|
Plagegeister aller Art und deren Bekämpfung: Programme gehen einfach aus und Avira Echtzeitscanner sowie normaler scan funktionieren nicht, das gleiche bei Malwarebytes...Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
18.05.2014, 15:10 | #1 |
| Programme gehen einfach aus und Avira Echtzeitscanner sowie normaler scan funktionieren nicht, das gleiche bei Malwarebytes... Guten Tag Ich habe ein wirklich großes Problem und schildere euch einfach was ich genau hatte und gemacht habe: Nun ich führe immer etwa alle paar tage einige Scans mit Malwarebytes durch, meistens nur die schnellen und nicht intensiven und ich ging davon aus, dass nichts wirklich stark befallen ist. Doch irgendwannmal beim surfen, habe ich gemerkt, dass der avira echtzeitscanner nicht funktionierte und als ich ihn anmachen wollte, ist er nicht aktiviert worden. Kurz darauf stürzte Firefox ab mit der Fehlermeldung, dass der plugin container nicht funktioniert. Und dann fing es erst richtig an. Mein pc ist ausgegangen mit einem bluescreen, in welchem stand, dass der pc aus Sicherheitsgründen gestoppt werden musste um schäden zu vermeiden(Bei der Fehlermeldung stand immer eine andere Ursache, meistens mit "MEMORY_MANAGEMENT"). Das alles ist öfters passiert. Darauf habe ich den pc mit avira und Malwarebytes intensiv scannen lassen (im abgesicherten modus). Der scan von avira ist dann einfach ausgegangen und sobald Malwarebytes fertig war, ist der scan auch dort einfach aus. Bei Malwarebytes hat es jedoch mich stark gewundert, denn der scan hat über 4000 infizierte objekte gefunden (das meiste waren rootkits, wie z.b C:\Windows\System32\drivers\atikmdag.sys) bevor er einfach "verschwand" Falls ihr irgendwelche Informationen braucht, gebe ich sie euch. Ich bedanke mich jetzt schon für hilfe. Logfile: HiJackthis Logfile: Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 16:31:49, on 18.05.2014 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.19518) Boot mode: Normal Running processes: C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe C:\Windows\system32\taskeng.exe C:\Fraps\fraps.exe C:\Windows\RtHDVCpl.exe C:\Program Files\HP\HP Software Update\hpwuschd2.exe C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe C:\Users\Alex\AppData\Local\Akamai\netsession_win.exe C:\Users\Alex\AppData\Local\Akamai\netsession_win.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Windows\system32\Dwm.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Alex\AppData\Local\Temp\OCS\ocs_v71b.exe C:\Users\Alex\AppData\Local\Temp\OCS\Downloads\fc14996dfa99adfc7baae624196888c5\7b4e384f5b096b9656fee276ba88bb81\HiJackThis204.exe C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicator.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.privitize.com/?aff=7 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;<local> R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {1ce76c93-a797-4ca2-ab3c-f4a6cfba3440} - (no file) R3 - URLSearchHook: (no name) - {64ead72b-ffd4-4e01-aa3a-4c71665d73e4} - (no file) R3 - URLSearchHook: (no name) - - (no file) R3 - URLSearchHook: (no name) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - (no file) R3 - URLSearchHook: (no name) - {7e111a5c-3d11-4f56-9463-5310c3c69025} - (no file) O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: icqBHO - {0766C1B9-B2DC-46E5-8934-4F3D6B42B1BD} - (no file) O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\Microsoft Office\Office14\GROOVEEX.DLL O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\Microsoft Office\Office14\URLREDIR.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - (no file) O3 - Toolbar: (no name) - {64ead72b-ffd4-4e01-aa3a-4c71665d73e4} - (no file) O3 - Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - (no file) O4 - HKLM\..\Run: [Skytel] Skytel.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [USBToolTip] C:\PROGRA~1\Pinnacle\Shared files\Programs\USBTip\USBTip.exe O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices O4 - HKLM\..\Run: [Gavii] C:\ProgramData\Gavii\Gavii.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start O4 - HKCU\..\Run: [HP Photosmart 5510 series (NET)] "C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN17P0803805NR:NW" -scfn "HP Photosmart 5510 series (NET)" -AutoStart 1 O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Alex\AppData\Local\Akamai\netsession_win.exe" O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe" O4 - HKCU\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe -s O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE" O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [MKLOL] "C:\Program Files\MKJogo\MKLOL\MK.exe" -auto O4 - HKCU\..\Run: [Raptr] C:\PROGRA~1\Raptr\raptrstub.exe --startup O4 - HKUS\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [HP Photosmart 5510 series (NET)] "C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN17P0803805NR:NW" -scfn "HP Photosmart 5510 series (NET)" -AutoStart 1 (User '?') O4 - HKUS\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun (User '?') O4 - HKUS\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Akamai NetSession Interface] "C:\Users\Alex\AppData\Local\Akamai\netsession_win.exe" (User '?') O4 - HKUS\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Facebook Update] "C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver (User '?') O4 - HKUS\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe" (User '?') O4 - HKUS\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe -s (User '?') O4 - HKUS\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE" (User '?') O4 - HKUS\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent (User '?') O4 - HKUS\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User '?') O4 - HKUS\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [MKLOL] "C:\Program Files\MKJogo\MKLOL\MK.exe" -auto (User '?') O4 - HKUS\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Raptr] C:\PROGRA~1\Raptr\raptrstub.exe --startup (User '?') O4 - HKUS\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\..\Run: [HP Photosmart 5510 series (NET)] "C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN17P0803805NR:NW" -scfn "HP Photosmart 5510 series (NET)" -AutoStart 1 (User '?') O4 - HKUS\S-1-5-21-2597287126-3799022477-3584391229-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?') O4 - S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Startup: Curse.lnk = C:\Users\Alex\AppData\Roaming\Curse Client\Bin\Curse.exe (User '?') O4 - S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1 Startup: Curse.lnk = C:\Users\Alex\AppData\Roaming\Curse Client\Bin\Curse.exe (User '?') O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (User 'Default user') O4 - Startup: Curse.lnk = C:\Users\Alex\AppData\Roaming\Curse Client\Bin\Curse.exe O4 - Global Startup: FILSHtray.lnk = C:\Program Files\FILSHtray\FILSHtray.exe O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe O8 - Extra context menu item: &Alles mit FlashGet laden - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: &Mit FlashGet laden - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~1\Microsoft Office\Office14\ONBttnIE.dll/105 O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~1\Microsoft Office\Office14\EXCEL.EXE/3000 O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: eBay - Der weltweite Online Marktplatz - {76577871-04EC-495E-A12B-91F7C3600AFA} - hxxp://rover.ebay.com/rover/1/707-44556-9400-3/4 (file missing) O9 - Extra button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Amazon.de - {8A918C1D-E123-4E36-B562-5C1519E434CE} - hxxp://www.amazon.de/exec/obidos/redirect-home?tag=Toshibadebholink-21&site=home (file missing) O15 - Trusted Zone: hxxp://*.aeriagames.com O15 - Trusted Zone: *.clonewarsadventures.com O15 - Trusted Zone: *.freerealms.com O15 - Trusted Zone: *.soe.com O15 - Trusted Zone: *.sony.com O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - hxxp://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = DENIS-PC O17 - HKLM\Software\..\Telephony: DomainName = DENIS-PC O17 - HKLM\System\CCS\Services\Tcpip\..\{41605B94-378C-4AEB-9E37-45B7583A35DD}: NameServer = 192.168.178.44,192.168.178.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = DENIS-PC O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = DENIS-PC O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe O23 - Service: Avira Planer (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira Echtzeit-Scanner (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - C:\Program Files\Hi-Rez Studios\HiPatchService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Riverbed Technology, Inc. - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: RzKLService - Razer Inc. - C:\Program Files\Razer\Razer Game Booster\RzKLService.exe O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe O23 - Service: SmartFaceVWatchSrv - Toshiba - C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe O23 - Service: Notebook Performance Tuning Service (TempoMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TempoSVC.exe O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -- End of file - 17007 bytes Geändert von DogeSoulz (18.05.2014 um 15:35 Uhr) |
