|
Plagegeister aller Art und deren Bekämpfung: Avira durch Gruppenrichtlinie geblockt - Trojaner?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
15.06.2014, 00:37 | #1 |
| Avira durch Gruppenrichtlinie geblockt - Trojaner? Hallo, ich habe jetzt wohl ein ernsthaftes Problem auf meinem Laptop, Windows Vista, 32 Bit-Betriebssystem, Home Premium. Ich kann Avira nicht mehr starten und nur sehr schwer deinstallieren, da die Fehlermeldung kommt, dass das Programm durch eine Gruppenrichtlinie geblockt ist und ich mich an den Systemadministrator wenden soll. Eine Mitteilung meiner Bank habe ich auch schon bekommen, dass meine Online-Banking-Daten ausgespäht worden sind und auf einem ausländischen Phishing-Server gespeichert worden sind. Ich habe schon AVG 2014 und Kaspersky installiert und laufen lassen und da ist jetzt soweit alles in Ordnung. Die ein, zwei Bedrohungen sind neutralisiert, die dort angezeigt worden sind. Im gesicherten Modus war ich anschließend, um Avira mit dem "Avira Registry Cleaner" komplett deinstallieren zu können. Nach Neuinstallation zeigt er mir die gleiche Fehlermeldung noch an. Also scheint es wirklich ein Trojaner zu sein. Ich kenne mich leider so gar nicht aus und habe versucht, mich ein bisschen schlau zu lesen... Kann mir jemand helfen? Vielen, vielen Dank! Grüße, Lorelai! |
15.06.2014, 00:42 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Avira durch Gruppenrichtlinie geblockt - Trojaner? Hallo und
__________________Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
15.06.2014, 02:20 | #3 |
| Avira durch Gruppenrichtlinie geblockt - Trojaner? Hallo,
__________________schon mal vielen Dank für die Hilfe. Leider bin ich überhaupt nicht fit in Informatik und hab jetzt versucht, den Schritten zu folgen. Ich habe Malwarebytes Anti-Malware, Emsisoft Anti Malware und ESET Online Scan nicht. Avira kann ich nicht öffnen, sodass ich leider nicht weiß, wie ich Logs in Kaspersky auslesen kann. Ich hab eine Datei mit dem Screenshot der Funde bei Kaspersky mal angehängt. Vielleicht hilft das weiter... Außer dass im Internet Explorer keine Downloads mehr möglich sind seit einer Woche, ist mir nichts weiteres aufgefallen. Hier ist FRST (hab meinen Nachnamen überall gelöscht): FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:12-06-2014 02 Ran by Claudia (administrator) on CLAUDIA1 on 15-06-2014 02:11:49 Running from C:\Users\Claudia\Desktop Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Google Inc.) C:\Program Files\Google\Update\1.3.24.7\GoogleCrashHandler.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (ABBYY) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe (Empolis GmbH) C:\Program Files\Common Files\Gnab\Service\ServiceController.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Empolis GmbH) C:\Program Files\Medion\MEDIONbox\Program\GCS.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe (InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPStart.exe () C:\Program Files\Launch Manager\LaunchAp.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe (Wistron) C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron Corp.) C:\Program Files\Launch Manager\OSD.exe (Wistron) C:\Program Files\Launch Manager\WButton.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe () C:\Windows\System32\PSIService.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe () C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe (Buhl Data Service GmbH) C:\Program Files\Sceneo\AbsolutTV\Services\PVR\pvrservice.exe (SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe (Sonix) C:\Windows\vsnp2uvc.exe () C:\Windows\FixCamera.exe () C:\Windows\tsnp2uvc.exe () C:\Program Files\1&1 Surf-Stick\AssistantServices.exe () C:\Program Files\1&1 Surf-Stick\UIExec.exe () C:\Program Files\TV IR\TV IR.exe (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Google Inc.) C:\Program Files\Picasa2\PicasaMediaDetector.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGCE.EXE (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGCE.EXE (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (1&1 Mail & Media GmbH) C:\Users\Claudia\AppData\Local\GMX Application {sync-000021}\gmx_mediacenter.exe (Microsoft Corporation) C:\Windows\System32\p2phost.exe (ArcSoft, Inc.) C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe (Dropbox, Inc.) C:\Users\Claudia Grützmacher\AppData\Roaming\Dropbox\bin\Dropbox.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (Wistron Corp.) C:\Program Files\Launch Manager\WisLMSvc.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Opera Software) C:\Program Files\Opera\opera.