Wallet) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01] CHR Extension: (Youtube Video Downloader) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\obmbipnhbnpicpechoajlkjfdiopnoki [2013-05-19] CHR Extension: (Tumblr Savior) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefddkjnflmjbclpnnoegglmmdfkidip [2014-01-05] CHR Extension: (Google Mail) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-10-10] CHR HKLM-x32\...\Chrome\Extension: [chakodcglgpacmjpjfaoopegbglbollk] - C:\Users\Michaela\AppData\LocalLow\ProxTube\CHROME\ProxTube.crx [2010-05-25] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-03-29] CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14] ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-03-29] (AVAST Software) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] () R2 wltrysvc; C:\Windows\System32\bcmwltry.exe [3051520 2008-12-21] (Dell Inc.) R2 yksvc; RUNDLL32.EXE ykx64coinst,serviceStartProc [X] ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2008-01-21] (Microsoft Corporation) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-03-29] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [64752 2014-03-29] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-03-29] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-03-29] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-03-29] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2014-03-29] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208928 2014-03-29] () R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [133672 2011-08-04] (Broadcom Corporation.) S1 Beep; No ImagePath R3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [89640 2011-08-04] (Broadcom Corporation.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-09] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) R3 OA009Ufd; C:\Windows\System32\DRIVERS\OA009Ufd.sys [159840 2009-03-06] (Creative Technology Ltd.) R3 OA009Vid; C:\Windows\System32\DRIVERS\OA009Vid.sys [311296 2009-03-19] (Creative Technology Ltd.) S3 usbbus; C:\Windows\System32\DRIVERS\lgx64bus.sys [17920 2008-09-04] (LG Electronics Inc.) S3 UsbDiag; C:\Windows\System32\DRIVERS\lgx64diag.sys [27136 2008-09-04] (LG Electronics Inc.) S3 USBModem; C:\Windows\System32\DRIVERS\lgx64modem.sys [33792 2008-09-04] (LG Electronics Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-09 15:43 - 2014-04-09 15:44 - 00028422 _____ () C:\Users\Michaela\Desktop\FRST.txt 2014-04-08 12:34 - 2014-04-08 12:34 - 00448512 _____ (OldTimer Tools) C:\Users\Michaela\Desktop\TFC.exe 2014-04-07 17:29 - 2014-04-07 17:29 - 00987442 _____ () C:\Users\Michaela\Desktop\SecurityCheck.exe 2014-04-05 15:00 - 2014-04-05 15:00 - 00000000 ____D () C:\Windows\ERUNT 2014-04-05 14:59 - 2014-04-05 14:59 - 01038974 _____ (Thisisu) C:\Users\Michaela\Desktop\JRT.exe 2014-04-05 14:43 - 2014-04-05 14:46 - 00000000 ____D () C:\AdwCleaner 2014-04-05 14:42 - 2014-04-05 14:42 - 01426178 _____ () C:\Users\Michaela\Desktop\adwcleaner.exe 2014-04-05 14:08 - 2014-04-09 15:34 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-05 13:51 - 2014-04-05 14:11 - 00000943 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-05 13:51 - 2014-04-05 14:11 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-05 13:51 - 2014-04-05 13:51 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-05 13:51 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-05 13:51 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-05 13:51 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-04 12:03 - 2014-04-04 12:03 - 00030914 _____ () C:\ComboFix.txt 2014-04-04 11:38 - 2014-04-04 12:03 - 00000000 ____D () C:\Qoobox 2014-04-04 11:38 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-04-04 11:38 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-04-04 11:38 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-04-04 11:38 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-04-04 11:38 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-04-04 11:38 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-04-04 11:38 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-04-04 11:38 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-04-04 11:37 - 2014-04-04 12:00 - 00000000 ____D () C:\Windows\erdnt 2014-04-04 11:34 - 2014-04-04 11:34 - 05193944 ____R (Swearware) C:\Users\Michaela\Desktop\ComboFix.exe 2014-04-04 00:16 - 2014-04-08 02:10 - 00000000 ___RD () C:\Users\Michaela\Bilder nach Datensicherung vom 03.04.14 2014-04-03 19:39 - 2014-04-03 19:39 - 00000000 ____D () C:\Users\Michaela\Documents\Bluetooth-Exchange-Ordner 2014-04-03 19:38 - 2014-04-03 19:38 - 00000000 ____D () C:\Users\Michaela\Documents\Amazon MP3 2014-04-03 15:32 - 2014-04-03 15:32 - 00000000 ____D () C:\Users\Michaela\Documents\Tumblr 2014-04-01 12:51 - 2014-04-09 15:43 - 00000000 ____D () C:\FRST 2014-04-01 12:33 - 2014-04-01 12:34 - 02157056 _____ (Farbar) C:\Users\Michaela\Desktop\FRST64.exe 2014-03-29 15:21 - 2014-04-04 11:26 - 00000808 _____ () C:\Windows\system32\spsys.log 2014-03-29 15:07 - 2014-03-29 15:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-29 15:03 - 2013-12-18 22:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-03-29 15:03 - 2013-12-18 22:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-03-29 15:03 - 2013-12-18 22:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-03-29 15:03 - 2013-12-18 22:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-03-29 15:02 - 2014-03-29 15:03 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-03-29 14:56 - 2014-03-29 14:56 - 00000000 ____D () C:\Users\Michaela\AppData\Roaming\Opera Software 2014-03-29 14:56 - 2014-03-29 14:56 - 00000000 ____D () C:\Users\Michaela\AppData\Local\Opera Software 2014-03-29 14:44 - 2014-03-29 14:45 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-03-29 14:27 - 2014-03-29 14:27 - 00000000 ____D () C:\Users\Michaela\AppData\Roaming\AVAST Software 2014-03-29 14:26 - 2014-04-05 13:24 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-03-29 14:25 - 2014-03-29 14:25 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-03-29 14:25 - 2014-03-29 14:25 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-03-29 14:25 - 2014-03-29 14:25 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-03-29 14:25 - 2014-03-29 14:25 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-03-29 14:25 - 2014-03-29 14:25 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-03-29 14:25 - 2014-03-29 14:25 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-03-29 14:25 - 2014-03-29 14:25 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2014-03-29 14:25 - 2014-03-29 14:25 - 00064752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr.sys 2014-03-29 14:25 - 2014-03-29 14:25 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-03-29 14:23 - 2014-03-29 14:23 - 00000000 ____D () C:\Program Files\AVAST Software 2014-03-29 14:20 - 2014-03-29 14:20 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-03-19 20:46 - 2014-03-27 22:55 - 00003246 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2157045702-3999625576-2718192899-1000 2014-03-19 20:45 - 2014-03-27 22:55 - 00003374 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2157045702-3999625576-2718192899-1000 2014-03-16 02:49 - 2014-03-16 02:49 - 00000000 ____D () C:\Users\Michaela\AppData\Local\Skype 2014-03-14 03:20 - 2014-04-03 15:30 - 00000000 ____D () C:\Users\Michaela\Documents\HTML Code 2014-03-13 04:01 - 2014-02-23 09:12 - 17847808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-13 04:01 - 2014-02-23 08:54 - 02334720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-13 04:01 - 2014-02-23 08:52 - 10926592 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-13 04:01 - 2014-02-23 08:48 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-13 04:01 - 2014-02-23 08:48 - 01347072 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-13 04:01 - 2014-02-23 08:46 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-13 04:01 - 2014-02-23 08:46 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-03-13 04:01 - 2014-02-23 08:46 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-13 04:01 - 2014-02-23 08:45 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-03-13 04:01 - 2014-02-23 08:45 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-03-13 04:01 - 2014-02-23 08:45 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-13 04:01 - 2014-02-23 08:44 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-13 04:01 - 2014-02-23 08:44 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-13 04:01 - 2014-02-23 08:44 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-13 04:01 - 2014-02-23 08:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-03-13 04:01 - 2014-02-23 08:43 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-13 04:01 - 2014-02-23 07:50 - 12347904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-13 04:01 - 2014-02-23 07:47 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-13 04:01 - 2014-02-23 07:43 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-13 04:01 - 2014-02-23 07:41 - 01105408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-13 04:01 - 2014-02-23 07:40 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-13 04:01 - 2014-02-23 07:39 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-13 04:01 - 2014-02-23 07:38 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-03-13 04:01 - 2014-02-23 07:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-13 04:01 - 2014-02-23 07:38 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-13 04:01 - 2014-02-23 07:37 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-13 04:01 - 2014-02-23 07:37 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-03-13 04:01 - 2014-02-23 07:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-13 04:01 - 2014-02-23 07:37 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-03-13 04:01 - 2014-02-23 07:36 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-13 04:01 - 2014-02-23 07:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-03-13 04:01 - 2014-02-23 07:35 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-13 00:48 - 2014-02-07 14:11 - 02776064 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-13 00:48 - 2014-02-03 15:20 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-13 00:48 - 2014-02-03 12:37 - 00505344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-13 00:48 - 2014-01-30 12:12 - 01111040 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-13 00:48 - 2014-01-30 09:46 - 00876032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-13 00:48 - 2013-11-13 03:54 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-03-13 00:48 - 2013-11-13 02:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll ==================== One Month Modified Files and Folders ======= 2014-04-09 15:44 - 2014-04-09 15:43 - 00028422 _____ () C:\Users\Michaela\Desktop\FRST.txt 2014-04-09 15:43 - 2014-04-01 12:51 - 00000000 ____D () C:\FRST 2014-04-09 15:43 - 2009-09-24 22:31 - 01488304 _____ () C:\Windows\WindowsUpdate.log 2014-04-09 15:37 - 2013-07-16 23:39 - 00000000 ___RD () C:\Users\Michaela\Dropbox 2014-04-09 15:37 - 2013-07-16 23:35 - 00000000 ____D () C:\Users\Michaela\AppData\Roaming\Dropbox 2014-04-09 15:34 - 2014-04-05 14:08 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-09 15:34 - 2012-08-15 22:10 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-09 15:34 - 2009-10-02 19:11 - 00000000 ____D () C:\Users\Michaela\AppData\Local\SoftThinks 2014-04-09 15:30 - 2012-10-10 20:49 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-09 15:30 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-09 15:30 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-09 15:30 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-09 02:10 - 2013-02-12 05:26 - 00003549 _____ () C:\Windows\bthservsdp.dat 2014-04-09 02:10 - 2006-11-02 17:42 - 00032530 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-04-09 02:08 - 2013-03-28 23:50 - 00000000 ____D () C:\Users\Michaela\AppData\Roaming\Skype 2014-04-09 01:46 - 2012-10-10 20:49 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-09 01:05 - 2013-03-11 14:00 - 00000940 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2157045702-3999625576-2718192899-1000UA.job 2014-04-08 13:05 - 2013-03-11 14:00 - 00000918 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2157045702-3999625576-2718192899-1000Core.job 2014-04-08 13:03 - 2008-01-21 05:26 - 00788458 _____ () C:\Windows\PFRO.log 2014-04-08 12:34 - 2014-04-08 12:34 - 00448512 _____ (OldTimer Tools) C:\Users\Michaela\Desktop\TFC.exe 2014-04-08 02:10 - 2014-04-04 00:16 - 00000000 ___RD () C:\Users\Michaela\Bilder nach Datensicherung vom 03.04.14 2014-04-07 17:29 - 2014-04-07 17:29 - 00987442 _____ () C:\Users\Michaela\Desktop\SecurityCheck.exe 2014-04-07 14:56 - 2008-01-21 13:10 - 01566076 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-07 14:56 - 2008-01-21 13:09 - 00673932 _____ () C:\Windows\system32\perfh007.dat 2014-04-07 14:56 - 2008-01-21 13:09 - 00145912 _____ () C:\Windows\system32\perfc007.dat 2014-04-07 14:54 - 2009-09-25 04:11 - 00000000 ____D () C:\Program Files (x86)\Dell DataSafe Local Backup 2014-04-07 14:53 - 2006-11-02 17:27 - 00288807 _____ () C:\Windows\setupact.log 2014-04-05 15:00 - 2014-04-05 15:00 - 00000000 ____D () C:\Windows\ERUNT 2014-04-05 14:59 - 2014-04-05 14:59 - 01038974 _____ (Thisisu) C:\Users\Michaela\Desktop\JRT.exe 2014-04-05 14:46 - 2014-04-05 14:43 - 00000000 ____D () C:\AdwCleaner 2014-04-05 14:42 - 2014-04-05 14:42 - 01426178 _____ () C:\Users\Michaela\Desktop\adwcleaner.exe 2014-04-05 14:11 - 2014-04-05 13:51 - 00000943 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-05 14:11 - 2014-04-05 13:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-05 13:51 - 2014-04-05 13:51 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-05 13:24 - 2014-03-29 14:26 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-04-04 12:03 - 2014-04-04 12:03 - 00030914 _____ () C:\ComboFix.txt 2014-04-04 12:03 - 2014-04-04 11:38 - 00000000 ____D () C:\Qoobox 2014-04-04 12:03 - 2006-11-02 15:33 - 00000000 __RHD () C:\Users\Default 2014-04-04 12:00 - 2014-04-04 11:37 - 00000000 ____D () C:\Windows\erdnt 2014-04-04 11:59 - 2006-11-02 14:34 - 00000215 _____ () C:\Windows\system.ini 2014-04-04 11:34 - 2014-04-04 11:34 - 05193944 ____R (Swearware) C:\Users\Michaela\Desktop\ComboFix.exe 2014-04-04 11:26 - 2014-03-29 15:21 - 00000808 _____ () C:\Windows\system32\spsys.log 2014-04-04 00:17 - 2009-10-02 19:11 - 00000000 ____D () C:\Users\Michaela 2014-04-03 23:53 - 2013-11-04 21:01 - 00000000 ____D () C:\Users\Michaela\Documents\Nitro+Chiral 2014-04-03 21:50 - 2009-10-22 16:40 - 00119808 _____ () C:\Users\Michaela\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-04-03 19:39 - 2014-04-03 19:39 - 00000000 ____D () C:\Users\Michaela\Documents\Bluetooth-Exchange-Ordner 2014-04-03 19:38 - 2014-04-03 19:38 - 00000000 ____D () C:\Users\Michaela\Documents\Amazon MP3 2014-04-03 15:32 - 2014-04-03 15:32 - 00000000 ____D () C:\Users\Michaela\Documents\Tumblr 2014-04-03 15:32 - 2013-11-04 21:49 - 00000000 ____D () C:\Users\Michaela\Documents\Durarara!! 2014-04-03 15:30 - 2014-03-14 03:20 - 00000000 ____D () C:\Users\Michaela\Documents\HTML Code 2014-04-03 15:30 - 2012-01-22 18:59 - 00000000 ____D () C:\Users\Michaela\Documents\Nintendo 2014-04-03 15:24 - 2009-10-07 15:42 - 00000000 ____D () C:\Users\Michaela\Documents\Dell WebCam Central 2014-04-03 15:21 - 2013-12-21 23:24 - 00000000 ____D () C:\Users\Michaela\Documents\Facebook 2014-04-03 09:51 - 2014-04-05 13:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-05 13:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-05 13:51 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-01 12:40 - 2009-09-25 04:04 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-04-01 12:34 - 2014-04-01 12:33 - 02157056 _____ (Farbar) C:\Users\Michaela\Desktop\FRST64.exe 2014-04-01 12:28 - 2009-10-03 13:07 - 00000000 ____D () C:\Users\Michaela\AppData\Roaming\Adobe 2014-04-01 12:27 - 2009-09-25 04:05 - 00000000 ____D () C:\ProgramData\Adobe 2014-04-01 12:15 - 2009-10-02 19:12 - 00080160 _____ () C:\Users\Michaela\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-01 12:11 - 2006-11-02 17:21 - 02247192 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-01 12:07 - 2009-09-25 04:00 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-03-29 15:21 - 2012-10-11 19:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 15:18 - 2013-06-04 18:00 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-03-29 15:08 - 2014-03-29 15:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-29 15:03 - 2014-03-29 15:02 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-03-29 15:03 - 2009-09-25 03:57 - 00000000 ____D () C:\Program Files (x86)\Java 2014-03-29 14:59 - 2012-10-22 15:28 - 00000000 ____D () C:\Users\Michaela\AppData\Local\Opera 2014-03-29 14:59 - 2012-10-22 15:28 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-03-29 14:56 - 2014-03-29 14:56 - 00000000 ____D () C:\Users\Michaela\AppData\Roaming\Opera Software 2014-03-29 14:56 - 2014-03-29 14:56 - 00000000 ____D () C:\Users\Michaela\AppData\Local\Opera Software 2014-03-29 14:45 - 2014-03-29 14:44 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-03-29 14:27 - 2014-03-29 14:27 - 00000000 ____D () C:\Users\Michaela\AppData\Roaming\AVAST Software 2014-03-29 14:25 - 2014-03-29 14:25 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-03-29 14:25 - 2014-03-29 14:25 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-03-29 14:25 - 2014-03-29 14:25 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-03-29 14:25 - 2014-03-29 14:25 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-03-29 14:25 - 2014-03-29 14:25 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-03-29 14:25 - 2014-03-29 14:25 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-03-29 14:25 - 2014-03-29 14:25 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2014-03-29 14:25 - 2014-03-29 14:25 - 00064752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr.sys 2014-03-29 14:25 - 2014-03-29 14:25 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-03-29 14:23 - 2014-03-29 14:23 - 00000000 ____D () C:\Program Files\AVAST Software 2014-03-29 14:20 - 2014-03-29 14:20 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-03-29 14:12 - 2014-03-03 19:28 - 00003352 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2157045702-3999625576-2718192899-1000 2014-03-29 14:12 - 2014-03-03 16:55 - 00003224 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2157045702-3999625576-2718192899-1000 2014-03-29 13:27 - 2013-05-02 22:19 - 00138184 ____H () C:\Windows\SysWOW64\mlfcache.dat 2014-03-28 23:21 - 2014-03-04 21:52 - 00003714 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{784B2923-D700-4DE6-920C-72A8F8621F24} 2014-03-27 22:55 - 2014-03-19 20:46 - 00003246 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2157045702-3999625576-2718192899-1000 2014-03-27 22:55 - 2014-03-19 20:45 - 00003374 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2157045702-3999625576-2718192899-1000 2014-03-27 15:41 - 2012-10-10 20:49 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-27 15:41 - 2012-10-10 20:49 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-19 12:57 - 2013-08-15 03:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-19 12:54 - 2006-11-02 14:35 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-03-16 02:49 - 2014-03-16 02:49 - 00000000 ____D () C:\Users\Michaela\AppData\Local\Skype 2014-03-16 02:49 - 2013-03-28 23:50 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-16 02:49 - 2013-03-28 23:50 - 00000000 ____D () C:\ProgramData\Skype 2014-03-13 11:01 - 2006-11-02 15:33 - 00000000 ____D () C:\Windows\rescache 2014-03-12 12:34 - 2012-08-15 22:10 - 00003738 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-12 12:34 - 2012-04-03 21:15 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 12:34 - 2011-11-06 12:37 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 15:43 ==================== End Of Log ============================ Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014 Ran by Michaela at 2014-04-09 15:45:54 Running from C:\Users\Michaela\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Disabled - Out of date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Disabled - Out of date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader X (10.1.9) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.9 - Adobe Systems Incorporated) Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd) Amazon MP3-Downloader 1.0.18 (HKCU\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC) Any Video Converter 5.0.5 (HKLM-x32\...\Any Video Converter_is1) (Version: - Any-Video-Converter.com) Apple Application Support (HKLM-x32\...\{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}) (Version: 2.1.7 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Audacity 2.0.3 (HKLM-x32\...\Audacity_is1) (Version: 2.0.3 - Audacity Team) avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2016 - Avast Software) Bing Bar (HKLM-x32\...\{B4089055-D468-45A4-A6BA-5A138DD715FC}) (Version: 7.0.850.0 - Microsoft Corporation) Choice Guard (x32 Version: 1.2.87.0 - Microsoft Corporation) Hidden Cisco EAP-FAST Module (HKLM-x32\...\{415B2719-AD3A-4944-B404-C472DB6085B3}) (Version: 2.1.6 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{83770D14-21B9-44B3-8689-F7B523F94560}) (Version: 1.0.12 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}) (Version: 1.0.13 - Cisco Systems, Inc.) Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Dell DataSafe Local Backup - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 2.25 - Dell) Dell DataSafe Local Backup (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.3.24 - Dell) Dell DataSafe Online (HKLM-x32\...\{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}) (Version: 1.1.0029 - Dell, Inc.) Dell Dock (HKLM\...\{E60B7350-EA5F-41E0-9D6F-E508781E36D2}) (Version: 2.0.0 - Dell) Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc) Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.) Dell Support Center (Support Software) (HKLM-x32\...\{E3BFEE55-39E2-4BE0-B966-89FE583822C1}) (Version: 2.5.09100 - Dell) Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.104.115.101 - Alps Electric) Dell Video Chat (HKLM-x32\...\Dell Video Chat) (Version: 6.1 (6751) - SightSpeed Inc.) Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 1.20.10 - Creative Technology Ltd) Dell Wireless WLAN Card Utility (HKLM\...\Broadcom 802.11 Application) (Version: 5.10.38.30 - Dell Inc.) Dropbox (HKCU\...\Dropbox) (Version: 2.4.11 - Dropbox, Inc.) Facebook Messenger 2.1.4814.0 (HKLM-x32\...\{7204BDEE-1A48-4D95-A964-44A9250B439E}) (Version: 2.1.4814.0 - Facebook) Free Audio Converter version 5.0.3.1206 (HKLM-x32\...