18.05.2014, 15:52 | #2 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Programme gehen einfach aus und Avira Echtzeitscanner sowie normaler scan funktionieren nicht, das gleiche bei Malwarebytes... Hallo und
__________________Lesestoff: Bitte keine Hijackthis-Logfiles posten!!! Zitat:
Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
18.05.2014, 17:37 | #3 |
| Programme gehen einfach aus und Avira Echtzeitscanner sowie normaler scan funktionieren nicht, das gleiche bei Malwarebytes... Danke für diese Antwort, nun weiß ich, was ich machen muss (bin neu hier)
__________________Hier dann das neue logfile FRST: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:17-05-2014 Ran by Alex (administrator) on DENIS-PC on 18-05-2014 17:39:33 Running from C:\Users\Alex\Downloads Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (AMD) C:\Windows\System32\atieclxx.exe (Agere Systems) C:\Windows\System32\agrsmsvc.exe (Hi-Rez Studios) C:\Program Files\Hi-Rez Studios\HiPatchService.exe (LogMeIn, Inc.) C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe (Razer Inc.) C:\Program Files\Razer\Razer Game Booster\RzKLService.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\TempoSVC.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA CORPORATION) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Toshiba) C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe (Google Inc.) C:\Program Files\Google\Update\1.3.24.7\GoogleCrashHandler.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Pinnacle Systems GmbH) C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe (Akamai Technologies, Inc.) C:\Users\Alex\AppData\Local\Akamai\netsession_win.exe () C:\Program Files\RocketDock\RocketDock.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Akamai Technologies, Inc.) C:\Users\Alex\AppData\Local\Akamai\netsession_win.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Valve Corporation) C:\Program Files\Steam\Steam.exe (Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe () C:\Users\Alex\Downloads\Defogger.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicator.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6037504 2008-04-08] (Realtek Semiconductor) HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard) HKLM\...\Run: [USBToolTip] => C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe [199752 2007-02-20] (Pinnacle Systems GmbH) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [Gavii] => C:\ProgramData\Gavii\Gavii.exe [464384 2013-06-25] (Gavii) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642304 2013-04-30] (Advanced Micro Devices, Inc.) HKLM\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [3814736 2014-05-13] (LogMeIn Inc.) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [183376 2014-05-14] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-09] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKU\S-1-5-21-2597287126-3799022477-3584391229-1000\...\Run: [HP Photosmart 5510 series (NET)] => C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe [1801064 2011-05-25] (Hewlett-Packard Co.) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Alex\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000\...\Run: [Facebook Update] => C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-12] (Facebook Inc.) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000\...\Run: [RocketDock] => C:\Program Files\RocketDock\RocketDock.exe [495616 2007-09-02] () HKU\S-1-5-21-2597287126-3799022477-3584391229-1000\...\Run: [CollaborationHost] => C:\Windows\system32\p2phost.exe [192000 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000\...\Run: [Steam] => C:\Program Files\Steam\steam.exe [1825984 2014-04-24] (Valve Corporation) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000\...\Run: [MKLOL] => C:\Program Files\MKJogo\MKLOL\MK.exe [1277128 2014-04-23] (MK) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000\...\Run: [Raptr] => C:\Program Files\Raptr\raptrstub.exe [55360 2014-03-28] (Raptr, Inc) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000\...\MountPoints2: {117382f1-9712-11df-a2e4-001e337dbd83} - "I:\WD SmartWare.exe" autoplay=true HKU\S-1-5-21-2597287126-3799022477-3584391229-1000\...\MountPoints2: {498fae07-3530-11e1-8877-00037a96d54c} - H:\setup.exe HKU\S-1-5-21-2597287126-3799022477-3584391229-1000\...\MountPoints2: {540fdc48-2455-11e3-8778-00037a96d54c} - I:\AutoRun.exe HKU\S-1-5-21-2597287126-3799022477-3584391229-1000\...\MountPoints2: {6c252832-636a-11e0-a993-00037a96d54c} - I:\LaunchU3.exe -a HKU\S-1-5-21-2597287126-3799022477-3584391229-1000\...\MountPoints2: {a67f9200-3de0-11e1-85c7-001e337dbd83} - I:\Autorun.exe HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [HP Photosmart 5510 series (NET)] => C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe [1801064 2011-05-25] (Hewlett-Packard Co.) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3514176 2011-11-10] (DT Soft Ltd) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Akamai NetSession Interface] => C:\Users\Alex\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Facebook Update] => C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-12] (Facebook Inc.) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [RocketDock] => C:\Program Files\RocketDock\RocketDock.exe [495616 2007-09-02] () HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [CollaborationHost] => C:\Windows\system32\p2phost.exe [192000 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Steam] => C:\Program Files\Steam\steam.exe [1825984 2014-04-24] (Valve Corporation) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [MKLOL] => C:\Program Files\MKJogo\MKLOL\MK.exe [1277128 2014-04-23] (MK) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Raptr] => C:\Program Files\Raptr\raptrstub.exe [55360 2014-03-28] (Raptr, Inc) HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {117382f1-9712-11df-a2e4-001e337dbd83} - "I:\WD SmartWare.exe" autoplay=true HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {498fae07-3530-11e1-8877-00037a96d54c} - H:\setup.exe HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {540fdc48-2455-11e3-8778-00037a96d54c} - I:\AutoRun.exe HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {6c252832-636a-11e0-a993-00037a96d54c} - I:\LaunchU3.exe -a HKU\S-1-5-21-2597287126-3799022477-3584391229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {a67f9200-3de0-11e1-85c7-001e337dbd83} - I:\Autorun.exe HKU\S-1-5-21-2597287126-3799022477-3584391229-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-2597287126-3799022477-3584391229-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [TOSCDSPD] => C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [430080 2008-04-24] (TOSHIBA) Startup: C:\Users\Acronis Agent User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk ShortcutTarget: Curse.lnk -> C:\Users\Alex\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FILSHtray.lnk ShortcutTarget: FILSHtray.lnk -> C:\Program Files\FILSHtray\FILSHtray.exe (FILSH Media GmbH) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/ HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA; URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} URLSearchHook: HKCU - (No Name) - {1ce76c93-a797-4ca2-ab3c-f4a6cfba3440} - No File URLSearchHook: HKCU - (No Name) - {7e111a5c-3d11-4f56-9463-5310c3c69025} - No File SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {D9B7797E-54DD-4A89-A72B-F847964FFCBC} URL = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA; SearchScopes: HKCU - {D9B7797E-54DD-4A89-A72B-F847964FFCBC} URL = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA; BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\..\Interfaces\{41605B94-378C-4AEB-9E37-45B7583A35DD}: [NameServer]192.168.178.44,192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\lluz7tv9.default-1400247563503 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=1.