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [178712 2007-10-03] (Intel Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6025216 2008-04-01] (Realtek Semiconductor) HKLM\...\Run: [SynTPStart] => C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2007-08-31] (Synaptics, Inc.) HKLM\...\Run: [LaunchAp] => C:\Program Files\Launch Manager\LaunchAp.exe [32768 2007-09-01] () HKLM\...\Run: [HotkeyApp] => C:\Program Files\Launch Manager\HotkeyApp.exe [188416 2007-09-06] (Wistron) HKLM\...\Run: [CtrlVol] => "C:\Program Files\Launch Manager\CtrlVol.exe" HKLM\...\Run: [LMgrOSD] => C:\Program Files\Launch Manager\OSD.exe [180224 2006-12-26] (Wistron Corp.) HKLM\...\Run: [Wbutton] => C:\Program Files\Launch Manager\Wbutton.exe [86016 2007-09-07] (Wistron) HKLM\...\Run: [toolbar_eula_launcher] => C:\Program Files\GoogleEULA\EULALauncher.exe [16896 2007-02-09] ( ) HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [Corel Photo Downloader] => "C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel PhotoDownloader.exe" -startup HKLM\...\Run: [Corel File Shell Monitor] => C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe [16200 2007-10-30] () HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.) HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [976320 2009-12-03] (SEIKO EPSON CORPORATION) HKLM\...\Run: [snp2uvc] => C:\Windows\vsnp2uvc.exe [581632 2007-11-30] (Sonix) HKLM\...\Run: [FixCamera] => C:\Windows\FixCamera.exe [20480 2007-02-12] () HKLM\...\Run: [tsnp2uvc] => C:\Windows\tsnp2uvc.exe [249856 2007-12-04] () HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40368 2011-05-27] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-03-29] (Adobe Systems Incorporated) HKLM\...\Run: [UIExec] => C:\Program Files\1&1 Surf-Stick\UIExec.exe [139088 2010-09-30] () HKLM\...\Run: [TV IR] => C:\Program Files\TV IR\TV IR.exe [692318 2010-12-22] () HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH) HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [183376 2014-05-14] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-09] (Avira Operations GmbH & Co. KG) HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\McAfee <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\Avira <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Avira <====== ATTENTION HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [1828136 2008-02-28] (Nero AG) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Picasa Media Detector] => C:\Program Files\Picasa2\PicasaMediaDetector.exe [443968 2008-02-26] (Google Inc.) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [EPSON SX420W Series] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIGCE.EXE [200704 2009-09-14] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Epson Stylus SX420W(Netzwerk)] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIGCE.EXE [200704 2009-09-14] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Device Detection] => C:\Program Files\Lidl_Fotos\dd.exe HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [GMX Application {sync-000021}] => C:\Users\Claudia Grützmacher\AppData\Local\GMX Application {sync-000021}\gmx_mediacenter.exe [878080 2013-08-09] (1&1 Mail & Media GmbH) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [CollaborationHost] => C:\Windows\system32\p2phost.exe [192000 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\RunOnce: [Shockwave Updater] - C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1100429.exe [439736 2008-03-19] (Adobe Systems, Inc.) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\MountPoints2: {680ae5c9-5a41-11de-81b4-0015afb8023d} - G:\BlueJ.bat HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\MountPoints2: {b7bf007e-eef6-11e3-92c0-000ae4cddb4b} - F:\HTC_Sync_Manager_PC.exe AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL File Not Found Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk ShortcutTarget: TMMonitor.lnk -> C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.) Startup: C:\Users\Claudia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Claudia\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} URLSearchHook: HKLM - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File URLSearchHook: HKLM - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File URLSearchHook: HKLM - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.) URLSearchHook: HKCU - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File URLSearchHook: HKCU - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.) SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 