\Free Audio Converter_is1) (Version: - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.154 - Google Inc.) Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden Integrated Webcam Driver (1.02.01.0320) (HKLM\...\Creative OA009) (Version: 1.02.01.0320 - Creative Technology Ltd.) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 13 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416013FF}) (Version: 6.0.130 - Sun Microsystems, Inc.) Java(TM) 6 Update 13 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216013FF}) (Version: 6.0.130 - Sun Microsystems, Inc.) Junk Mail filter update (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden LG PC Suite II (HKLM-x32\...\{14DCD95A-EBA3-4BF0-B7EF-533852E99BE6}) (Version: 2.00.0000 - LG PC Suite) LG PC Suite II (x32 Version: 2.00.0000 - LG PC Suite) Hidden LG USB Modem driver (HKLM-x32\...\{C3ABE126-2BB2-4246-BFE1-6797679B3579}) (Version: 4.9.2 - LG Electronics) Live! Cam Avatar Creator (HKLM-x32\...\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.2303.1 - Creative Technology Ltd) Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Default Manager (HKLM-x32\...\{095B1DCF-5E8B-47EC-9B18-481918A731DB}) (Version: 2.0.69.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint Viewer 2007 (German) (HKLM-x32\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM-x32\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (HKLM-x32\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM-x32\...\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}) (Version: 8.0.58299 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM-x32\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Opera Stable 20.0.1387.82 (HKLM-x32\...\Opera 20.0.1387.82) (Version: 20.0.1387.82 - Opera Software ASA) PowerDVD DX (HKLM-x32\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 8.2.5024 - Dell Corp.) Quickset (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 9.2.18 - Dell Inc.) QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) RealDownloader (x32 Version: 1.3.3 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden Roxio Creator Audio (x32 Version: 3.7.0 - Roxio) Hidden Roxio Creator Copy (x32 Version: 3.7.0 - Roxio) Hidden Roxio Creator Data (x32 Version: 3.7.0 - Roxio) Hidden Roxio Creator DE (HKLM-x32\...\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}) (Version: 10.1 - Roxio) Roxio Creator DE (x32 Version: 3.7.0 - Roxio) Hidden Roxio Creator Tools (x32 Version: 3.7.0 - Roxio) Hidden Roxio Express Labeler 3 (x32 Version: 3.2.1 - Roxio) Hidden Roxio Update Manager (x32 Version: 6.0.0 - Roxio) Hidden Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Synthesia (HKLM-x32\...\Synthesia) (Version: 8.4 - Synthesia LLC) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) WIDCOMM Bluetooth Software (HKLM\...\{6E7F4CA3-B2DE-413C-A7A1-43AA5BE19EA1}) (Version: 6.5.0.2000 - WIDCOMM, Inc.) Windows Live Anmelde-Assistent (HKLM-x32\...\{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}) (Version: 5.000.818.6 - Microsoft Corporation) Windows Live Call (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8050.1202 - Microsoft Corporation) Windows Live Essentials (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 14.0.8051.1204 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Sync (HKLM-x32\...\{8C1E2925-14F8-45AA-B999-1E2A74BF5607}) (Version: 14.0.8050.1202 - Microsoft Corporation) Windows Live Writer (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.) Yahoo! Software Update (HKLM-x32\...\Yahoo! Software Update) (Version: - ) Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version: - Yahoo! Inc.) ==================== Restore Points ========================= 31-03-2014 08:45:44 Geplanter Prüfpunkt 01-04-2014 09:20:00 Windows Update 01-04-2014 10:06:47 削除済み 咎狗の血 02-04-2014 16:47:57 Geplanter Prüfpunkt 04-04-2014 10:54:30 Geplanter Prüfpunkt 04-04-2014 14:40:32 Windows Update 05-04-2014 14:32:27 Geplanter Prüfpunkt 06-04-2014 13:04:06 Geplanter Prüfpunkt 08-04-2014 15:43:10 Windows Update ==================== Hosts content: ========================== 2006-11-02 14:34 - 2014-04-04 11:59 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {19BCA020-F0B4-4C5B-A57C-CF09E3EF4781} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2157045702-3999625576-2718192899-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {254095AE-FB97-48EA-94A5-D8BF2AB79714} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {2A429D84-C847-4D6B-9502-3D35AC976676} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2157045702-3999625576-2718192899-1000UA => C:\Users\Michaela\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-11] (Facebook Inc.) Task: {2EB14C14-2C5F-4626-BA90-D9196121F7AE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: {36A56C1C-9BEA-44D8-94FD-62456F325528} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2157045702-3999625576-2718192899-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {388C0D7F-DC58-437E-812B-4BE3674FBB6D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {46CD1E8E-C415-4159-AE4E-F1ED803AFE8A} - System32\Tasks\Launch BCM WLAN Tray => C:\Windows\system32\WLTRAY.EXE [2008-12-21] (Dell Inc.) Task: {55C81DE2-89F3-4B72-84BD-1B91CA453711} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2157045702-3999625576-2718192899-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {5ABD53F8-82CF-4CD6-93BC-810C5612C7A7} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation) Task: {7133A15E-30E1-43F9-8C91-1F2CA85D8470} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2157045702-3999625576-2718192899-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {7C638E5B-ECE5-4424-A7E5-2C913CA682E9} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {87E7CBB4-22BF-4BC1-BEC9-3CF65F0B7BE3} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2157045702-3999625576-2718192899-1000Core => C:\Users\Michaela\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-11] (Facebook Inc.) Task: {A5EC54B9-100A-4D35-9901-99A32AF722CF} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2157045702-3999625576-2718192899-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {B2E92356-AF15-46C2-9760-3E810CEBBD3A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-10] (Google Inc.) Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {EB167214-C513-42A7-9F0B-69BE18A83294} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-03-29] (AVAST Software) Task: {F5F46528-E855-4E3F-A3B0-5623AE50F8CB} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2157045702-3999625576-2718192899-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {F6BFCBD6-889A-48E7-9943-27C9D6B5854A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-10] (Google Inc.) Task: {FC41EBBD-8B04-47C7-B2AD-F6C2BEC1A210} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-2157045702-3999625576-2718192899-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2013-08-14] (RealNetworks, Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2157045702-3999625576-2718192899-1000Core.job => C:\Users\Michaela\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2157045702-3999625576-2718192899-1000UA.job => C:\Users\Michaela\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2009-09-25 03:57 - 2008-12-21 20:35 - 00032768 _____ () C:\Windows\System32\WLTRYSVC.EXE 2009-09-25 03:57 - 2008-12-21 20:35 - 00057856 _____ () C:\Windows\System32\bcmwlrmt.dll 2013-08-14 15:19 - 2013-08-14 15:19 - 00039056 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe 2009-09-25 04:12 - 2009-04-24 21:52 - 00156912 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe 2009-09-25 04:11 - 2009-07-16 18:00 - 00410864 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe 2013-05-22 20:50 - 2013-05-22 20:50 - 00400704 _____ () C:\Users\Michaela\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe 2014-03-04 07:50 - 2014-03-04 07:50 - 00472576 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_64\VistaBridgeLibrary\264c91e0ec39698f61d36c00a26cc16b\VistaBridgeLibrary.ni.dll 2009-07-07 17:23 - 2009-07-07 17:23 - 01779952 _____ () C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe 2014-04-09 15:32 - 2014-04-09 15:32 - 02192384 _____ () C:\Program Files\AVAST Software\Avast\defs\14040901\algo.dll 2009-09-25 04:11 - 2009-07-16 17:58 - 00115952 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\PSTVdsDisk.dll 2009-09-25 04:11 - 2009-07-16 17:59 - 00128240 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll 2009-09-25 04:11 - 2009-07-16 17:58 - 01123568 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\LibXml2.dll 2009-09-25 04:11 - 2009-07-16 17:59 - 00079088 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll 2009-09-25 04:11 - 2009-07-16 17:59 - 00234736 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll 2009-09-25 04:11 - 2009-07-16 17:59 - 00074992 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll 2009-09-25 04:11 - 2009-07-16 17:59 - 00111856 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll 2009-09-25 04:11 - 2009-07-16 17:59 - 00121072 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll 2009-07-07 17:24 - 2009-07-07 17:24 - 00268528 _____ () C:\Program Files (x86)\Dell DataSafe Online\SdbShared.dll 2009-07-07 17:23 - 2009-07-07 17:23 - 00058608 _____ () C:\Program Files (x86)\Dell DataSafe Online\BalloonWindow.dll 2009-07-07 17:24 - 2009-07-07 17:24 - 00095472 _____ () C:\Program Files (x86)\Dell DataSafe Online\SdbUI.dll 2009-07-07 17:24 - 2009-07-07 17:24 - 00046320 _____ () C:\Program Files (x86)\Dell DataSafe Online\de\SdbUI.resources.dll 2009-07-07 17:24 - 2009-07-07 17:24 - 00369904 _____ () C:\Program Files (x86)\Dell DataSafe Online\de\DataSafeOnline.resources.dll 2009-07-07 17:24 - 2009-07-07 17:24 - 00140528 _____ () C:\Program Files (x86)\Dell DataSafe Online\SdbShared.XmlSerializers.dll 2009-07-07 17:23 - 2009-07-07 17:23 - 00017648 _____ () C:\Program Files (x86)\Dell DataSafe Online\cpputils.dll 2014-03-29 14:25 - 2014-03-29 14:25 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2013-10-19 01:55 - 2013-10-19 01:55 - 25100288 _____ () C:\Users\Michaela\AppData\Roaming\Dropbox\bin\libcef.dll 2014-03-15 21:47 - 2014-03-15 02:50 - 00051016 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\chrome_elf.dll 2014-03-15 21:47 - 2014-03-15 02:50 - 04061000 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll 2014-03-15 21:47 - 2014-03-15 02:50 - 00394568 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll 2014-03-15 21:47 - 2014-03-15 02:50 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/09/2014 03:32:20 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/08/2014 05:23:47 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/08/2014 01:09:23 PM) (Source: Swapdrive Backup) (User: ) Description: Swapdrive Backup: Web Service Error: System.Net.WebException: Der Remotename konnte nicht aufgelöst werden: 'wsvcdell.backup.com' bei System.Net.HttpWebRequest.GetRequestStream(TransportContext& context) bei System.Net.HttpWebRequest.GetRequestStream() bei System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String methodName, Object[] parameters) bei Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest req) bei Swapdrive.Shared.ActivationWsvcs.GetInfo() Error: (04/08/2014 01:05:44 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/08/2014 01:03:00 PM) (Source: EventSystem) (User: ) Description: 80070005EventSystem.EventSubscription{AA44355E-6911-4447-BA5D-6720480579AF}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000} Error: (04/08/2014 00:27:22 