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Alex\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Alex\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Alex\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Alex\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DoNotTrackMe: Online Privacy Protection - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\lluz7tv9.default-1400247563503\Extensions\donottrackplus@abine.com [2014-05-16] FF Extension: ProxTube - Unblock YouTube - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\lluz7tv9.default-1400247563503\Extensions\ich@maltegoetz.de [2014-05-16] FF Extension: Facebook Cleaner - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\lluz7tv9.default-1400247563503\Extensions\jid0-TBRXf78ZEzGQyccB8SA1ALbcMpE@jetpack.xpi [2014-05-16] FF Extension: Privacy Badger Firefox - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\lluz7tv9.default-1400247563503\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2014-05-16] FF Extension: NoScript - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\lluz7tv9.default-1400247563503\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-05-16] FF Extension: Adblock Plus - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\lluz7tv9.default-1400247563503\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-05-16] FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-04-01] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] Chrome: ======= CHR HomePage: CHR Extension: (Skype Click to Call) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-09-16] CHR Extension: (Chrome In-App Payments service) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-16] CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-10-02] CHR HKLM\...\Chrome\Extension: [ofahndfepeaeelmhdkjiihmofnokhmik] - C:\Users\Alex\AppData\Local\Temp\tbch.crx [2012-10-02] ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1039440 2014-05-09] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [123984 2014-05-14] (Avira Operations GmbH & Co. KG) S4 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2008-04-17] (TOSHIBA CORPORATION) R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1682768 2014-05-13] (LogMeIn Inc.) U2 HiPatchService; C:\Program Files\Hi-Rez Studios\HiPatchService.exe [8704 2013-02-12] (Hi-Rez Studios) S2 KMService; C:\Windows\system32\srvany.exe [8192 2003-04-18] () R2 LMIGuardianSvc; C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [375056 2014-04-15] (LogMeIn, Inc.) R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [235696 2014-01-16] (McAfee, Inc.) R2 RzKLService; C:\Program Files\Razer\Razer Game Booster\RzKLService.exe [105448 2013-11-22] (Razer Inc.) R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.) R3 SmartFaceVWatchSrv; C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe [73728 2008-04-24] (Toshiba) R2 TempoMonitoringService; C:\Program Files\Toshiba TEMPRO\TempoSVC.exe [99720 2008-04-24] (Toshiba Europe GmbH) R2 TOSHIBA SMART Log Service; C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [126976 2007-12-03] (TOSHIBA Corporation) S4 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.) S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X] ==================== Drivers (Whitelisted) ==================== R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdLH3.sys [83984 2012-02-23] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [93528 2014-05-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-05-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2014-05-09] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [239168 2012-01-02] (DT Soft Ltd) R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [26024 2009-12-18] (Elaborate Bytes AG) R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [21504 2010-02-16] (hxxp://www.atmel.com) R3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus.sys [171520 2005-09-23] (Pinnacle Systems GmbH) R1 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [73432 2014-04-03] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [107736 2014-05-18] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51416 2014-04-03] (Malwarebytes Corporation) S3 MotioninJoyXFilter; C:\Windows\System32\DRIVERS\MijXfilt.sys [99400 2012-05-12] (MotioninJoy) R3 NETwNv32; C:\Windows\System32\DRIVERS\NETwNv32.sys [7346176 2011-11-01] (Intel Corporation) R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.) S3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [141408 2008-02-27] (Realtek Semiconductor Corp.) S3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2010-07-01] (Screaming Bee LLC) S1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2014-05-09] (Avira GmbH) S3 tenCapture; C:\Windows\System32\DRIVERS\tenCapture.sys [20664 2012-07-20] (Hajo Krabbenhöft) R3 UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [18432 2007-12-17] (Chicony Electronics Co., Ltd.) S3 xnacc; C:\Windows\System32\DRIVERS\xnacc.sys [521216 2008-01-21] (Microsoft Corporation) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\Users\Alex\AppData\Local\Temp\catchme.sys [X] S3 EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [X] S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X] S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\1.3\temp\FairplayKD.sys [X] S3 igfx; system32\DRIVERS\igdkmd32.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [X] S3 vtany; \??\C:\Windows\vtany.sys [X] S3 WinRing0_1_2_0; \??\C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys [X] S3 XDva387; \??\C:\Windows\system32\XDva387.sys [X] S3 XDva390; \??\C:\Windows\system32\XDva390.sys [X] S3 XDva393; \??\C:\Windows\system32\XDva393.sys [X] S3 XDva394; \??\C:\Windows\system32\XDva394.sys [X] S3 XDva396; \??\C:\Windows\system32\XDva396.sys [X] S3 XDva397; \??\C:\Windows\system32\XDva397.sys [X] S3 XDva400; \??\C:\Windows\system32\XDva400.sys [X] S3 XDva401; \??\C:\Windows\system32\XDva401.sys [X] S3 XDva405; \??\C:\Windows\system32\XDva405.sys [X] S3 XDva407; \??\C:\Windows\system32\XDva407.sys [X] S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-18 17:39 - 2014-05-18 17:39 - 00028755 _____ () C:\Users\Alex\Downloads\FRST.txt 2014-05-18 17:39 - 2014-05-18 17:39 - 00000000 ___DC () C:\FRST 2014-05-18 17:37 - 2014-05-18 17:38 - 00000470 _____ () C:\Users\Alex\Downloads\defogger_disable.log 2014-05-18 17:37 - 2014-05-18 17:37 - 00000156 _____ () C:\Users\Alex\defogger_reenable 2014-05-18 17:34 - 2014-05-18 17:34 - 01056768 _____ (Farbar) C:\Users\Alex\Downloads\FRST.exe 2014-05-18 17:34 - 2014-05-18 17:34 - 00050477 _____ () C:\Users\Alex\Downloads\Defogger.exe 2014-05-18 17:23 - 2014-05-18 17:23 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Avira 2014-05-18 17:21 - 2014-05-09 11:16 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2014-05-18 17:20 - 2014-05-09 11:16 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-05-18 17:20 - 2014-05-09 11:16 - 00093528 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-18 17:20 - 2014-05-09 11:16 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-05-18 17:18 - 2014-05-18 17:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-05-18 17:18 - 2014-05-18 17:20 - 00000000 ____D () C:\Program Files\Avira 2014-05-18 17:18 - 2014-05-18 17:18 - 00001015 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-05-18 17:06 - 2014-05-18 17:06 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Alex\Downloads\avira_de_av___ws.exe 2014-05-18 16:39 - 2014-05-18 17:11 - 00002120 _____ () C:\Windows\PFRO.log 2014-05-18 16:35 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll 2014-05-18 16:33 - 2014-05-18 16:37 - 00000000 ___DC () C:\AdwCleaner 2014-05-18 16:32 - 2014-05-18 16:32 - 00017009 _____ () C:\Users\Alex\Desktop\hijackthis.log 2014-05-18 16:30 - 2014-05-18 16:30 - 00961360 _____ (Chip Digital GmbH) C:\Users\Alex\Downloads\HijackThis - CHIP-Downloader.exe 2014-05-18 16:30 - 2014-05-18 16:30 - 00961360 _____ (Chip Digital GmbH) C:\Users\Alex\Downloads\AdwCleaner - CHIP-Downloader.exe 2014-05-18 15:41 - 2014-05-18 17:22 - 00059078 _____ () C:\Windows\WindowsUpdate.log 2014-05-18 15:25 - 2014-05-18 15:25 - 00000000 __SHD () C:\found.000 2014-05-16 18:36 - 2014-05-16 18:44 - 00000000 __SDC () C:\ComboFix 2014-05-16 18:36 - 2014-05-16 18:36 - 00000000 ___DC () C:\Qoobox 2014-05-16 18:36 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-05-16 18:36 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-05-16 18:36 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-05-16 18:36 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-05-16 18:36 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-05-16 18:36 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-05-16 18:36 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-05-16 18:36 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-05-16 18:35 - 2014-05-16 18:36 - 00000000 __SDC () C:\32788R22FWJFW 2014-05-16 18:35 - 2014-05-16 18:35 - 00000000 ____D () C:\Windows\erdnt 2014-05-16 18:32 - 2014-05-16 18:32 - 05200990 ____R (Swearware) C:\Users\Alex\Downloads\ComboFix.exe 2014-05-16 17:32 - 2014-05-16 17:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus 2014-05-16 17:32 - 2014-05-16 17:32 - 00000000 ____D () C:\Program Files\McAfee Security Scan 2014-05-16 16:49 - 2014-05-16 17:32 - 00001930 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2014-05-16 16:49 - 2014-05-16 16:49 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2014-05-15 19:10 - 2014-05-15 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2014-05-09 21:32 - 2014-05-09 21:51 - 00000000 ____D () C:\Users\Alex\Documents\Horizon Game 2014-05-07 19:30 - 2014-05-07 19:30 - 00000940 _____ () C:\Users\Alex\Desktop\Curse.lnk 2014-05-07 19:29 - 2014-05-08 15:21 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Curse Client 2014-05-07 19:29 - 2014-05-07 19:29 - 00000926 _____ () C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse.lnk 2014-05-07 19:28 - 2014-05-07 19:28 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Curse 2014-05-03 12:09 - 2014-04-29 22:18 - 06020608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-03 12:09 - 2014-04-29 21:28 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-28 21:03 - 2014-04-28 21:09 - 498305161 _____ () C:\Users\Alex\Documents\►1 HOUR ULTRA GAMING MIX JULY 2013◄ ヽ( ≧ω≦)ノ.mp4 2014-04-24 14:00 - 2014-04-24 14:00 - 00002124 _____ () C:\Users\Public\Desktop\Free Video to MP3 Converter.lnk 2014-04-24 12:47 - 2014-04-24 12:47 - 00000000 ____D () C:\ProgramData\YTD Video Downloader 2014-04-24 12:46 - 2014-04-24 12:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader 2014-04-21 18:33 - 2014-04-21 18:36 - 00000000 ____D () C:\Users\Alex\Desktop\Server auf 1.7.2 2014-04-20 10:10 - 2014-04-20 10:10 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_07_00.Wdf ==================== One Month Modified Files and Folders ======= 2014-05-18 17:39 - 2014-05-18 17:39 - 00028755 _____ () C:\Users\Alex\Downloads\FRST.txt 2014-05-18 17:39 - 2014-05-18 17:39 - 00000000 ___DC () C:\FRST 2014-05-18 17:38 - 2014-05-18 17:37 - 00000470 _____ () C:\Users\Alex\Downloads\defogger_disable.log 2014-05-18 17:37 - 2014-05-18 17:37 - 00000156 _____ () C:\Users\Alex\defogger_reenable 2014-05-18 17:37 - 2010-06-18 20:43 - 00000000 ____D () C:\Users\Alex 2014-05-18 17:34 - 2014-05-18 17:34 - 01056768 _____ (Farbar) C:\Users\Alex\Downloads\FRST.exe 2014-05-18 17:34 - 2014-05-18 17:34 - 00050477 _____ () C:\Users\Alex\Downloads\Defogger.exe 2014-05-18 17:32 - 2012-04-19 18:02 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-18 17:26 - 2014-04-09 16:45 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-18 17:26 - 2013-08-23 13:29 - 00000000 ____D () C:\Program Files\Steam 2014-05-18 17:26 - 2008-01-21 09:16 - 00234818 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-18 17:23 - 2014-05-18 17:23 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Avira 2014-05-18 17:22 - 2014-05-18 15:41 - 00059078 _____ () C:\Windows\WindowsUpdate.log 2014-05-18 17:21 - 2014-05-18 17:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-05-18 17:20 - 2014-05-18 17:18 - 00000000 ____D () C:\Program Files\Avira 2014-05-18 17:20 - 2010-06-18 21:32 - 00000000 ____D () C:\ProgramData\Avira 2014-05-18 17:19 - 2011-10-15 15:50 - 00000433 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-05-18 17:18 - 2014-05-18 17:18 - 00001015 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-05-18 17:18 - 2013-12-25 18:39 - 00000000 ____D () C:\ProgramData\Package Cache 2014-05-18 17:18 - 2010-11-30 20:26 - 00001090 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-18 17:18 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-18 17:17 - 2006-11-02 15:01 - 00032562 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-05-18 17:16 - 2011-12-29 15:48 - 00000000 ____D () C:\Users\Alex\AppData\Local\LogMeIn Hamachi 2014-05-18 17:15 - 2011-09-21 20:30 - 00000000 ____D () C:\Fraps 2014-05-18 17:11 - 2014-05-18 16:39 - 00002120 _____ () C:\Windows\PFRO.log 2014-05-18 17:11 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-18 17:11 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-18 17:06 - 2014-05-18 17:06 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Alex\Downloads\avira_de_av___ws.exe 2014-05-18 16:46 - 2010-11-30 20:26 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-18 16:37 - 2014-05-18 16:33 - 00000000 ___DC () C:\AdwCleaner 2014-05-18 16:36 - 2012-06-13 20:19 - 00000000 ____D () C:\ProgramData\ICQ 2014-05-18 16:36 - 2010-11-28 12:28 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft 2014-05-18 16:32 - 2014-05-18 16:32 - 00017009 _____ () C:\Users\Alex\Desktop\hijackthis.log 2014-05-18 16:30 - 2014-05-18 16:30 - 00961360 _____ (Chip Digital GmbH) C:\Users\Alex\Downloads\HijackThis - CHIP-Downloader.exe 2014-05-18 16:30 - 2014-05-18 16:30 - 00961360 _____ (Chip Digital GmbH) C:\Users\Alex\Downloads\AdwCleaner - CHIP-Downloader.exe 2014-05-18 15:25 - 2014-05-18 15:25 - 00000000 __SHD () C:\found.000 2014-05-18 14:01 - 2014-01-10 12:58 - 00001356 _____ () C:\Users\Alex\AppData\Local\d3d9caps.dat 2014-05-17 20:31 - 2012-05-25 19:21 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\uTorrent 2014-05-17 20:31 - 2012-01-02 13:21 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\DAEMON Tools Lite 2014-05-17 20:31 - 2010-06-25 20:41 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Winamp 2014-05-17 20:31 - 2010-06-23 18:19 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Media Player Classic 2014-05-17 20:23 - 2013-04-16 20:14 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\.minecraft 2014-05-17 20:03 - 2010-06-18 22:38 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Skype 2014-05-17 18:20 - 2012-03-24 13:10 - 00001134 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2597287126-3799022477-3584391229-1000UA.job 2014-05-17 18:20 - 2012-03-24 13:09 - 00001112 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2597287126-3799022477-3584391229-1000Core.job 2014-05-16 22:09 - 2014-04-06 11:28 - 00000000 ____D () C:\Users\Alex\Desktop\Spiele 2014-05-16 22:07 - 2013-08-05 14:12 - 00000000 ____D () C:\Users\Alex\Desktop\Meme'n'Shit 2014-05-16 22:06 - 2014-02-12 15:04 - 00000000 ____D () C:\Users\Alex\Desktop\Nightcore and Dubstep 2014-05-16 18:44 - 2014-05-16 18:36 - 00000000 __SDC () C:\ComboFix 2014-05-16 18:36 - 2014-05-16 18:36 - 00000000 ___DC () C:\Qoobox 2014-05-16 18:36 - 2014-05-16 18:35 - 00000000 __SDC () C:\32788R22FWJFW 2014-05-16 18:35 - 2014-05-16 18:35 - 00000000 ____D () C:\Windows\erdnt 2014-05-16 18:32 - 2014-05-16 18:32 - 05200990 ____R (Swearware) C:\Users\Alex\Downloads\ComboFix.exe 2014-05-16 17:32 - 2014-05-16 17:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus 2014-05-16 17:32 - 2014-05-16 17:32 - 00000000 ____D () C:\Program Files\McAfee Security Scan 2014-05-16 17:32 - 2014-05-16 16:49 - 00001930 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2014-05-16 16:49 - 2014-05-16 16:49 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2014-05-16 16:49 - 2012-04-19 18:02 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-05-16 16:49 - 2011-06-19 06:35 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-05-16 16:49 - 2010-06-18 21:36 - 00000000 ____D () C:\Users\Alex\AppData\Local\Adobe 2014-05-16 15:32 - 2014-04-01 20:12 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-15 22:08 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-05-15 20:24 - 2011-08-19 19:55 - 00000000 ____D () C:\Users\Alex\AppData\Local\PMB Files 2014-05-15 20:24 - 2011-08-19 19:55 - 00000000 ____D () C:\ProgramData\PMB Files 2014-05-15 19:10 - 2014-05-15 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2014-05-15 19:10 - 2012-12-15 11:14 - 00000822 _____ () C:\Users\Public\Desktop\LogMeIn Hamachi.lnk 2014-05-15 19:10 - 2011-08-14 11:47 - 00000000 ____D () C:\Program Files\LogMeIn Hamachi 2014-05-11 12:15 - 2011-02-12 19:34 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\vlc 2014-05-09 21:51 - 2014-05-09 21:32 - 00000000 ____D () C:\Users\Alex\Documents\Horizon Game 2014-05-09 15:24 - 2010-06-23 18:16 - 00180224 _____ () C:\Users\Alex\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-05-09 11:16 - 2014-05-18 17:21 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2014-05-09 11:16 - 2014-05-18 17:20 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-05-09 11:16 - 2014-05-18 17:20 - 00093528 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-09 11:16 - 2014-05-18 17:20 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-05-08 15:21 - 2014-05-07 19:29 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Curse Client 2014-05-07 19:30 - 2014-05-07 19:30 - 00000940 _____ () C:\Users\Alex\Desktop\Curse.lnk 2014-05-07 19:29 - 2014-05-07 19:29 - 00000926 _____ () C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse.lnk 2014-05-07 19:28 - 2014-05-07 19:28 