SearchScopes: HKCU - {01_TL-YODL-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_google&q={searchTerms} SearchScopes: HKCU - {03_TL-TELEFONBUCH-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_telefonbuch&q={searchTerms} SearchScopes: HKCU - {04_TL-AMAZON-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_amazon&q={searchTerms} SearchScopes: HKCU - {05_TL-EBAY-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_ebay&q={searchTerms} SearchScopes: HKCU - {06_TL-DISCOUNT24-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_discount24&q={searchTerms} SearchScopes: HKCU - {07_TL-CONRAD-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_conrad&q={searchTerms} SearchScopes: HKCU - {08_TL-OTTO-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_otto&q={searchTerms} SearchScopes: HKCU - {09_TL-CLIPFISH-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_clipfish&q={searchTerms} SearchScopes: HKCU - {10_TL-MYVIDEO-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_myvideo&q={searchTerms} SearchScopes: HKCU - {11_TL-MUSICLOAD-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_musicload&q={searchTerms} SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 SearchScopes: HKCU - {CF739809-1C6C-47C0-85B9-569DBB141420} URL = hxxp://toolbar.ask.com/toolbarv/askRedirect?gct=&gc=1&q={searchTerms}&crm=1&toolbar=DVS SearchScopes: HKCU - {DBAFD4EB-E4E1-4A25-97C2-D1CB5F7D0368} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=971163&p={searchTerms} BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.) BHO: No Name - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.) BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO: DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File Toolbar: HKLM - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Toolbar: HKLM - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.) Toolbar: HKLM - Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - DVDVideoSoftTB Toolbar - {E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} hxxp://photoservice.fujicolor.de/ips-opdata/objects/jordan.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 83.169.185.161 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default FF DefaultSearchEngine: ICQ Search FF SearchEngineOrder.1: Ask FF SelectedSearchEngine: ICQ Search FF Homepage: hxxp://www.hiergehtslos.de FF Keyword.URL: hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdivx32.dll (DivX,Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Claudia Grützmacher\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\ask.xml FF SearchPlugin: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\icqplugin-1.xml FF SearchPlugin: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\icqplugin.xml FF SearchPlugin: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\clipfish.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\conrad.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\discount24.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\ebay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\musicload.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\myvideo.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\otto.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\quelle.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\telefonbuch-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\webnews.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Microsoft .NET Framework Assistant - C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2009-08-13] FF Extension: ICQ Toolbar - C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2011-04-24] FF Extension: DVDVideoSoftTB Community Toolbar - C:\Users\Claudia Grützmacher\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2011-10-29] FF Extension: Free YouTube Download (Free Studio) Menu - C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2012-12-31] FF Extension: DVDVideoSoft Toolbar - C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} [2009-12-18] FF Extension: Firefox Companion for eBay - C:\Program Files\Mozilla Firefox\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088} [2008-11-14] FF Extension: ICQ Toolbar - C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2008-12-15] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKLM\...\Firefox\Extensions: - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: 卡巴斯基網址顧問 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-14] FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: 虛擬鍵盤 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-14] FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: 惡意網站攔截器 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-14] FF HKCU\...