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/07/2014 05:27:26 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen bereits aktiven Komponentenversion. Die widersprüchlichen Komponenten sind: Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest. Error: (04/07/2014 05:11:48 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen bereits aktiven Komponentenversion. Die widersprüchlichen Komponenten sind: Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest. Error: (04/07/2014 02:56:49 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen bereits aktiven Komponentenversion. Die widersprüchlichen Komponenten sind: Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest. Error: (04/07/2014 02:56:32 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen bereits aktiven Komponentenversion. Die widersprüchlichen Komponenten sind: Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest. System errors: ============= Error: (04/09/2014 03:46:33 PM) (Source: Service Control Manager) (User: ) Description: Google Update-Dienst (gupdate)%%1053 Error: (04/09/2014 03:46:33 PM) (Source: Service Control Manager) (User: ) Description: 30000Google Update-Dienst (gupdate) Error: (04/09/2014 03:46:33 PM) (Source: DCOM) (User: ) Description: 1053gupdate/comsvc{4EB61BAC-A3B6-4760-9581-655041EF4D69} Error: (04/09/2014 03:35:49 PM) (Source: Service Control Manager) (User: ) Description: 30000Microsoft .NET Framework NGEN v4.0.30319_X86 Error: (04/09/2014 03:34:01 PM) (Source: Service Control Manager) (User: ) Description: Beep Error: (04/09/2014 03:33:18 PM) (Source: Service Control Manager) (User: ) Description: Bluetooth Service Error: (04/09/2014 03:32:20 PM) (Source: Service Control Manager) (User: ) Description: Intel(R) PRO/1000 NDIS 6 Adapter Driver%%1058 Error: (04/09/2014 03:32:20 PM) (Source: Service Control Manager) (User: ) Description: Intel(R) PRO/1000 PCI Express-Netzwerkverbindungstreiber%%1058 Error: (04/09/2014 03:32:20 PM) (Source: Service Control Manager) (User: ) Description: Bluetooth-Gerät (PAN)%%1058 Error: (04/08/2014 05:26:17 PM) (Source: VDS Dynamic Provider) (User: ) Description: Der Anbieter konnte Benachrichtigungen nicht speichern, die vom Treiber stammen. Der Dienst für virtuelle Datenträger muss neu gestartet werden. hr=80042505 Microsoft Office Sessions: ========================= Error: (05/27/2013 11:18:45 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 12395 seconds with 6840 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-04-09 15:45:42.833 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-09 15:45:42.151 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-09 15:45:41.480 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-09 15:45:40.821 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-09 15:45:40.086 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-09 15:45:39.442 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-09 15:45:38.773 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-09 15:45:38.102 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-09 15:34:00.568 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-08 22:46:58.599 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 58% Total physical RAM: 4055.45 MB Available physical RAM: 1703.08 MB Total Pagefile: 8288.18 MB Available Pagefile: 5332.13 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:283.4 GB) (Free:116.74 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive e: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:6.38 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 298 GB) (Disk ID: 7F8F3E8E) Partition 1: (Not Active) - (Size=39 MB) - (Type=DE) Partition 2: (Not Active) - (Size=15 GB) - (Type=07 NTFS) Partition 3: (Active) - (Size=283 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Bis auf den langsamen Systemstart ist alles soweit in Ordnung denke ich. Die Meldung bezüglich dass mein System mit der Darstellung Probleme hat kam nicht mehr. |
10.04.2014, 09:34 | #19 |
/// the machine /// TB-Ausbilder | Wie kann ich Daten sichern da MusikTrojaner vermutet Deinstalliere mal Avast und teste den Systemstart nochmal.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.04.2014, 14:36 | #20 |
| Wie kann ich Daten sichern da MusikTrojaner vermutet Ok, hab Avast deinstalliert und wieder installiert. Nach der Deinstallation hab ich den Laptop neu gestartet und es genauso lang gedauert. Deswegen Avast wieder direkt installiert. Für den Download hab ich mich diesmal bei Avast direkt umgeschaut. Wenn man allerdings die Freeware möchte (Avast Free) dann schickt die Avast Homepage einen zu Computerbild mit einem Direktlink. Hab das dort dann runtergeladen und wieder installiert. Hab jetz schonmal nen neuen FRST Scan gemacht (nach Neuinstallation von avast) weil ich natürlich jetzt beim Download bis auf Malewarebytes komplett ohne Schutz war. Hoffe da ist jetzt nichts passiert. Wie gesagt, auch ohne Avast dauert das hochfahren sehr lange. Und was ich noch gefunden hab: In meinem Download Ordner ist eine Datei namens FCAC.tmp. Wenn ich drüberhover sehe ich dass diese Datei wohl schon länger da ist und zwar seit 10.12.13 (ist mir aber noch nie aufgefallen). Soll/Kann ich die löschen? Oder lieber in Ruhe lassen? FRST: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 (ATTENTION: ====> FRST version is 29 days old and could be outdated) Ran by Michaela (administrator) on MICHAELA-PC on 11-04-2014 15:00:58 Running from C:\Users\Michaela\Desktop Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe () C:\Windows\System32\WLTRYSVC.EXE (Dell Inc.) C:\Windows\System32\bcmwltry.exe (Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe (SoftThinks) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Microsoft Corporation) C:\Windows\system32\conime.exe () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Dell Inc.) C:\Windows\System32\WLTRAY.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe () C:\Users\Michaela\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe (CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (SupportSoft, Inc.) C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (Dropbox, Inc.) C:\Users\Michaela\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe (SupportSoft, Inc.) C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastUi.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [305664 2009-03-31] (Alps Electric Co., Ltd.) HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\Windows\system32\WLTRAY.exe [4119552 2008-12-21] (Dell Inc.) HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [178712 2008-06-15] (Intel Corporation) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [462848 2009-03-31] (IDT, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Dell DataSafe Online] - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe [1779952 2009-07-07] () HKLM-x32\...\Run: [Microsoft Default Manager] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [250192 2009-04-24] (Microsoft Corporation) HKLM-x32\...\Run: [PDVDDXSrv] - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [128232 2009-02-05] (CyberLink Corp.) HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [405639 2009-01-09] (Creative Technology Ltd) HKLM-x32\...\Run: [DellSupportCenter] - C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe [206064 2009-05-21] (SupportSoft, Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2012-02-20] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512 2013-09-19] (RealNetworks, Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-04-11] (AVAST Software) HKLM\...\RunOnce: [DSUpdateLauncher] - "c:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\runhstart.bat" [374 2009-03-09] () HKLM-x32\...\RunOnce: [Launcher] - "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe" [165104 2009-07-16] (Softthinks) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2157045702-3999625576-2718192899-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [138240 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-2157045702-3999625576-2718192899-1000\...\Run: [AmazonMP3DownloaderHelper] - C:\Users\Michaela\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] () Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Michaela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Michaela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Michaela\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank URLSearchHook: HKCU - YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File URLSearchHook: HKCU - YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: ProxTube - {0AA2810A-F009-4BD7-A10A-32F140A1B9F3} - C:\Users\Michaela\AppData\LocalLow\ProxTube\IE\ProxTube.dll (Malte Goetz) BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Michaela\AppData\Roaming\Mozilla\Firefox\Profiles\ighg0d3g.default FF NewTab: about:blank FF Homepage: about:home FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*'))%20%7B%20return%20'PROXY%20nq-us04.personalitycores.com%3A8000%3B%20PROXY%20nq-us05.personalitycores.com%3A8000%3B%20PROXY%20nq-us08.personalitycores.com%3A8000%3B%20PROXY%20nq-us09.personalitycores.com%3A8000%3B%20PROXY%20nq-us10.personalitycores.com%3A8000%3B%20PROXY%20nq-us11.personalitycores.com%3A8000%3B%20PROXY%20nq-us07.personalitycores.com%3A8000%3B%20PROXY%20nq-us12.personalitycores.com%3A8000%3B%20PROXY%20nq-us06.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF NetworkProxy: "type", 2 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Michaela\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Michaela\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - C:\Users\Michaela\AppData\Roaming\Mozilla\Firefox\Profiles\ighg0d3g.default\Extensions\maltegoetz@proxtube.com [2012-11-08] FF Extension: ProxMate - Proxy on steroids! - C:\Users\Michaela\AppData\Roaming\Mozilla\Firefox\Profiles\ighg0d3g.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-08-17] FF Extension: Adblock Plus - C:\Users\Michaela\AppData\Roaming\Mozilla\Firefox\Profiles\ighg0d3g.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-28] FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-04-11] Chrome: ======= CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=97c644c5-ac6a-452e-b40f-ec9598ff936e&searchtype=hp&installDate=02/06/2013 CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll () CHR Plugin: (Java(TM) Platform SE 6 U13) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll No File CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll No File CHR Plugin: (Adobe Acrobat) - c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer Download Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Plugin: (RealJukebox NS Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll No File CHR Extension: (Boa Mistura) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\alhbnbjlmhkpfeocomgpfkffnbncjjpn [2013-08-08] CHR Extension: (YouTube) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-10-10] CHR Extension: (Adblock Plus) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-12-28] CHR Extension: (Google-Suche) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-10-10] CHR Extension: (Google+) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm [2013-08-08] CHR Extension: (XKit) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpfgeeomkfdefkckijiabdbogjkdaecd [2014-01-11] CHR Extension: (avast! Online Security) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-04-11] CHR Extension: (ProxMate - Proxy on steroids!) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgjpnmnpjmabddgmjdiaggacbololbjm [2013-08-17] CHR Extension: (Google Keep) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2013-09-20] CHR Extension: (RealDownloader) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-09-20] CHR Extension: (Dropbox) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2013-08-08] CHR Extension: (Google Wallet) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01] CHR Extension: (Youtube Video Downloader) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\obmbipnhbnpicpechoajlkjfdiopnoki [2013-05-19] CHR Extension: (Tumblr Savior) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefddkjnflmjbclpnnoegglmmdfkidip [2014-01-05] CHR Extension: (Google Mail) - C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-10-10] CHR HKLM-x32\...\Chrome\Extension: [chakodcglgpacmjpjfaoopegbglbollk] - C:\Users\Michaela\AppData\LocalLow\ProxTube\CHROME\ProxTube.crx [2010-05-25] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-04-11] CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14] ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-11] (AVAST Software) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] () R2 wltrysvc; C:\Windows\System32\bcmwltry.exe [3051520 2008-12-21] (Dell Inc.) R2 yksvc; RUNDLL32.EXE ykx64coinst,serviceStartProc [X] ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2008-01-21] (Microsoft Corporation) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-11] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [64752 2014-04-11] (AVAST Software) S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-11] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-04-11] (AVAST Software) S1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-04-11] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2014-04-11] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208928 2014-04-11] () R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [133672 2011-08-04] (Broadcom Corporation.) S1 Beep; No ImagePath R3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [89640 2011-08-04] (Broadcom Corporation.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-11] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) R3 OA009Ufd; C:\Windows\System32\DRIVERS\OA009Ufd.sys [159840 2009-03-06] (Creative Technology Ltd.) R3 OA009Vid; C:\Windows\System32\DRIVERS\OA009Vid.sys [311296 2009-03-19] (Creative Technology Ltd.) S3 usbbus; C:\Windows\System32\DRIVERS\lgx64bus.sys [17920 2008-09-04] (LG Electronics Inc.) S3 UsbDiag; C:\Windows\System32\DRIVERS\lgx64diag.sys [27136 2008-09-04] (LG Electronics Inc.) S3 USBModem; C:\Windows\System32\DRIVERS\lgx64modem.sys [33792 2008-09-04] (LG Electronics Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-11 15:00 - 2014-04-11 15:01 - 00028261 _____ () C:\Users\Michaela\Desktop\FRST.txt 2014-04-11 14:45 - 2014-04-11 14:45 - 00000000 ____D () C:\Users\Michaela\AppData\Roaming\AVAST Software 2014-04-11 14:44 - 2014-04-11 14:44 - 00003838 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-04-11 14:44 - 2014-04-11 14:44 - 00001831 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-04-11 14:43 - 2014-04-11 14:42 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-04-11 14:43 - 2014-04-11 14:42 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-04-11 14:43 - 2014-04-11 14:42 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-04-11 14:43 - 2014-04-11 14:42 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-04-11 14:43 - 2014-04-11 14:42 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-04-11 14:43 - 2014-04-11 14:42 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2014-04-11 14:42 - 2014-04-11 14:42 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-04-11 14:42 - 2014-04-11 14:42 - 00064752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr.sys 2014-04-11 14:42 - 2014-04-11 14:42 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-04-11 14:40 - 2014-04-11 14:40 - 00000000 ____D () C:\Program Files\AVAST Software 2014-04-09 16:25 - 2014-03-08 06:54 - 17848832 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 16:25 - 2014-03-08 06:06 - 10926592 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-09 16:25 - 2014-03-08 05:49 - 02334720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-09 16:25 - 2014-03-08 05:41 - 01347072 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-09 16:25 - 2014-03-08 05:40 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-09 16:25 - 2014-03-08 05:39 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-09 16:25 - 2014-03-08 05:38 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-04-09 16:25 - 2014-03-08 05:37 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-09 16:25 - 2014-03-08 05:34 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-04-09 16:25 - 2014-03-08 05:34 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-09 16:25 - 2014-03-08 05:33 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-09 16:25 - 2014-03-08 05:32 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-09 16:25 - 2014-03-08 05:32 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-09 16:25 - 2014-03-08 05:30 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-04-09 16:25 - 2014-03-08 05:29 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 16:25 - 2014-03-08 05:24 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-09 16:25 - 2014-03-08 01:51 - 12347904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 16:25 - 2014-03-08 01:20 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-09 16:25 - 2014-03-08 01:12 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-09 16:25 - 2014-03-08 01:03 - 01105408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-09 16:25 - 2014-03-08 01:02 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-09 16:25 - 2014-03-08 01:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-09 16:25 - 2014-03-08 01:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-04-09 16:25 - 2014-03-08 00:59 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-09 16:25 - 2014-03-08 00:57 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-04-09 16:25 - 2014-03-08 00:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-09 16:25 - 2014-03-08 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-09 16:25 - 2014-03-08 00:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-09 16:25 - 2014-03-08 00:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-09 16:25 - 2014-03-08 00:52 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 16:25 - 2014-03-08 00:52 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-04-09 16:25 - 2014-03-08 00:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-09 15:52 - 2014-02-06 06:21 - 01212416 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 15:52 - 2014-02-06 03:57 - 00861696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-08 12:34 - 2014-04-08 12:34 - 00448512 _____ (OldTimer Tools) C:\Users\Michaela\Desktop\TFC.exe 2014-04-07 17:29 - 2014-04-07 17:29 - 00987442 _____ () C:\Users\Michaela\Desktop\SecurityCheck.exe 2014-04-05 15:00 - 2014-04-05 15:00 - 00000000 ____D () C:\Windows\ERUNT 2014-04-05 14:59 - 2014-04-05 14:59 - 01038974 _____ (Thisisu) C:\Users\Michaela\Desktop\JRT.exe 2014-04-05 14:43 - 2014-04-05 14:46 - 00000000 ____D () C:\AdwCleaner 2014-04-05 14:42 - 2014-04-05 14:42 - 01426178 _____ () C:\Users\Michaela\Desktop\adwcleaner.exe 2014-04-05 14:08 - 2014-04-11 14:29 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-05 13:51 - 2014-04-05 14:11 - 00000943 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-05 13:51 - 2014-04-05 14:11 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-05 13:51 - 2014-04-05 13:51 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-05 13:51 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-05 13:51 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-05 13:51 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-04 12:03 - 2014-04-04 12:03 - 00030914 _____ () C:\ComboFix.txt 2014-04-04 11:38 - 2014-04-04 12:03 - 00000000 ____D () C:\Qoobox 2014-04-04 11:38 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-04-04 11:38 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-04-04 11:38 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-04-04 11:38 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-04-04 11:38 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-04-04 11:38 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-04-04 11:38 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-04-04 11:38 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-04-04 11:37 - 2014-04-04 12:00 - 00000000 ____D () C:\Windows\erdnt 2014-04-04 11:34 - 2014-04-04 11:34 - 05193944 ____R (Swearware) C:\Users\Michaela\Desktop\ComboFix.exe 2014-04-04 00:16 - 2014-04-10 21:47 - 00000000 ___RD () C:\Users\Michaela\Bilder nach Datensicherung vom 03.04.14 2014-04-03 19:39 - 2014-04-03 19:39 - 00000000 ____D () C:\Users\Michaela\Documents\Bluetooth-Exchange-Ordner 2014-04-03 19:38 - 2014-04-03 19:38 - 00000000 ____D () C:\Users\Michaela\Documents\Amazon MP3 2014-04-03 15:32 - 2014-04-03 15:32 - 00000000 ____D () C:\Users\Michaela\Documents\Tumblr 2014-04-01 12:51 - 2014-04-11 15:00 - 00000000 ____D () C:\FRST 2014-04-01 12:33 - 2014-04-01 12:34 - 02157056 _____ (Farbar) C:\Users\Michaela\Desktop\FRST64.exe 2014-03-29 15:21 - 2014-04-04 11:26 - 00000808 _____ () C:\Windows\system32\spsys.log 2014-03-29 15:07 - 2014-03-29 15:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-29 15:03 - 2013-12-18 22:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-03-29 15:03 - 2013-12-18 22:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-03-29 15:03 - 2013-12-18 22:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-03-29 15:03 - 2013-12-18 22:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-03-29 15:02 - 2014-03-29 15:03 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-03-29 14:56 - 2014-03-29 14:56 - 00000000 ____D () C:\Users\Michaela\AppData\Roaming\Opera Software 2014-03-29 14:56 - 2014-03-29 14:56 - 00000000 ____D () C:\Users\Michaela\AppData\Local\Opera Software 2014-03-29 14:44 - 2014-03-29 14:45 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-03-29 14:20 - 2014-04-11 14:39 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-03-19 20:46 - 2014-03-27 22:55 - 00003246 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2157045702-3999625576-2718192899-1000 2014-03-19 20:45 - 2014-03-27 22:55 - 00003374 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2157045702-3999625576-2718192899-1000 2014-03-16 02:49 - 2014-03-16 02:49 - 00000000 ____D () C:\Users\Michaela\AppData\Local\Skype 2014-03-14 03:20 - 2014-04-03 15:30 - 00000000 ____D () C:\Users\Michaela\Documents\HTML Code 2014-03-13 00:48 - 2014-02-07 14:11 - 02776064 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-13 00:48 - 2014-02-03 15:20 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-13 00:48 - 2014-02-03 12:37 - 00505344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-13 00:48 - 2014-01-30 12:12 - 01111040 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-13 00:48 - 2014-01-30 09:46 - 00876032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-13 00:48 - 2013-11-13 03:54 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-03-13 00:48 - 2013-11-13 02:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll ==================== One Month Modified Files and Folders ======= 2014-04-11 15:01 - 2014-04-11 15:00 - 00028261 _____ () C:\Users\Michaela\Desktop\FRST.txt 2014-04-11 15:00 - 2014-04-01 12:51 - 00000000 ____D () C:\FRST 2014-04-11 14:46 - 2012-10-10 20:49 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-11 14:46 - 2012-10-10 20:49 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-11 14:45 - 2014-04-11 14:45 - 00000000 ____D () C:\Users\Michaela\AppData\Roaming\AVAST Software 2014-04-11 14:44 - 2014-04-11 14:44 - 00003838 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-04-11 14:44 - 2014-04-11 14:44 - 00001831 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-04-11 14:42 - 2014-04-11 14:43 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-04-11 14:42 - 2014-04-11 14:43 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-04-11 14:42 - 2014-04-11 14:43 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-04-11 14:42 - 2014-04-11 14:43 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-04-11 14:42 - 2014-04-11 14:43 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-04-11 14:42 - 2014-04-11 14:43 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2014-04-11 14:42 - 2014-04-11 14:42 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-04-11 14:42 - 2014-04-11 14:42 - 00064752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr.sys 2014-04-11 14:42 - 2014-04-11 14:42 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-04-11 14:41 - 2009-09-25 04:11 - 00000000 ____D () C:\Program Files (x86)\Dell DataSafe Local Backup 2014-04-11 14:40 - 2014-04-11 14:40 - 00000000 ____D () C:\Program Files\AVAST Software 2014-04-11 14:39 - 2014-03-29 14:20 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-04-11 14:39 - 2009-09-24 22:31 - 01591507 _____ () C:\Windows\WindowsUpdate.log 2014-04-11 14:34 - 2012-08-15 22:10 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-11 14:32 - 2013-07-16 23:39 - 00000000 ___RD () C:\Users\Michaela\Dropbox 2014-04-11 14:32 - 2013-07-16 23:35 - 00000000 ____D () C:\Users\Michaela\AppData\Roaming\Dropbox 2014-04-11 14:30 - 2009-10-02 19:11 - 00000000 ____D () C:\Users\Michaela\AppData\Local\SoftThinks 2014-04-11 14:29 - 2014-04-05 14:08 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-11 14:26 - 2008-01-21 05:26 - 01127100 _____ () C:\Windows\PFRO.log 2014-04-11 14:26 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-11 14:26 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-11 14:26 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-11 14:24 - 2013-02-12 05:26 - 00003549 _____ () C:\Windows\bthservsdp.dat 2014-04-11 14:24 - 2006-11-02 17:42 - 00032530 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-04-11 02:22 - 2013-03-28 23:50 - 00000000 ____D () C:\Users\Michaela\AppData\Roaming\Skype 2014-04-11 01:05 - 2013-03-11 14:00 - 00000940 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2157045702-3999625576-2718192899-1000UA.job 2014-04-10 21:47 - 2014-04-04 00:16 - 00000000 ___RD () C:\Users\Michaela\Bilder nach Datensicherung vom 03.04.14 2014-04-09 16:25 - 2009-09-25 04:18 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-09 16:24 - 2013-08-15 03:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-09 16:22 - 2006-11-02 14:35 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-04-08 13:05 - 2013-03-11 14:00 - 00000918 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2157045702-3999625576-2718192899-1000Core.job 2014-04-08 12:34 - 2014-04-08 12:34 - 00448512 _____ (OldTimer Tools) C:\Users\Michaela\Desktop\TFC.exe 2014-04-07 17:29 - 2014-04-07 17:29 - 00987442 _____ () C:\Users\Michaela\Desktop\SecurityCheck.exe 2014-04-07 14:56 - 2008-01-21 13:10 - 01566076 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-07 14:56 - 2008-01-21 13:09 - 00673932 _____ () C:\Windows\system32\perfh007.dat 2014-04-07 14:56 - 2008-01-21 13:09 - 00145912 _____ () C:\Windows\system32\perfc007.dat 2014-04-07 14:53 - 2006-11-02 17:27 - 00288807 _____ () C:\Windows\setupact.log 2014-04-05 15:00 - 2014-04-05 15:00 - 00000000 ____D () C:\Windows\ERUNT 2014-04-05 14:59 - 2014-04-05 14:59 - 01038974 _____ (Thisisu) C:\Users\Michaela\Desktop\JRT.exe 2014-04-05 14:46 - 2014-04-05 14:43 - 00000000 ____D () C:\AdwCleaner 2014-04-05 14:42 - 2014-04-05 14:42 - 01426178 _____ () C:\Users\Michaela\Desktop\adwcleaner.exe 2014-04-05 14:11 - 2014-04-05 13:51 - 00000943 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-05 14:11 - 2014-04-05 13:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-05 13:51 - 2014-04-05 13:51 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-04 12:03 - 2014-04-04 12:03 - 00030914 _____ () C:\ComboFix.txt 2014-04-04 12:03 - 2014-04-04 11:38 - 00000000 ____D () C:\Qoobox 2014-04-04 12:03 - 2006-11-02 15:33 - 00000000 __RHD () C:\Users\Default 2014-04-04 12:00 - 2014-04-04 11:37 - 00000000 ____D () C:\Windows\erdnt 2014-04-04 11:59 - 2006-11-02 14:34 - 00000215 _____ () C:\Windows\system.ini 2014-04-04 11:34 - 2014-04-04 11:34 - 05193944 ____R (Swearware) C:\Users\Michaela\Desktop\ComboFix.exe 2014-04-04 11:26 - 2014-03-29 15:21 - 00000808 _____ () C:\Windows\system32\spsys.log 2014-04-04 00:17 - 2009-10-02 19:11 - 00000000 ____D () C:\Users\Michaela 2014-04-03 23:53 - 2013-11-04 21:01 - 00000000 ____D () C:\Users\Michaela\Documents\Nitro+Chiral 2014-04-03 21:50 - 2009-10-22 16:40 - 00119808 _____ () C:\Users\Michaela\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-04-03 19:39 - 2014-04-03 19:39 - 00000000 ____D () C:\Users\Michaela\Documents\Bluetooth-Exchange-Ordner 2014-04-03 19:38 - 2014-04-03 19:38 - 00000000 ____D () C:\Users\Michaela\Documents\Amazon MP3 2014-04-03 15:32 - 2014-04-03 15:32 - 00000000 ____D () C:\Users\Michaela\Documents\Tumblr 2014-04-03 15:32 - 2013-11-04 21:49 - 00000000 ____D () C:\Users\Michaela\Documents\Durarara!! 2014-04-03 15:30 - 2014-03-14 03:20 - 00000000 ____D () C:\Users\Michaela\Documents\HTML Code 2014-04-03 15:30 - 2012-01-22 18:59 - 00000000 ____D () C:\Users\Michaela\Documents\Nintendo 2014-04-03 15:24 - 2009-10-07 15:42 - 00000000 ____D () C:\Users\Michaela\Documents\Dell WebCam Central 2014-04-03 15:21 - 2013-12-21 23:24 - 00000000 ____D () C:\Users\Michaela\Documents\Facebook 2014-04-03 09:51 - 2014-04-05 13:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-05 13:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-05 13:51 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-01 12:40 - 2009-09-25 04:04 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-04-01 12:34 - 2014-04-01 12:33 - 02157056 _____ (Farbar) C:\Users\Michaela\Desktop\FRST64.exe 2014-04-01 12:28 - 2009-10-03 13:07 - 00000000 ____D () C:\Users\Michaela\AppData\Roaming\Adobe 2014-04-01 12:27 - 2009-09-25 04:05 - 00000000 ____D () C:\ProgramData\Adobe 2014-04-01 12:15 - 2009-10-02 19:12 - 00080160 _____ () C:\Users\Michaela\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-01 12:11 - 2006-11-02 17:21 - 02247192 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-01 12:07 - 2009-09-25 04:00 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-03-29 15:21 - 2012-10-11 19:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 15:18 - 2013-06-04 18:00 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-03-29 15:08 - 2014-03-29 15:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-29 15:03 - 2014-03-29 15:02 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-03-29 15:03 - 2009-09-25 03:57 - 00000000 ____D () C:\Program Files (x86)\Java 2014-03-29 14:59 - 2012-10-22 15:28 - 00000000 ____D () C:\Users\Michaela\AppData\Local\Opera 2014-03-29 14:59 - 2012-10-22 15:28 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-03-29 14:56 - 2014-03-29 14:56 - 00000000 ____D () C:\Users\Michaela\AppData\Roaming\Opera Software 2014-03-29 14:56 - 2014-03-29 14:56 - 00000000 ____D () C:\Users\Michaela\AppData\Local\Opera Software 2014-03-29 14:45 - 2014-03-29 14:44 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-03-29 14:12 - 2014-03-03 19:28 - 00003352 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2157045702-3999625576-2718192899-1000 2014-03-29 14:12 - 2014-03-03 16:55 - 00003224 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2157045702-3999625576-2718192899-1000 2014-03-29 13:27 - 2013-05-02 22:19 - 00138184 ____H () C:\Windows\SysWOW64\mlfcache.dat 2014-03-28 23:21 - 2014-03-04 21:52 - 00003714 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{784B2923-D700-4DE6-920C-72A8F8621F24} 2014-03-27 22:55 - 2014-03-19 20:46 - 00003246 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2157045702-3999625576-2718192899-1000 2014-03-27 22:55 - 2014-03-19 20:45 - 00003374 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2157045702-3999625576-2718192899-1000 2014-03-27 15:41 - 2012-10-10 20:49 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-27 15:41 - 2012-10-10 20:49 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-16 02:49 - 2014-03-16 02:49 - 00000000 ____D () C:\Users\Michaela\AppData\Local\Skype 2014-03-16 02:49 - 2013-03-28 23:50 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-03-16 02:49 - 2013-03-28 23:50 - 00000000 ____D () C:\ProgramData\Skype 2014-03-13 11:01 - 2006-11-02 15:33 - 00000000 ____D () C:\Windows\rescache 2014-03-12 12:34 - 2012-08-15 22:10 - 00003738 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-12 12:34 - 2012-04-03 21:15 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 12:34 - 2011-11-06 12:37 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-11 14:52 ==================== End Of Log ============================ --- --- --- Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014 Ran by Michaela at 2014-04-11 15:02:11 Running from C:\Users\Michaela\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader X (10.1.9) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.9 - Adobe Systems Incorporated) Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd) Amazon MP3-Downloader 1.0.18 (HKCU\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC) Any Video Converter 5.0.5 (HKLM-x32\...\Any Video Converter_is1) (Version: - Any-Video-Converter.com) Apple Application Support (HKLM-x32\...\{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}) (Version: 2.1.7 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Audacity 2.0.3 (HKLM-x32\...\Audacity_is1) (Version: 2.0.3 - Audacity Team) avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2016 - Avast Software) Bing Bar (HKLM-x32\...\{B4089055-D468-45A4-A6BA-5A138DD715FC}) (Version: 7.0.850.0 - Microsoft Corporation) Choice Guard (x32 Version: 1.2.87.0 - Microsoft Corporation) Hidden Cisco EAP-FAST Module (HKLM-x32\...\{415B2719-AD3A-4944-B404-C472DB6085B3}) (Version: 2.1.6 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{83770D14-21B9-44B3-8689-F7B523F94560}) (Version: 1.0.12 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}) (Version: 1.0.13 - Cisco Systems, Inc.) Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Dell DataSafe Local Backup - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 2.25 - Dell) Dell DataSafe Local Backup (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.3.24 - Dell) Dell DataSafe Online (HKLM-x32\...\{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}) (Version: 1.1.0029 - Dell, Inc.) Dell Dock (HKLM\...\{E60B7350-EA5F-41E0-9D6F-E508781E36D2}) (Version: 2.0.0 - Dell) Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc) Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.) Dell Support Center (Support Software) (HKLM-x32\...