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Curse 2014-05-03 16:12 - 2013-10-01 14:39 - 00000000 ____D () C:\Users\Alex\AppData\Local\Paint.NET 2014-05-02 15:36 - 2012-01-01 16:43 - 00000000 ____D () C:\Program Files\Common Files\Steam 2014-04-29 22:43 - 2014-04-08 20:15 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Raptr 2014-04-29 22:37 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\tapi 2014-04-29 22:18 - 2014-05-03 12:09 - 06020608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-29 21:28 - 2014-05-03 12:09 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-28 21:09 - 2014-04-28 21:03 - 498305161 _____ () C:\Users\Alex\Documents\►1 HOUR ULTRA GAMING MIX JULY 2013◄ ヽ( ≧ω≦)ノ.mp4 2014-04-24 20:02 - 2012-01-07 14:49 - 00000000 ____D () C:\Users\Alex\AppData\Local\Akamai 2014-04-24 14:00 - 2014-04-24 14:00 - 00002124 _____ () C:\Users\Public\Desktop\Free Video to MP3 Converter.lnk 2014-04-24 14:00 - 2010-11-28 12:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2014-04-24 14:00 - 2010-11-28 12:28 - 00000000 ____D () C:\Program Files\DVDVideoSoft 2014-04-24 13:59 - 2010-11-28 12:28 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\DVDVideoSoft 2014-04-24 12:47 - 2014-04-24 12:47 - 00000000 ____D () C:\ProgramData\YTD Video Downloader 2014-04-24 12:46 - 2014-04-24 12:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader 2014-04-21 18:36 - 2014-04-21 18:33 - 00000000 ____D () C:\Users\Alex\Desktop\Server auf 1.7.2 2014-04-20 10:10 - 2014-04-20 10:10 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_07_00.Wdf Some content of TEMP: ==================== C:\Users\Alex\AppData\Local\Temp\avgnt.exe C:\Users\Alex\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-18 17:20 ==================== End Of Log ============================ --- --- --- Und die addition.txt : Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:17-05-2014 Ran by Alex at 2014-05-18 17:40:41 Running from C:\Users\Alex\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.6.0.5970 - Adobe Systems Incorporated) Adobe AIR (Version: 3.6.0.5970 - Adobe Systems Incorporated) Hidden Adobe Download Assistant (HKLM\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.5 - Adobe Systems Incorporated) Adobe Download Assistant (Version: 1.2.5 - Adobe Systems Incorporated) Hidden Adobe Flash Player 13 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Reader 8.2.2 - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-A82000000003}) (Version: 8.2.2 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.2.122 - Adobe Systems, Inc.) Age of Wonders III (HKLM\...\QWdlb2ZXb25kZXJzSUlJ_is1) (Version: 1 - ) AION Free-To-Play (Version: 2.70.0000 - Gameforge) Hidden Akamai NetSession Interface (HKCU\...\Akamai) (Version: - Akamai Technologies, Inc) AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{0BD03BF6-3A66-EC7F-5155-28A8D6C69409}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.) Application Profiles (HKLM\...\{63059735-CA97-FDFB-0E7A-3B8D81572EFD}) (Version: 2.0.4888.34279 - Advanced Micro Devices, Inc.) Assassins Creed IV Black Flag (HKLM\...\QXNzYXNzaW5zQ3JlZWRJVkJsYWNrRmxhZw==_is1) (Version: 1 - ) Audacity 2.0 (HKLM\...\Audacity_is1) (Version: - Audacity Team) Avira (HKLM\...\{68e29fba-92b1-4f6f-a604-1d8679da3a9f}) (Version: 1.1.13.24161 - Avira Operations GmbH & Co. KG) Avira (Version: 1.1.13.24161 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.4.642 - Avira) BattlEye for OA Uninstall (HKLM\...\BattlEye for OA) (Version: - ) BIT.TRIP Presents... Runner2: Future Legend of Rhythm Alien (HKLM\...\Steam App 218060) (Version: - Gaijin Games) BIT.TRIP RUNNER (HKLM\...\Steam App 63710) (Version: - Gaijin Games) Bluetooth Stack for Windows by Toshiba (HKLM\...\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v6.10.07.2(T) - TOSHIBA CORPORATION) Camera Assistant Software for Toshiba (HKLM\...\{37C866E4-AA67-4725-9E95-A39968DD7960}) (Version: 1.7.193.0508L - Chicony Electronics Co.,Ltd.) Castlevania: Lords of Shadow 2 (HKLM\...\Q2FzdGxldmFuaWFMb3Jkc29mU2hhZG93Mg==_is1) (Version: 1 - ) Catalyst Control Center - Branding (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden Catalyst Pro Control Center (Version: 2013.0429.2313.39747 - Ihr Firmenname) Hidden CCC Help Chinese Standard (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help English (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help French (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help German (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden ccc-utility (Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.06 - Piriform) CD/DVD Drive Acoustic Silencer (HKLM\...\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}) (Version: 2.02.03 - TOSHIBA) Cheat Engine 6.1 (HKLM\...\Cheat Engine 6.1_is1) (Version: - Dark Byte) Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Craften Terminal 3.3.4897.28268 (HKLM\...\{4e7c3936-7c06-4ef0-928b-c5d92f372578}_is1) (Version: 3.3.4897.28268 - Craften Dev Team) Curse (HKLM\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 6.0.0.0 - Curse) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.45.1.0236 - DT Soft Ltd) Dark Souls Prepare to Die Edition (HKLM\...\GFWL_{4E4D0FA1-F880-4CCB-999A-501000008200}) (Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.) Dark Souls Prepare to Die Edition (Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.) Hidden Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{5971CA1F-6BDE-498F-952C-9F2BF94070A4}) (Version: - Microsoft) Dev-C++ 5 beta 9 release (4.9.9.2) (HKLM\...\Dev-C++) (Version: - ) DivX-Setup (HKLM\...\DivX Setup.divx.com) (Version: 2.1.2.2 - DivX, Inc. ) Dungeon Defenders (HKLM\...\Steam App 65800) (Version: - Trendy Entertainment) DVD MovieFactory for TOSHIBA (HKLM\...\{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}) (Version: 5.51 - Ulead Systems, Inc.) Fable III (HKLM\...\GFWL_{4D53090A-9B45-437B-A66A-831000008300}) (Version: 1.0.0000.131 - Microsoft Game Studios) Fable III (Version: 1.0.0000.131 - Microsoft Game Studios) Hidden Facebook Video Calling 2.0.0.447 (HKLM\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited) FILSHtray (HKLM\...\{5928359F-BF46-4646-BF19-B64E55171EB5}) (Version: 0.12 - FILSH Media GmbH) FILSHtray Version 0.11 (HKLM\...\{5928359F-BF46-4646-BF19-B64E55171EB5}_is1) (Version: 0.11 - FILSH Media GmbH) Foxtab (HKLM\...\foxtab) (Version: - FoxTab) <==== ATTENTION Fraps (remove only) (HKLM\...\Fraps) (Version: - ) Free Studio version 5.0.0 (HKLM\...\Free Studio_is1) (Version: - DVDVideoSoft Limited.) Free Video to MP3 Converter version 5.0.37.327 (HKLM\...\Free Video to MP3 Converter_is1) (Version: 5.0.37.327 - DVDVideoSoft Ltd.) Free Zip 9.20 (HKLM\...\7-Zip) (Version: - Somoto Ltd) <==== ATTENTION GameSpy Arcade (HKLM\...\GameSpy Arcade) (Version: - ) Garry's Mod (HKLM\...\Steam App 4000) (Version: - Garry) Google Chrome (HKLM\...\Google Chrome) (Version: 34.0.1847.137 - Google Inc.) Google Update Helper (Version: 1.3.24.7 - Google Inc.) Hidden Grand Theft Auto IV (HKLM\...\Steam App 12210) (Version: - Rockstar North) Gyazo 1.0.1 (HKLM\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc. & Toshiyuki Masui) HDMI Control Manager (HKLM\...\{F81AB80B-5BB7-4E36-8BA5-E07541CE1BFC}) (Version: 1.7 - TOSHIBA) Heaven DX11 Benchmark version 3.0 (HKLM\...\Unigine Heaven DX11 Benchmark (Basic Edition)_is1) (Version: 3.0 - Unigine Corp.) Hi-Rez Studios Games (HKLM\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios) Hitman: Absolution (HKLM\...\Steam App 203140) (Version: - IO Interactive) HP FWUpdateEDO2 (HKLM\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard) HP Photosmart 5510 series - Grundlegende Software für das Gerät (HKLM\...\{FD44CC6E-E0B9-4570-84BA-F1F20E2AAF3A}) (Version: 24.0.342.0 - Hewlett-Packard Co.) HP Update (HKLM\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard) HPDiagnosticAlert (Version: 1.00.0000 - Microsoft) Hidden ICQ Sparberater (HKLM\...\{0766C1B9-B2DC-46E5-8934-4F3D6B42B1BD}) (Version: 1.3.671 - solute gmbh) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java DB 10.5.3.0 (HKLM\...\{00BA866C-F2A2-4BB9-A308-3DFA695B6F7C}) (Version: 10.5.3.0 - Sun Microsystems, Inc) Java(TM) 6 Update 22 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216022F0}) (Version: 6.0.220 - Oracle) Java(TM) 6 Update 27 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216027F0}) (Version: 6.0.270 - Oracle) Java(TM) 6 Update 29 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216020FF}) (Version: 6.0.290 - Sun Microsystems, Inc.) Java(TM) 6 Update 6 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160060}) (Version: 1.6.0.60 - Sun Microsystems, Inc.) Java(TM) SE Development Kit 6 Update 20 (HKLM\...