\Thunderbird\Extensions: [{0E810812-F4BB-4309-942A-755587587A5E}] - C:\Program Files\BullGuard Software\BullGuard\antispam\tbspamfilter Chrome: ======= CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll () CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (DivX Web Player) - C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll (DivX,Inc.) CHR Plugin: (DivX Player Netscape Plugin) - C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc) CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Plugin: (Picasa) - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2014-06-14] CHR Extension: (Google Wallet) - C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-14] CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [2014-06-14] CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2012-12-31] ========================== Services (Whitelisted) ================= R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY) R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG) R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [123984 2014-05-14] (Avira Operations GmbH & Co. KG) R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files\ALDI Foto Service Nord\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) [File not signed] R2 GnabService; c:\program files\common files\gnab\service\servicecontroller.exe [36864 2007-04-19] (Empolis GmbH) [File not signed] S2 gupdate1c9e6034feeea56; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-06-05] (Google Inc.) R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] () [File not signed] R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1801216 2008-02-28] (Buhl Data Service GmbH) [File not signed] R2 UI Assistant Service; C:\Program Files\1&1 Surf-Stick\AssistantServices.exe [253264 2010-09-30] () R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [61440 2006-06-14] (Ulead Systems, Inc.) [File not signed] S3 usnjsvc; C:\Program Files\MSN Messenger\usnsvc.exe [97136 2007-01-19] (Microsoft Corporation) R3 WisLMSvc; C:\Program Files\Launch Manager\WisLMSvc.exe [118784 2007-09-11] (Wistron Corp.) [File not signed] ==================== Drivers (Whitelisted) ==================== R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) [File not signed] R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [122136 2014-05-13] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [198936 2014-05-13] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [149784 2014-05-13] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-05-13] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [192280 2014-05-13] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [237848 2014-05-13] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [107288 2014-05-13] (AVG Technologies CZ, s.r.o.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [93528 2014-05-09] (Avira Operations GmbH & Co. KG) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-05-13] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [210200 2014-05-13] (AVG Technologies CZ, s.r.o.) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-05-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2014-05-09] (Avira Operations GmbH & Co. KG) S3 DVC; C:\Windows\System32\Drivers\DVC.sys [38401 2001-09-09] (Samsung Electronics) [File not signed] R1 Hotkey; C:\Windows\system32\Drivers\Hotkey.sys [9867 2003-04-28] () [File not signed] R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-06-14] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576608 2014-06-14] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-06-14] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2014-06-14] (Kaspersky Lab ZAO) R0 Si3531; C:\Windows\System32\DRIVERS\Si3531.sys [212008 2008-07-25] (Silicon Image, Inc) R0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [17064 2008-07-25] (Silicon Image, Inc.) R0 SiRemFil; C:\Windows\System32\DRIVERS\SiRemFil.sys [12200 2008-07-25] (Silicon Image, Inc.) S3 smsbda; C:\Windows\System32\drivers\smsbda.sys [45440 2011-03-06] (Siano) S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [9610880 2007-11-29] () S1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2014-05-09] (Avira GmbH) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] U5 klflt; C:\Windows\System32\Drivers\klflt.sys [94304 2014-06-14] (Kaspersky Lab ZAO) S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-15 02:11 - 