\{E3BFEE55-39E2-4BE0-B966-89FE583822C1}) (Version: 2.5.09100 - Dell) Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.104.115.101 - Alps Electric) Dell Video Chat (HKLM-x32\...\Dell Video Chat) (Version: 6.1 (6751) - SightSpeed Inc.) Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 1.20.10 - Creative Technology Ltd) Dell Wireless WLAN Card Utility (HKLM\...\Broadcom 802.11 Application) (Version: 5.10.38.30 - Dell Inc.) Dropbox (HKCU\...\Dropbox) (Version: 2.4.11 - Dropbox, Inc.) Facebook Messenger 2.1.4814.0 (HKLM-x32\...\{7204BDEE-1A48-4D95-A964-44A9250B439E}) (Version: 2.1.4814.0 - Facebook) Free Audio Converter version 5.0.3.1206 (HKLM-x32\...\Free Audio Converter_is1) (Version: - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.116 - Google Inc.) Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden Integrated Webcam Driver (1.02.01.0320) (HKLM\...\Creative OA009) (Version: 1.02.01.0320 - Creative Technology Ltd.) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 13 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416013FF}) (Version: 6.0.130 - Sun Microsystems, Inc.) Java(TM) 6 Update 13 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216013FF}) (Version: 6.0.130 - Sun Microsystems, Inc.) Junk Mail filter update (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden LG PC Suite II (HKLM-x32\...\{14DCD95A-EBA3-4BF0-B7EF-533852E99BE6}) (Version: 2.00.0000 - LG PC Suite) LG PC Suite II (x32 Version: 2.00.0000 - LG PC Suite) Hidden LG USB Modem driver (HKLM-x32\...\{C3ABE126-2BB2-4246-BFE1-6797679B3579}) (Version: 4.9.2 - LG Electronics) Live! Cam Avatar Creator (HKLM-x32\...\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.2303.1 - Creative Technology Ltd) Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Default Manager (HKLM-x32\...\{095B1DCF-5E8B-47EC-9B18-481918A731DB}) (Version: 2.0.69.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint Viewer 2007 (German) (HKLM-x32\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM-x32\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (HKLM-x32\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM-x32\...\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}) (Version: 8.0.58299 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM-x32\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Opera Stable 20.0.1387.82 (HKLM-x32\...\Opera 20.0.1387.82) (Version: 20.0.1387.82 - Opera Software ASA) PowerDVD DX (HKLM-x32\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 8.2.5024 - Dell Corp.) Quickset (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 9.2.18 - Dell Inc.) QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) RealDownloader (x32 Version: 1.3.3 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden Roxio Creator Audio (x32 Version: 3.7.0 - Roxio) Hidden Roxio Creator Copy (x32 Version: 3.7.0 - Roxio) Hidden Roxio Creator Data (x32 Version: 3.7.0 - Roxio) Hidden Roxio Creator DE (HKLM-x32\...\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}) (Version: 10.1 - Roxio) Roxio Creator DE (x32 Version: 3.7.0 - Roxio) Hidden Roxio Creator Tools (x32 Version: 3.7.0 - Roxio) Hidden Roxio Express Labeler 3 (x32 Version: 3.2.1 - Roxio) Hidden Roxio Update Manager (x32 Version: 6.0.0 - Roxio) Hidden Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Synthesia (HKLM-x32\...\Synthesia) (Version: 8.4 - Synthesia LLC) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) WIDCOMM Bluetooth Software (HKLM\...\{6E7F4CA3-B2DE-413C-A7A1-43AA5BE19EA1}) (Version: 6.5.0.2000 - WIDCOMM, Inc.) Windows Live Anmelde-Assistent (HKLM-x32\...\{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}) (Version: 5.000.818.6 - Microsoft Corporation) Windows Live Call (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8050.1202 - Microsoft Corporation) Windows Live Essentials (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 14.0.8051.1204 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Sync (HKLM-x32\...\{8C1E2925-14F8-45AA-B999-1E2A74BF5607}) (Version: 14.0.8050.1202 - Microsoft Corporation) Windows Live Writer (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.) Yahoo! Software Update (HKLM-x32\...\Yahoo! Software Update) (Version: - ) Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version: - Yahoo! Inc.) ==================== Restore Points ========================= 01-04-2014 09:20:00 Windows Update 01-04-2014 10:06:47 削除済み 咎狗の血 02-04-2014 16:47:57 Geplanter Prüfpunkt 04-04-2014 10:54:30 Geplanter Prüfpunkt 04-04-2014 14:40:32 Windows Update 05-04-2014 14:32:27 Geplanter Prüfpunkt 06-04-2014 13:04:06 Geplanter Prüfpunkt 08-04-2014 15:43:10 Windows Update 09-04-2014 14:19:57 Windows Update 11-04-2014 12:22:04 avast! antivirus system restore point 11-04-2014 12:39:38 avast! antivirus system restore point ==================== Hosts content: ========================== 2006-11-02 14:34 - 2014-04-04 11:59 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {03BA4908-B28C-4614-8A03-C33865C1B379} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-04-11] (AVAST Software) Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {19BCA020-F0B4-4C5B-A57C-CF09E3EF4781} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2157045702-3999625576-2718192899-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {254095AE-FB97-48EA-94A5-D8BF2AB79714} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {2A429D84-C847-4D6B-9502-3D35AC976676} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2157045702-3999625576-2718192899-1000UA => C:\Users\Michaela\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-11] (Facebook Inc.) Task: {2EB14C14-2C5F-4626-BA90-D9196121F7AE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: {36A56C1C-9BEA-44D8-94FD-62456F325528} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2157045702-3999625576-2718192899-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {388C0D7F-DC58-437E-812B-4BE3674FBB6D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {46CD1E8E-C415-4159-AE4E-F1ED803AFE8A} - System32\Tasks\Launch BCM WLAN Tray => C:\Windows\system32\WLTRAY.EXE [2008-12-21] (Dell Inc.) Task: {55C81DE2-89F3-4B72-84BD-1B91CA453711} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2157045702-3999625576-2718192899-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {5ABD53F8-82CF-4CD6-93BC-810C5612C7A7} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation) Task: {7133A15E-30E1-43F9-8C91-1F2CA85D8470} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2157045702-3999625576-2718192899-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {7C638E5B-ECE5-4424-A7E5-2C913CA682E9} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {87E7CBB4-22BF-4BC1-BEC9-3CF65F0B7BE3} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2157045702-3999625576-2718192899-1000Core => C:\Users\Michaela\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-11] (Facebook Inc.) Task: {A5EC54B9-100A-4D35-9901-99A32AF722CF} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2157045702-3999625576-2718192899-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {B2E92356-AF15-46C2-9760-3E810CEBBD3A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-10] (Google Inc.) Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {F5F46528-E855-4E3F-A3B0-5623AE50F8CB} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2157045702-3999625576-2718192899-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {F6BFCBD6-889A-48E7-9943-27C9D6B5854A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-10] (Google Inc.) Task: {FC41EBBD-8B04-47C7-B2AD-F6C2BEC1A210} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-2157045702-3999625576-2718192899-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2013-08-14] (RealNetworks, Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2157045702-3999625576-2718192899-1000Core.job => C:\Users\Michaela\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2157045702-3999625576-2718192899-1000UA.job => C:\Users\Michaela\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2009-09-25 03:57 - 2008-12-21 20:35 - 00032768 _____ () C:\Windows\System32\WLTRYSVC.EXE 2009-09-25 03:57 - 2008-12-21 20:35 - 00057856 _____ () C:\Windows\System32\bcmwlrmt.dll 2013-08-14 15:19 - 2013-08-14 15:19 - 00039056 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe 2009-09-25 04:11 - 2009-07-16 18:00 - 00410864 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe 2013-05-22 20:50 - 2013-05-22 20:50 - 00400704 _____ () C:\Users\Michaela\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe 2014-03-04 07:50 - 2014-03-04 07:50 - 00472576 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_64\VistaBridgeLibrary\264c91e0ec39698f61d36c00a26cc16b\VistaBridgeLibrary.ni.dll 2009-07-07 17:23 - 2009-07-07 17:23 - 01779952 _____ () C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe 2009-09-25 04:11 - 2009-07-16 17:58 - 00115952 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\PSTVdsDisk.dll 2009-09-25 04:11 - 2009-07-16 17:59 - 00128240 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll 2009-09-25 04:11 - 2009-07-16 17:58 - 01123568 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\LibXml2.dll 2009-09-25 04:11 - 2009-07-16 17:59 - 00079088 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll 2009-09-25 04:11 - 2009-07-16 17:59 - 00234736 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll 2009-09-25 04:11 - 2009-07-16 17:59 - 00074992 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll 2009-09-25 04:11 - 2009-07-16 17:59 - 00111856 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll 2009-09-25 04:11 - 2009-07-16 17:59 - 00121072 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll 2009-07-07 17:24 - 2009-07-07 17:24 - 00268528 _____ () C:\Program Files (x86)\Dell DataSafe Online\SdbShared.dll 2009-07-07 17:23 - 2009-07-07 17:23 - 00058608 _____ () C:\Program Files (x86)\Dell DataSafe Online\BalloonWindow.dll 2009-07-07 17:24 - 2009-07-07 17:24 - 00095472 _____ () C:\Program Files (x86)\Dell DataSafe Online\SdbUI.dll 2009-07-07 17:24 - 2009-07-07 17:24 - 00046320 _____ () C:\Program Files (x86)\Dell DataSafe Online\de\SdbUI.resources.dll 2009-07-07 17:24 - 2009-07-07 17:24 - 00369904 _____ () C:\Program Files (x86)\Dell DataSafe Online\de\DataSafeOnline.resources.dll 2009-07-07 17:24 - 2009-07-07 17:24 - 00140528 _____ () C:\Program Files (x86)\Dell DataSafe Online\SdbShared.XmlSerializers.dll 2009-07-07 17:23 - 2009-07-07 17:23 - 00017648 _____ () C:\Program Files (x86)\Dell DataSafe Online\cpputils.dll 2013-10-19 01:55 - 2013-10-19 01:55 - 25100288 _____ () C:\Users\Michaela\AppData\Roaming\Dropbox\bin\libcef.dll 2014-04-11 14:47 - 2014-04-11 14:47 - 02209792 _____ () C:\Program Files\AVAST Software\Avast\defs\14041100\algo.dll 2014-04-11 14:42 - 2014-04-11 14:42 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2014-04-10 21:02 - 2014-04-02 03:57 - 00065352 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\chrome_elf.dll 2014-04-10 21:02 - 2014-04-02 03:57 - 04081480 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll 2014-04-10 21:02 - 2014-04-02 03:58 - 00390472 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll 2014-04-10 21:02 - 2014-04-02 03:57 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/11/2014 02:28:04 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/11/2014 02:16:44 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (04/11/2014 