\{32A3A4F4-B792-11D6-A78A-00B0D0160200}) (Version: 1.6.0.200 - Sun Microsystems, Inc.) JavaFX 2.1.1 (HKLM\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) JetBrains dotPeek 1.1 (HKLM\...\{D5A5829D-E916-4277-8E08-2EBD98EC4A10}) (Version: 1.1.1.33 - JetBrains Inc) K-Lite Codec Pack 6.0.4 (Full) (HKLM\...\KLiteCodecPack_is1) (Version: 6.0.4 - ) League of Legends (HKLM\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (Version: 3.0.1 - Riot Games ) Hidden Left 4 Dead 2 (HKLM\...\Steam App 550) (Version: - Valve) LogMeIn Hamachi (HKLM\...\LogMeIn Hamachi) (Version: 2.2.0.193 - LogMeIn, Inc.) LogMeIn Hamachi (Version: 2.2.0.193 - LogMeIn, Inc.) Hidden Magicka (HKLM\...\Steam App 42910) (Version: - Arrowhead Game Studios) Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.141.11 - McAfee, Inc.) MegaTrainer eXperience V1.1.9.4 (HKLM\...\MegaTrainer eXperience_is1) (Version: - ) Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - ) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Mathematics (HKLM\...\{4D090F70-6F08-4B60-9357-A1DFD4458F09}) (Version: 4.0 - Корпорация Майкрософт) Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Primary Interoperability Assemblies 2005 (HKLM\...\{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Silverlight 4 SDK (HKLM\...\{801B0DA3-A3FF-46CC-B97F-D76D510AF5AE}) (Version: 4.0.50401.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM\...\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Express for Windows Phone CTP - ENU (Version: 10.0.30319 - Microsoft Corporation) Hidden Microsoft Windows Phone Developer Resources (HKLM\...\{B86149D3-18A2-41FD-A153-60AF944E47FE}) (Version: 7.0.6176.0 - Microsoft Corporation) Microsoft Windows Phone Developer Tools CTP - ENU (HKLM\...\Microsoft Visual Studio 2010 Express for Windows Phone CTP - ENU) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Microsoft XML Parser (Version: 8.0.7820.0 - Microsoft Corporation) Hidden Microsoft XML Parser (Version: 8.20.8730.4 - Microsoft Corporation) Hidden Microsoft XNA Framework Redistributable 3.1 (HKLM\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Microsoft XNA Game Studio 4.0 Windows Phone Extensions (HKLM\...\{5DDF31D2-63BB-4268-895B-FB05A82A1C00}) (Version: 4.0.20410.0 - Microsoft Corporation) MKey v1.2.6 (HKLM\...\MKey_is1) (Version: 1.2.6 - SerioSoft) MKLOL (HKCU\...\MKLOL) (Version: - ) MotioninJoy Gamepad tool 0.7.1001 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.7.1001 - www.motioninjoy.com) Mozilla Firefox 28.0 (x86 de) (HKLM\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) Mp3 Convert Master v1.1.1.475 (HKLM\...\Mp3 Convert Master_is1) (Version: - Power Convert Mp3 Solution Ltd.) MSVCRT Redists (Version: 1.0 - Sony Creative Software Inc.) Hidden MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) myphotobook 3.5 (HKLM\...\myphotobook) (Version: 3.5 - myphotobook) MySQL Connector/ODBC 5.1 (HKLM\...\{29042B1C-0713-4575-B7CA-5C8E7B0899D4}) (Version: 5.1.5 - MySQL AB) NARUTO SHIPPUDEN: Ultimate Ninja STORM 3 Full Burst (HKLM\...\TkFSVVRPU0hJUFBVREVOVWx0aW1hdGVOaW5qYVNUT1JNM0Z1~D4302771_is1) (Version: 1 - ) NC Launcher (GameForge) (HKLM\...\NCLauncher_GameForge) (Version: - NCsoft) neroxml (Version: 1.0.0 - Nero AG) Hidden NetSpeedMonitor 2.5.4.0 x86 (HKLM\...\{86501894-E722-4385-A792-B7C2F28FAE7B}) (Version: 2.5.4.0 - Florian Gilles) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.49.2 - Black Tree Gaming) No-IP DUC (HKLM\...\NoIPDUC) (Version: 4.0.1 - Vitalwerks Internet Solutions LLC) Notepad++ (HKLM\...\Notepad++) (Version: 6.1.2 - ) NVIDIA PhysX (HKLM\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation) Oblivion (HKLM\...\{C66BF9FD-D367-4E13-8EB8-385FFEA20DB3}) (Version: 1.2.0416 - Bethesda Softworks) OpenOffice.org 3.4.1 (HKLM\...\{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}) (Version: 3.41.9593 - Apache Software Foundation) Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41417}) (Version: 3.61.0 - dotPDN LLC) Pando Media Booster (HKLM\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.7.0.0 - Pando Networks Inc.) PCSX2 - Playstation 2 Emulator (HKLM\...\pcsx2-r5350) (Version: - ) PeerBlock 1.1 (r518) (HKLM\...\{015C5B35-B678-451C-9AEE-821E8D69621C}_is1) (Version: 1.1.0.518 - PeerBlock, LLC) Picasa 2 (HKLM\...\Picasa2) (Version: 2.0 - Google, Inc.) Pinnacle Studio 15 (HKLM\...\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}) (Version: 15.0.0.7593 - Pinnacle Systems) Pinnacle Video Treiber (HKLM\...\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.030 - Pinnacle Systems) Raptr (HKLM\...\Raptr) (Version: - ) Razer Game Booster (HKLM\...\Razer Game Booster_is1) (Version: 4.1.59.0 - Razer Inc.) Realtek 8169 8168 8101E 8102E Ethernet Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5599 - Realtek Semiconductor Corp.) Reus (HKLM\...\Steam App 222730) (Version: - Abbey Games) RICOH R5C83x/84x Flash Media Controller Driver Ver.3.54.02 (HKLM\...\{59F6A514-9813-47A3-948C-8A155460CC2A}) (Version: 3.54.02 - ) RocketDock 1.3.5 (HKLM\...\RocketDock_is1) (Version: - Punk Software) S4 League_EU (HKLM\...\{FE50D634-70E2-4DC2-A4A8-90A2B15C2AD8}) (Version: 1.00.0000 - ) San Andreas Mod Installer (HKLM\...\San Andreas Mod Installer1.1) (Version: 1.1 - cpmusick) Scanitto Pro (HKLM\...\{FC9FED7B-11C5-4BAA-AAF0-395AD111EE92}_is1) (Version: 2.0.7.87 - Masters ITC Software) Serious Sam 3: BFE (HKLM\...\Steam App 41070) (Version: - Croteam) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (Version: - Microsoft) Hidden Silkroad (HKLM\...\Silkroad) (Version: - ) Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.3.11079 - Skype Technologies S.A.) Skype™ 6.14 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Sparkle 2 Evo (HKLM\...\Steam App 253650) (Version: - ) Speccy (HKLM\...\Speccy) (Version: 1.24 - Piriform) Spore (HKLM\...\Steam App 17390) (Version: - Maxis™) STDU Viewer version 1.5.528.0 (HKLM\...\STDU Viewer_is1) (Version: 1.5.528.0 - STDUtility) Steam (HKLM\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Stronghold Crusader Extreme HD (HKLM\...\{8C3727F2-8E37-49E4-820C-03B1677F53B6}) (Version: 1.30.1000 - Firefly Studios) Sun ODF Plugin for Microsoft Office 3.2 (HKLM\...\{BD136CE7-6666-4273-A056-8D92F8625AAB}) (Version: 3.2.9483 - Sun Microsystems) Surgeon Simulator 2013 (HKLM\...\Steam App 233720) (Version: - Bossa Studios) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden System Requirements Lab for Intel (HKLM\...\{C7CA731B-BF9A-46D9-92CF-8A8737AE9240}) (Version: 4.5.13.0 - Husdawg, LLC) TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.13 - TeamSpeak Systems GmbH) TeamViewer 6 (HKLM\...\TeamViewer 6) (Version: 6.0.9947 - TeamViewer GmbH) The Elder Scrolls Online Beta (HKLM\...\The Elder Scrolls Online Beta_is1) (Version: 0.3.4 - ) To the Moon (HKLM\...\Steam App 206440) (Version: - Freebird Games) TOSHIBA Assist (HKLM\...\{12B3A009-A080-4619-9A2A-C6DB151D8D67}) (Version: 2.01.04 - TOSHIBA) TOSHIBA Benutzerhandbücher (HKLM\...\{1C971EE3-B4C4-4367-9676-57549919C6CE}) (Version: 7.40 - TOSHIBA) TOSHIBA ConfigFree (HKLM\...\{0D5D0BEE-FBA9-4928-A50D-6CDFAB827755}) (Version: 7.2.13 - TOSHIBA Corporation) TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.0.1.3 - TOSHIBA Corporation) TOSHIBA DVD PLAYER (HKLM\...\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}) (Version: 1.31.14 - TOSHIBA Corporation) TOSHIBA Extended Tiles for Windows Mobility Center (HKLM\...\InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}) (Version: 1.01.00 - Toshiba) TOSHIBA Extended Tiles for Windows Mobility Center (Version: 1.01.00 - Toshiba) Hidden TOSHIBA Face Recognition (HKLM\...\InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B}) (Version: 2.0.2.32 - TOSHIBA Corporation) TOSHIBA Face Recognition (Version: 2.0.2.32 - TOSHIBA Corporation) Hidden TOSHIBA Hardware Setup (HKLM\...\{2883F6F5-0509-43F3-868C-D50330DD9DD3}) (Version: 2.00.08 - ) Toshiba Online Product Information (HKLM\...\{2290A680-4083-410A-ADCC-7092C67FC052}) (Version: 1.00.0012 - TOSHIBA) TOSHIBA Recovery Disc Creator (HKLM\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.0.0.1b - TOSHIBA) TOSHIBA SD Memory Utilities (HKLM\...\{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}) (Version: 1.8.1.3 - TOSHIBA) TOSHIBA Software Modem (HKLM\...\TOSHIBA Software Modem) (Version: 2.1.77 (SM2177ALD04) - Agere Systems) TOSHIBA Supervisor Password (HKLM\...\{4B1E87C3-00DE-4898-8E39-E390AAEF2391}) (Version: 2.00.04 - ) Toshiba TEMPRO (HKLM\...\{03FAA727-E2B7-471C-AC41-2E1C7F29C7EA}) (Version: 1.1 - Toshiba Europe GmbH) TOSHIBA Value Added Package (HKLM\...\InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}) (Version: 1.1.19 - TOSHIBA Corporation) TOSHIBA Value Added Package (Version: 1.1.19 - TOSHIBA Corporation) Hidden TRDCReminder (HKLM\...\InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}) (Version: 1.00.0015 - TOSHIBA) TRDCReminder (Version: 1.00.0015 - TOSHIBA) Hidden TRORDCLauncher (HKLM\...\InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}) (Version: 1.0.0.1 - TOSHIBA) TRORDCLauncher (Version: 1.0.0.1 - TOSHIBA) Hidden TuneUp Utilities 2011 (HKLM\...\TuneUp Utilities 2011) (Version: 10.0.2011.65 - TuneUp Software) TuneUp Utilities 2011 (Version: 10.0.2011.65 - TuneUp Software) Hidden TuneUp Utilities Language Pack (en-US) (Version: 10.0.2011.65 - TuneUp Software) Hidden UltraVnc (HKLM\...\Ultravnc2_is1) (Version: 1.1.8 - uvnc bvba) Uninstall 1.0.0.1 (HKLM\...\Uninstall_is1) (Version: - ) Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{39767ECA-1731-45DB-AB5B-6BF40E151D66}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{BA610006-2C39-4419-9834-CF61AB24810A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUS_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUS_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2775360) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{80F56E3F-1D47-4E45-B6E0-FEF4E919F4F9}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUS_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{799005D3-9B70-4219-AFE0-BC479614CC4D}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft) Uplay (HKLM\...\Uplay) (Version: 4.0 - Ubisoft) VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0 - DivX, Inc) Hidden Velvet Assassin (HKLM\...\Steam App 16720) (Version: - Replay Studios) VirtualCloneDrive (HKLM\...\VirtualCloneDrive) (Version: - Elaborate Bytes) Visual C++ 2008 x86 Runtime - (v9.0.30729) (Version: 9.0.30729 - Microsoft Corporation) Hidden Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM\...\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation) VLC media player 2.1.1 (HKLM\...\VLC media player) (Version: 2.1.1 - VideoLAN) Winamp (HKLM\...\Winamp) (Version: 5.61 - Nullsoft, Inc) Winamp Anwendungserkennung (HKCU\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Windows Live ID Sign-in Assistant (HKLM\...\{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}) (Version: 6.500.3165.0 - Microsoft Corporation) Windows Media Encoder 9-Reihe (HKLM\...\Windows Media Encoder 9) (Version: - ) Windows Media Encoder 9-Reihe (Version: 9.00.3374 - Microsoft Corporation) Hidden Windows Phone 7 Add-in for Visual Studio 2010 - ENU (HKLM\...\{5DE94C5E-21D3-37DA-9378-6E409964A466}) (Version: 10.0.30319 - Microsoft Corporation) Windows Phone Emulator - ENU (HKLM\...\{F9B9C3E2-F779-3B3A-9092-454A2C5B64F3}) (Version: 10.0.30319 - Microsoft Corporation) WinPcap 4.1.3 (HKLM\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.) WinRAR 4.01 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH) Wireshark 1.10.5 (32-bit) (HKLM\...\Wireshark) (Version: 1.10.5 - The Wireshark developer community, hxxp://www.wireshark.org) WISO Bewerbung 2008 (HKLM\...\{FD065B02-AE17-4496-8C0F-FFD3A9FD9460}) (Version: 6.1.0.56 - Buhl Data Service GmbH) World of Warcraft (HKLM\...\World of Warcraft) (Version: 5.4.0.17399 - Blizzard Entertainment) Wrye Bash (HKLM\...\Wrye Bash) (Version: 0.3.0.3 - Wrye & Wrye Bash Development Team) XnView 1.97.8 (HKLM\...\XnView_is1) (Version: 1.97.8 - Gougelet Pierre-e) YTD Video Downloader 4.8 (HKLM\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.8 - GreenTree Applications SRL) Карточная игра в дурака 7.0 (HKLM\...\Карточная игра в дурака 7.0) (Version: - Конюхов Александр) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2006-11-02 12:23 - 2010-05-20 14:58 - 00001306 ___RA C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 pagead2.googlesyndication.com ==================== Scheduled Tasks (whitelisted) ============= Task: {06845CFB-6FEF-4AB0-900A-7D510DA95A96} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-11-30] (Google Inc.) Task: {07591A9E-B1DA-4FF8-AFBF-4E0390CE014C} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation) Task: {077E0840-15B7-43AA-9290-3B38E043CFA5} - System32\Tasks\Ad-Aware Update (Daily 3) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {0B554F72-3630-4D59-BF64-1552F750F2AA} - System32\Tasks\Ad-Aware Update (Daily 1) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {147EECFD-8FB3-4F1F-A281-8C4828129070} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2597287126-3799022477-3584391229-1000Core => C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-30] (Google Inc.) Task: {197D8C5D-0B30-4067-A656-33456F9B5B1D} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => c:\program files\windows defender\MpCmdRun.exe [2008-01-21] (Microsoft Corporation) Task: {1A4E5AC3-A2AE-49D3-93A1-C73CFAE917D1} - System32\Tasks\Ad-Aware Update (Daily 2) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {364FD7D6-4160-4138-B479-FE2A11C2DD5D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-11-30] (Google Inc.) Task: {3708A422-DCBD-45DD-89B1-569B0B362865} - System32\Tasks\Ad-Aware Update (Daily 4) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {3E7B9811-6783-4F05-A4A0-A16C7AF2754B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-09-19] (Piriform Ltd) Task: {443F5210-D2E9-445B-A1C3-2D8A44714501} - System32\Tasks\{E68435F9-1FB1-4136-9142-944D83456001} => Firefox.exe hxxp://ui.skype.com/ui/0/5.5.0.113.259/en/abandoninstall?page=tsPlugin&installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;userlevelpresent Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {4EF0C4E6-071F-4755-A0B0-8480A4946C6F} - System32\Tasks\Google Updater and Installer => C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-30] (Google Inc.) Task: {65B53797-7968-4860-AB67-377C67021690} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2011 => C:\Program Files\TuneUp Utilities 2011\OneClick.exe [2010-10-27] (TuneUp Software) Task: {6CE59EFE-883F-494D-AE97-E8A523B94C47} - System32\Tasks\{2EF2447B-73EA-47BB-84D6-B3401485EFB8} => C:\Program Files\Skype\Phone\Skype.exe [2014-02-10] (Skype Technologies S.A.) Task: {6E1B6976-6994-4FF1-B634-5E5C1D8CC824} - System32\Tasks\FRAPS => C:\Fraps\fraps.exe [2012-08-30] (Beepa P/L) Task: {71532537-9FC7-42DA-BCE1-1504F4819E4F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2597287126-3799022477-3584391229-1000UA => C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.) Task: {78E7CFF9-9918-41F3-80F9-49FB6DA23C44} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation) Task: {7CB191D9-0C0B-4387-8934-D0E3C8317DDD} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2597287126-3799022477-3584391229-1000UA => C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-30] (Google Inc.) Task: {B4525DD7-B5B2-4D82-B5B1-116A3DA5C1A0} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files\TuneUp Utilities 2011\OneClick.exe [2010-10-27] (TuneUp Software) Task: {B5D45EEE-DC70-4B53-A23A-0009E54DC66C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-16] (Adobe Systems Incorporated) Task: {D281501D-9C81-465D-A0B5-922DAA58FB76} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files\IObit\Game Booster 3\AutoUpdate.exe Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {FCE784A7-DA29-4C9F-A0B5-7999CE66D45D} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2597287126-3799022477-3584391229-1000Core => C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2597287126-3799022477-3584391229-1000Core.job => C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2597287126-3799022477-3584391229-1000UA.job => C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2597287126-3799022477-3584391229-1000Core.job => C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2597287126-3799022477-3584391229-1000UA.job => C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2008-04-24 18:25 - 2008-04-24 18:25 - 00126976 _____ () C:\Windows\system32\SmartFaceVCtrl.dll 2008-04-24 18:25 - 2008-04-24 18:25 - 06701056 _____ () C:\Windows\system32\FaceHI.dll 2008-04-24 18:25 - 2008-04-24 18:25 - 00995328 _____ () C:\Windows\system32\FaceRec.dll 2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2012-10-07 19:03 - 2007-09-02 13:57 - 00069632 _____ () C:\Program Files\RocketDock\RocketDock.dll 2010-06-18 21:36 - 2011-05-28 23:04 - 00140288 _____ () C:\Program Files\WinRAR\rarext.dll 2011-07-18 23:04 - 2011-07-18 23:04 - 00296448 _____ () C:\Program Files\Notepad++\NppShell_04.dll 2012-10-07 19:03 - 2007-09-02 13:58 - 00495616 _____ () C:\Program Files\RocketDock\RocketDock.exe 2012-12-02 12:16 - 2013-04-30 04:46 - 00037376 _____ () C:\Windows\system32\atitmpxx.dll 2014-05-14 14:27 - 2014-05-14 14:27 - 00137296 _____ () C:\Program Files\Avira\My Avira\Avira.OE.NativeCore.dll 2014-05-14 14:27 - 2014-05-14 14:27 - 00065616 _____ () C:\Program Files\Avira\My Avira\Avira.OE.AvConnectorNative.dll 2014-05-18 17:22 - 2014-05-14 14:27 - 00049744 _____ () C:\Users\Alex\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll 2014-01-09 19:33 - 2014-04-22 00:55 - 00340480 _____ () C:\Program Files\Steam\libavresample-1.dll 2014-04-25 10:57 - 2014-04-22 00:55 - 00471552 _____ () C:\Program Files\Steam\libavutil-53.dll 2013-07-01 08:20 - 2014-04-01 00:09 - 00754688 _____ () C:\Program Files\Steam\SDL2.dll 2013-07-26 14:46 - 2014-04-24 00:01 - 01092288 _____ () C:\Program Files\Steam\bin\chromehtml.dll 2013-07-15 14:32 - 2014-03-03 21:15 - 20626624 _____ () C:\Program Files\Steam\bin\libcef.dll 2013-06-14 15:49 - 2013-06-15 01:49 - 01100800 _____ () C:\Program Files\Steam\bin\avcodec-53.dll 2013-06-14 15:49 - 2013-06-15 01:49 - 00124416 _____ () C:\Program Files\Steam\bin\avutil-51.dll 2013-06-14 15:49 - 2013-06-15 01:49 - 00192000 _____ () C:\Program Files\Steam\bin\avformat-53.dll 2014-04-01 20:12 - 2014-04-01 20:13 - 03642480 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2014-05-18 17:34 - 2014-05-18 17:34 - 00050477 _____ () C:\Users\Alex\Downloads\Defogger.exe ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Alex\Anwendungsdaten:NT AlternateDataStreams: C:\Users\Alex\AppData\Roaming:NT AlternateDataStreams: C:\ProgramData\TEMP:AD022376 AlternateDataStreams: C:\ProgramData\TEMP:BF14D50A ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/18/2014 05:17:25 PM) (Source: .NET Runtime) (EventID: 1023) (User: ) Description: .NET Runtime version 2.0.50727.4247 - Schwerwiegender Fehler im Ausführungsmodul (742BD69E) (80131506). Error: (05/18/2014 05:17:21 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung raptr.exe, Version 3.7.4.0, Zeitstempel 0x4bbd3163, fehlerhaftes Modul QtCore4.dll, Version 4.8.2.0, Zeitstempel 0x4fa6d505, Ausnahmecode 0xc0000005, Fehleroffset 0x00001a63, Prozess-ID 0xbfc, Anwendungsstartzeit raptr.exe0. Error: (05/18/2014 05:17:11 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: WmiApRplC:\Windows\system32\wbem\wmiaprpl.dll4 Error: (05/18/2014 05:17:10 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4 Error: (05/18/2014 05:17:10 PM) (Source: PerfNet) (EventID: 2005) (User: ) Description: Error: (05/18/2014 05:17:10 PM) (Source: Perflib) (EventID: 1010) (User: ) Description: OutlookC:\PROGRA~1\Microsoft Office\Office14\OLMAPI32.DLL4 Error: (05/18/2014 05:17:09 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: MSDTCC:\Windows\system32\msdtcuiu.DLL4 Error: (05/18/2014 05:17:09 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: LsaC:\Windows\system32\Secur32.dll4 Error: (05/18/2014 05:17:09 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: ESENTC:\Windows\system32\esentprf.dll4 Error: (05/18/2014 05:17:08 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\system32\bitsperf.dll4 System errors: ============= Error: (05/18/2014 05:36:17 PM) (Source: Application Popup) (EventID: 1801) (User: ) Description: Die Hardware hat einen Speicherfehler gemeldet, der nicht behoben werden kann. Error: (05/18/2014 05:20:24 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT-AUTORITÄT) Description: 0x8000002a44\SystemRoot\System32\Config\RegBack\SOFTWARE Error: (05/18/2014 05:19:02 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: 1Neustart des DienstsRAS-Verbindungsverwaltung%%1056 Error: (05/18/2014 05:19:01 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: 1Neustart des DienstsWindows-Verwaltungsinstrumentation%%1056 Error: (05/18/2014 05:19:01 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: 1Neustart des DienstsComputerbrowser%%1056 Error: (05/18/2014 05:19:01 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: 1Neustart des DienstsBenutzerprofildienst%%1056 Error: (05/18/2014 05:10:24 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Bytes Speicher konnten durch den DNS-Proxy-Agenten nicht zugeordnet werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner Fehler ist im Speicher-Manager aufgetreten. Error: (05/18/2014 05:08:59 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Bytes Speicher konnten durch den DNS-Proxy-Agenten nicht zugeordnet werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner Fehler ist im Speicher-Manager aufgetreten. Error: (05/18/2014 04:27:09 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Bytes Speicher konnten durch den DNS-Proxy-Agenten nicht zugeordnet werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner Fehler ist im Speicher-Manager aufgetreten. Error: (05/18/2014 04:26:59 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Bytes Speicher konnten durch den DNS-Proxy-Agenten nicht zugeordnet werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner Fehler ist im Speicher-Manager aufgetreten. Microsoft Office Sessions: ========================= Error: (05/18/2014 05:17:25 PM) (Source: .NET Runtime) (EventID: 1023) (User: ) Description: .NET Runtime version 2.0.50727.4247 - Schwerwiegender Fehler im Ausführungsmodul (742BD69E) (80131506). Error: (05/18/2014 05:17:21 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: raptr.exe3.7.4.04bbd3163QtCore4.dll4.8.2.04fa6d505c000000500001a63bfc01cf72ac2360df91 Error: (05/18/2014 05:17:11 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: WmiApRplC:\Windows\system32\wbem\wmiaprpl.dll4 Error: (05/18/2014 05:17:10 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4 Error: (05/18/2014 05:17:10 PM) (Source: PerfNet) (EventID: 2005) (User: ) Description: Error: (05/18/2014 05:17:10 PM) (Source: Perflib) (EventID: 1010) (User: ) Description: OutlookC:\PROGRA~1\Microsoft Office\Office14\OLMAPI32.DLL4 Error: (05/18/2014 05:17:09 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: MSDTCC:\Windows\system32\msdtcuiu.DLL4 Error: (05/18/2014 05:17:09 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: LsaC:\Windows\system32\Secur32.dll4 Error: (05/18/2014 05:17:09 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: ESENTC:\Windows\system32\esentprf.dll4 Error: (05/18/2014 05:17:08 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\system32\bitsperf.dll4 CodeIntegrity Errors: =================================== Date: 2014-05-18 17:39:51.669 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-18 17:39:51.457 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-18 17:39:51.270 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-18 17:39:51.091 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-18 17:30:32.072 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-18 17:30:31.897 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-18 17:30:31.727 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-18 17:30:31.558 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-18 17:28:40.407 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-18 17:28:40.178 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 64% Total physical RAM: 3069.26 MB Available physical RAM: 1102.69 MB Total Pagefile: 6337.66 MB Available Pagefile: 4068.48 MB Total Virtual: 2047.88 MB Available Virtual: 1895.48 MB ==================== Drives ================================ Drive c: (Vista) (Fixed) (Total:116.21 GB) (Free:9.63 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:232.89 GB) (Free:21.41 GB) NTFS Drive f: (Data) (Fixed) (Total:115.21 GB) (Free:69.36 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: FCFD687F) Partition 1: (Not Active) - (Size=1 GB) - (Type=27) Partition 2: (Active) - (Size=116 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=115 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: EEEEEEEE) Partition 1: (Not Active) - (Size=233 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
19.05.2014, 00:31 | #4 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Programme gehen einfach aus und Avira Echtzeitscanner sowie normaler scan funktionieren nicht, das gleiche bei Malwarebytes...Zitat:
Code:
ATTFilter S2 KMService; C:\Windows\system32\srvany.exe [8192 2003-04-18] () Code:
ATTFilter 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com Bitte lesen => http://www.trojaner-board.de/95393-c...-software.html Es geht weiter wenn du alles Illegale entfernt hast. Bei wiederholten Crack/Keygen Verstößen behalte ich es mir vor, den Support einzustellen, d.h. Hilfe nur noch bei der Datensicherung und Neuinstallation des Betriebssystems.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Programme gehen einfach aus und Avira Echtzeitscanner sowie normaler scan funktionieren nicht, das gleiche bei Malwarebytes... |
abgesicherten, abnormal viele funde, abstürze, avira, bluescreen, c:\windows, echtzeit-scanner, einfach, fehlermeldung, firefox, funktionieren, gestoppt, großes, infizierte, logfiles, malwarebytes, memory_management, nichts, plötzliche pc abstürze, problem, programme, rootkit, rootkits, scan, scannen, scanner, schnellen, surfen, system, system32, windows |