2014-06-15 02:14 - 00034989 _____ () C:\Users\Claudia\Desktop\FRST.txt 2014-06-15 02:05 - 2014-06-15 02:12 - 00000000 ____D () C:\FRST 2014-06-15 02:03 - 2014-06-15 02:03 - 01073152 _____ (Farbar) C:\Users\Claudia\Desktop\FRST.exe 2014-06-15 00:42 - 2014-06-15 00:42 - 00001006 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-06-15 00:42 - 2014-06-15 00:42 - 00000000 ____D () C:\ProgramData\Package Cache 2014-06-15 00:41 - 2014-06-15 00:41 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Claudia Grützmacher\Desktop\avira_de_av_4019404326__ws.exe 2014-06-14 22:13 - 2014-06-14 22:13 - 00227096 _____ () C:\Users\Claudia\Desktop\avira_registry_cleaner_de.exe 2014-06-14 14:46 - 2014-06-14 14:46 - 00262144 _____ () C:\Windows\system32\config\elam 2014-06-14 14:04 - 2014-06-14 14:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus 2014-06-14 14:04 - 2014-06-14 14:02 - 00000970 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2014-06-14 13:57 - 2014-06-15 01:49 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-06-14 13:57 - 2014-06-14 14:31 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-06-14 13:57 - 2014-06-14 14:31 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-06-14 13:57 - 2014-06-14 13:57 - 00000000 ____D () C:\Program Files\Kaspersky Lab 2014-06-14 01:15 - 2014-06-14 01:15 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\PeerNetworking 2014-06-13 22:53 - 2014-06-13 22:53 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\AVG2014 2014-06-13 22:52 - 2014-06-13 22:52 - 00000862 _____ () C:\Users\Public\Desktop\AVG 2014.lnk 2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\TuneUp Software 2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2014-06-13 22:50 - 2014-06-13 22:53 - 00000000 ____D () C:\ProgramData\AVG2014 2014-06-13 22:50 - 2014-06-13 22:50 - 00000000 ___HD () C:\$AVG 2014-06-13 22:49 - 2014-06-13 22:49 - 00000000 ____D () C:\Program Files\AVG 2014-06-13 22:47 - 2014-06-14 18:29 - 00000000 ____D () C:\ProgramData\MFAData 2014-06-13 22:47 - 2014-06-13 22:58 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Avg2014 2014-06-13 22:47 - 2014-06-13 22:47 - 00000000 ____D () C:\Users\Claudia\AppData\Local\MFAData 2014-06-13 22:42 - 2014-06-13 22:45 - 164819976 _____ (AVG Technologies) C:\Users\Claudia\Desktop\avg_free_x64_all_2014_4592a7484.exe 2014-06-13 21:56 - 2014-06-13 22:41 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Nico Mak Computing 2014-06-11 19:28 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-11 19:27 - 2014-05-28 18:48 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-11 19:27 - 2014-05-28 18:39 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-11 19:27 - 2014-05-28 18:38 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-11 19:27 - 2014-05-28 18:33 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-11 19:27 - 2014-05-28 18:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-11 19:27 - 2014-05-28 18:32 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-11 19:27 - 2014-05-28 18:31 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-06-11 19:27 - 2014-05-28 18:31 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-11 19:27 - 2014-05-28 18:30 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-06-11 19:27 - 2014-05-28 18:29 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-11 19:27 - 2014-05-28 18:29 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-11 19:27 - 2014-05-28 18:29 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-11 19:27 - 2014-05-28 18:29 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-06-11 19:27 - 2014-05-28 18:29 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-06-11 19:27 - 2014-05-28 18:28 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-11 19:27 - 2014-04-05 04:42 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-11 19:27 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-11 19:27 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-08 13:24 - 2014-06-08 13:24 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf 2014-06-08 12:54 - 2014-06-08 12:54 - 00000000 ____D () C:\Program Files\HTC 2014-06-08 12:45 - 2014-06-08 12:45 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Downloaded Installations 2014-06-08 12:42 - 2014-06-08 12:56 - 00000000 ____D () C:\Temp 2014-06-08 12:42 - 2014-06-08 12:42 - 00000000 ____D () C:\ProgramData\HTC 2014-06-08 12:42 - 2009-06-10 09:49 - 00024576 _____ (HTC, Corporation) C:\Windows\system32\Drivers\ANDROIDUSB.sys 2014-06-08 12:42 - 2009-06-09 07:41 - 01122664 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll 2014-06-07 20:30 - 2014-06-07 20:30 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Adobe 2014-06-07 19:59 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet (1).RequestDispatcherServlet 2014-06-07 19:56 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet.RequestDispatcherServlet 2014-05-18 00:39 - 2014-05-18 00:39 - 00000000 ____D () C:\Users\Claudia\restore 2014-05-18 00:02 - 2014-06-14 01:26 - 00000000 ____D () C:\ProgramData\tmp 2014-05-18 00:02 - 2014-05-18 16:35 - 00000000 ____D () C:\ProgramData\hps 2014-05-18 00:01 - 2014-05-18 00:01 - 00001106 _____ () C:\Users\Public\Desktop\OnlineFotoservice.lnk 2014-05-18 00:01 - 2014-05-18 00:01 - 00001091 _____ () C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk 2014-05-18 00:01 - 2014-05-18 00:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OnlineFotoservice 2014-05-17 23:20 - 2014-05-17 23:20 - 00000000 ____D () C:\Program Files\OnlineFotoservice 2014-05-16 20:11 - 2014-05-16 20:11 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2014-05-16 19:46 - 2014-03-25 15:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll ==================== One Month Modified Files and Folders ======= 2014-06-15 02:14 - 2014-06-15 02:11 - 00034989 _____ () C:\Users\Claudia\Desktop\FRST.txt 2014-06-15 02:14 - 2008-08-07 14:00 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Temp 2014-06-15 02:12 - 2014-06-15 02:05 - 00000000 ____D () C:\FRST 2014-06-15 02:06 - 2012-09-08 16:32 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Dropbox 2014-06-15 02:05 - 2009-06-30 19:24 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-15 02:03 - 2014-06-15 02:03 - 01073152 _____ (Farbar) C:\Users\Claudia\Desktop\FRST.exe 2014-06-15 01:49 - 2014-06-14 13:57 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-06-15 01:24 - 2006-11-02 14:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-15 01:24 - 2006-11-02 14:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-15 01:11 - 2008-01-21 09:16 - 01643446 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-15 00:48 - 2008-08-07 13:55 - 01501350 _____ () C:\Windows\WindowsUpdate.log 2014-06-15 00:42 - 2014-06-15 00:42 - 00001006 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-06-15 00:42 - 2014-06-15 00:42 - 00000000 ____D () C:\ProgramData\Package Cache 2014-06-15 00:42 - 2012-11-25 22:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-06-15 00:42 - 2012-10-23 16:35 - 00000000 ____D () C:\ProgramData\Avira 2014-06-15 00:42 - 2012-10-23 16:35 - 00000000 ____D () C:\Program Files\Avira 2014-06-15 00:41 - 2014-06-15 00:41 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Claudia\Desktop\avira_de_av_4019404326__ws.exe 2014-06-15 00:35 - 2014-05-13 22:19 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\DropboxMaster 2014-06-15 00:35 - 2012-09-08 16:36 - 00000000 ___RD () C:\Users\Claudia\Dropbox 2014-06-15 00:31 - 2009-06-30 19:24 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-15 00:31 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-15 00:24 - 2006-11-02 15:01 - 00032534 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-06-14 22:13 - 2014-06-14 22:13 - 00227096 _____ () C:\Users\Claudia\Desktop\avira_registry_cleaner_de.exe 2014-06-14 19:19 - 2012-11-17 22:37 - 00001967 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-06-14 18:29 - 2014-06-13 22:47 - 00000000 ____D () C:\ProgramData\MFAData 2014-06-14 15:05 - 2008-01-21 04:47 - 00431444 _____ () C:\Windows\PFRO.log 2014-06-14 14:46 - 2014-06-14 14:46 - 00262144 _____ () C:\Windows\system32\config\elam 2014-06-14 14:31 - 2014-06-14 13:57 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-06-14 14:31 - 2014-06-14 13:57 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-06-14 14:31 - 2013-10-17 15:47 - 00135776 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2014-06-14 14:31 - 2013-10-17 15:47 - 00025184 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys 2014-06-14 14:31 - 2013-06-06 17:38 - 00144992 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys 2014-06-14 14:04 - 2014-06-14 14:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus 2014-06-14 14:02 - 2014-06-14 14:04 - 00000970 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2014-06-14 14:01 - 2008-08-07 14:00 - 00000000 ____D () C:\Users\Claudia 2014-06-14 13:57 - 2014-06-14 13:57 - 00000000 ____D () C:\Program Files\Kaspersky Lab 2014-06-14 01:26 - 2014-05-18 00:02 - 00000000 ____D () C:\ProgramData\tmp 2014-06-14 01:15 - 2014-06-14 01:15 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\PeerNetworking 