02:11:32 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/11/2014 02:22:50 AM) (Source: EventSystem) (User: ) Description: 80070005EventSystem.EventSubscription{AA44355E-6911-4447-BA5D-6720480579AF}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000} Error: (04/11/2014 00:43:58 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\MICHAELA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PREFERENCES> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (04/11/2014 00:43:58 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\MICHAELA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PREFERENCES> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (04/10/2014 08:13:54 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (04/10/2014 08:10:27 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/09/2014 04:49:36 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/09/2014 04:36:17 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (04/11/2014 02:31:07 PM) (Source: Service Control Manager) (User: ) Description: 30000Microsoft .NET Framework NGEN v4.0.30319_X86 Error: (04/11/2014 02:28:37 PM) (Source: Service Control Manager) (User: ) Description: Beep Error: (04/11/2014 02:28:37 PM) (Source: Service Control Manager) (User: ) Description: Bluetooth Service Error: (04/11/2014 02:28:04 PM) (Source: Service Control Manager) (User: ) Description: Intel(R) PRO/1000 NDIS 6 Adapter Driver%%1058 Error: (04/11/2014 02:28:04 PM) (Source: Service Control Manager) (User: ) Description: Intel(R) PRO/1000 PCI Express-Netzwerkverbindungstreiber%%1058 Error: (04/11/2014 02:28:04 PM) (Source: Service Control Manager) (User: ) Description: Bluetooth-Gerät (PAN)%%1058 Error: (04/11/2014 02:14:10 PM) (Source: Service Control Manager) (User: ) Description: Beep Error: (04/11/2014 02:12:34 PM) (Source: Service Control Manager) (User: ) Description: Bluetooth Service Error: (04/11/2014 02:11:32 PM) (Source: Service Control Manager) (User: ) Description: Intel(R) PRO/1000 NDIS 6 Adapter Driver%%1058 Error: (04/11/2014 02:11:32 PM) (Source: Service Control Manager) (User: ) Description: Intel(R) PRO/1000 PCI Express-Netzwerkverbindungstreiber%%1058 Microsoft Office Sessions: ========================= Error: (05/27/2013 11:18:45 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 12395 seconds with 6840 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-04-11 15:02:02.442 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-11 15:02:01.834 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-11 15:02:01.241 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-11 15:02:00.570 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-11 15:01:59.915 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-11 15:01:59.322 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-11 15:01:58.605 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-11 15:01:57.903 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-11 14:29:26.142 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-11 14:14:08.943 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 54% Total physical RAM: 4055.45 MB Available physical RAM: 1853.82 MB Total Pagefile: 8288.18 MB Available Pagefile: 5690.34 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:283.4 GB) (Free:115.85 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive e: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:6.38 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 298 GB) (Disk ID: 7F8F3E8E) Partition 1: (Not Active) - (Size=39 MB) - (Type=DE) Partition 2: (Not Active) - (Size=15 GB) - (Type=07 NTFS) Partition 3: (Active) - (Size=283 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
12.04.2014, 20:00 | #21 |
| Wie kann ich Daten sichern da MusikTrojaner vermutet Ach und ein Problem gibt es noch mit dem System. Obwohl ich nichts mache außer ein bisschen auf den mir bekannten websites zu surfen (tumblr, facebook, google, googlemail, dict.cc) möchte sich Snapdo immer wieder installieren. Malewarebytes erwischt esaber zum Glück immer. Heisst das, dass mein PC noch nicht trojanerfrei ist? Wie immer häng ich dir auch gleich noch ein mbam-Log an. Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 12.04.2014 Suchlauf-Zeit: 20:49:23 Logdatei: mbam.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.12.05 Rootkit Datenbank: v2014.03.27.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Chameleon: Deaktiviert Betriebssystem: Windows Vista Service Pack 2 CPU: x64 Dateisystem: NTFS Benutzer: Michaela Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 252036 Verstrichene Zeit: 34 Min, 46 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 1 PUP.Optional.Snapdo.A, C:\Users\Michaela\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=97c644c5-ac6a-452e-b40f-ec9598ff936e&searchtype=hp&installDate=02/06/2013",), Ersetzt,[4c29b772304bcb6bcc2fe66381832dd3] Physische Sektoren: 0 (No malicious items detected) (end) |
13.04.2014, 16:57 | #22 |
/// the machine /// TB-Ausbilder | Wie kann ich Daten sichern da MusikTrojaner vermutet Die eine Datei kannste löschen. Revo Uninstaller - Download - Filepony damit Chrome deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.google.com/chrome/answer/3296214?hl=de Mach mal bitte nen Clean Boot und teste den Rechner nochmal: How to perform a clean boot in Windows
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.04.2014, 18:26 | #23 |
| Wie kann ich Daten sichern da MusikTrojaner vermutet Jetzt muss ich nochmal für Dumme nachfragen bevor Ich was kaputt mache. Revo-Uninstaller: Ist runtergeladen und installiert. Hab ihn dann ausgeführt um bevor ich Chrome deinstallieren wollte gefragt zu werden welchen Modus ich möchte. Soll ich da den voreingestellten Modus lassen oder den super-gründlichen, der auch der langsamste ist? Soll ich damit nur Chrome deinstallieren oder auch meine anderen Browser nachdem ich Chrome dann wieder installiert hab? (Hab auch noch InternetExplorer, Firefox, Safari und Opera - Grund für die vielen browser: Ich bastle an HTML codes auf tumblr rum und muss die Darstellung auch in anderen Browsern checken. Nicht dass du dich wunderst ) Browsereinstellungen zurücksetzen: Soll ich dann nach Neuinstallation von Chrome machen denke ich. Frage: Geht mir beim deinstallieren auch mein avast Online-Security abhanden und Adblock? Clean Boot: Der Teil macht mir richtig Angst weil ich gelesen habe bei Microsoft dass ein 'verhunzter' CleanBoot den Computer evtl. nicht mehr starten lässt. Werde mich ganz genau an die Schritte halten aber meine Hauptfrage ist: Was mach ich denn dann nach dem CleanBoot? Einen Virenscan oder? Oder was meinst du mit testen? Nur nachschauen ob er dann schnell hochfährt? Hab noch was, dass ich evtl. als Ursache sehe: Dieses schwarze Fenster beim Hochfahren zwischen dem Willkommen-Screen und meinem tatsächlich Desktop verschwindet glaub ich wenn ich die Benutzerkontensteuerung ausschalte. Bekomme aber dann Meldungen dass mein System Sicherheitsprobleme hat von den Windows Sicherheitshinweisen. Die sagen mir übrigens auch das avast ausgeschaltet ist, obwoh Avast selber meldet dass es läuft? Kann es sein dass avast das nicht an das Sicherheitscenter melden kann? Bin langsam am verzweifeln... Und deswegen fass ich jetzt bis du wieder Zeit hast (ich muss dich echt viel davon kosten ><) nichts an. Danke. |
14.04.2014, 15:02 | #24 |
/// the machine /// TB-Ausbilder | Wie kann ich Daten sichern da MusikTrojaner vermutet Nur Chrome im Moment. Adblock musste neu installieren, Avast normal nicht. Nach dem Clean boot die GEschwindigkeit des Rechners testen. Wenn dann alles gut ist wieder einen Dienst nach dem anderen aktivieren, reboot, testen, solange bis der Fehler wieder da ist und wir wissen, welcher Dienst es ist.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.04.2014, 18:08 | #25 |
| Wie kann ich Daten sichern da MusikTrojaner vermutet Chrome Schritt abgeschlossen. Meine Extensions wieder installiert (Adblock und so) Brauchst du ein neues FRST zum checken? snapdo wurde beim von mir manuell ausgeführten Bedrohungssuchlauf wieder entdeckt von mbam. Den anderen Schritt mit dem booten mach ich morgen nach meinen Arzterminen. Darf ich auch PM wenn irgendwas zwischendrin auftaucht wo ich mich nicht auskenne? Natürlch nur wenn ich sehe dass du online bist und wirklich nur fürs clean booten. Sonst warte ich brav Soll ich Internet Explorer eigentlich komplett runterschmeißen vom Pc? Hab gehört der hat so viele Hintertürchen - benutzen tu ich ihn eh nicht. |
15.04.2014, 13:55 | #26 |
/// the machine /// TB-Ausbilder | Wie kann ich Daten sichern da MusikTrojaner vermutet Nein, der bleibt drauf, is ne WIndows Komponente, und immer schön updaten. Klar, schick einfach ne PM
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.04.2014, 13:51 | #27 |
| Wie kann ich Daten sichern da MusikTrojaner vermutet Hallo schrauber. Ich hab jetzt einmal den sauberen Start gemacht. Braucht dann immernoch ein bisschen aber sind nur noch an die 10 Sekunden (statt der mindestens 3 Minuten oder länger sonst). Wenn ich den Pc Start wieder auf normal zurück setze dauert es wieder sehr lang. Jetzt frage ich weil ich die Übersetzung von Microsoft nicht ganz verstehe. Ich mach nen clean boot. ok. und dann sollte bei den Diensten ja alles deaktiviert sein. Avast aktiviert sich selbst aber mit dem startet er ja schon schneller. Soll ich jetzt die leere Liste nach und nach bei jedem Neustart um ein Hacken erweitern? Oder soll ich immer nur ein Dienst einzeln testen? Ich versuch das mal besser zu veranschaulichen: Dienst 1 und 2 hat keine Verzögerung beim hochfahren verursacht und jetzt wäre Dienst 3 an der Reihe zum testen. Variante A (Nach Clean Boot) [x] avast [x] Dienst 1 [x] Dienst 2 [x] Dienst 3 Variante B (Nach Clean Boot) [x] avast [ ] Dienst 1 [ ] Dienst 2 [x] Dienst 3 Hoffe du verstehst mich >< |
17.04.2014, 10:06 | #28 |
/// the machine /// TB-Ausbilder | Wie kann ich Daten sichern da MusikTrojaner vermutet Clean Boot Neustart 1 Dienst dazu, nur einen Neustart 1 Dienst mehr, immer nur einen zwischen jedem Neustart Irgendwann startest Du dann neu, BÄM, Rechner ist langsam, dann weißt du es ist der Dienst den du als letztes aktiviert hast. Diesen Namen brauchen wir
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.04.2014, 11:37 | #29 |
| Wie kann ich Daten sichern da MusikTrojaner vermutet Hab den Übeltäter: Bluetooth Service, Hersteller Broadcom Corporation Dazu noch folgende Anmerkung: mein Laptop hatte kein Bluetooth. Deswegen habe ich so einen Ergänzung USB Bluetooth Teil gekauft. Wenn ich alles aktiviere außer dem kleinen Kerl dann komm ich nach dem Willkommen Bildschirm direkt auf den Desktop. Würde nicht dramatisch sein ohne Bluetooth da ich auch mediafire und Dropbox zur Datenübertragung zum Phone nutze. |
18.04.2014, 09:52 | #30 |
/// the machine /// TB-Ausbilder | Wie kann ich Daten sichern da MusikTrojaner vermutet Installier mal die Treiber von dem Teil neu und/oder die Software, das könnte schon helfen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Wie kann ich Daten sichern da MusikTrojaner vermutet |
avast, bilder, dateien, daten, datensicherung, einfach, erstellt, externe festplatte, festplatte, folge, folgendes, musik, musik im hintergrund, nichts, problem, pup.optional.babylon.a, pup.optional.datamngr.a, pup.optional.opencandy, pup.optional.snapdo, pup.optional.snapdo.a, pup.optional.websearch.a, trojaner verdacht, virenscan |