2014-06-13 22:58 - 2014-06-13 22:47 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Avg2014 2014-06-13 22:53 - 2014-06-13 22:53 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\AVG2014 2014-06-13 22:53 - 2014-06-13 22:50 - 00000000 ____D () C:\ProgramData\AVG2014 2014-06-13 22:52 - 2014-06-13 22:52 - 00000862 _____ () C:\Users\Public\Desktop\AVG 2014.lnk 2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\TuneUp Software 2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2014-06-13 22:50 - 2014-06-13 22:50 - 00000000 ___HD () C:\$AVG 2014-06-13 22:49 - 2014-06-13 22:49 - 00000000 ____D () C:\Program Files\AVG 2014-06-13 22:47 - 2014-06-13 22:47 - 00000000 ____D () C:\Users\Claudia\AppData\Local\MFAData 2014-06-13 22:45 - 2014-06-13 22:42 - 164819976 _____ (AVG Technologies) C:\Users\Claudia\Desktop\avg_free_x64_all_2014_4592a7484.exe 2014-06-13 22:41 - 2014-06-13 21:56 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Nico Mak Computing 2014-06-11 20:10 - 2008-04-21 14:41 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-06-11 20:05 - 2013-08-06 20:05 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-11 20:05 - 2006-11-02 12:24 - 92708840 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-06-11 19:53 - 2008-11-30 15:45 - 00002627 _____ () C:\Users\Claudia\Desktop\Microsoft Office Word 2007.lnk 2014-06-11 19:49 - 2009-08-24 13:59 - 00000000 ____D () C:\Users\Claudia\Documents\Bewerbung 2014-06-09 01:59 - 2008-08-07 18:11 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Corel 2014-06-09 00:54 - 2008-08-07 19:39 - 00000000 ____D () C:\Users\Claudia\Documents\My PSP Files 2014-06-09 00:54 - 2008-08-07 18:12 - 00004182 ___SH () C:\Windows\system32\KGyGaAvL.sys 2014-06-08 13:24 - 2014-06-08 13:24 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf 2014-06-08 13:24 - 2006-11-02 14:52 - 00162202 _____ () C:\Windows\setupact.log 2014-06-08 12:56 - 2014-06-08 12:42 - 00000000 ____D () C:\Temp 2014-06-08 12:54 - 2014-06-08 12:54 - 00000000 ____D () C:\Program Files\HTC 2014-06-08 12:54 - 2008-04-21 09:32 - 00025966 _____ () C:\Windows\DPINST.LOG 2014-06-08 12:45 - 2014-06-08 12:45 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Downloaded Installations 2014-06-08 12:42 - 2014-06-08 12:42 - 00000000 ____D () C:\ProgramData\HTC 2014-06-07 20:30 - 2014-06-07 20:30 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Adobe 2014-06-07 20:25 - 2012-07-08 20:11 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-06-07 20:25 - 2011-07-13 22:41 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-06-07 19:59 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet (1).RequestDispatcherServlet 2014-06-07 19:59 - 2014-06-07 19:56 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet.RequestDispatcherServlet 2014-06-07 19:57 - 2008-04-21 10:34 - 00000000 ____D () C:\ProgramData\Adobe 2014-05-28 18:48 - 2014-06-11 19:27 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-28 18:39 - 2014-06-11 19:27 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-05-28 18:38 - 2014-06-11 19:27 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-05-28 18:33 - 2014-06-11 19:27 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-05-28 18:32 - 2014-06-11 19:27 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-05-28 18:32 - 2014-06-11 19:27 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-05-28 18:31 - 2014-06-11 19:27 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-05-28 18:31 - 2014-06-11 19:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-05-28 18:30 - 2014-06-11 19:27 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-05-28 18:29 - 2014-06-11 19:27 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-28 18:29 - 2014-06-11 19:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-05-28 18:29 - 2014-06-11 19:27 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-28 18:29 - 2014-06-11 19:27 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-05-28 18:29 - 2014-06-11 19:27 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-05-28 18:28 - 2014-06-11 19:27 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-05-24 12:35 - 2012-09-08 16:36 - 00000965 _____ () C:\Users\Claudia\Desktop\Dropbox.lnk 2014-05-24 12:35 - 2012-09-08 16:33 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-05-18 21:51 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-05-18 19:45 - 2009-06-08 18:48 - 00000000 ____D () C:\Program Files\Picasa2 2014-05-18 19:10 - 2009-11-15 15:52 - 00130060 _____ () C:\Users\Claudia\AppData\Roaming\mdbu.bin 2014-05-18 16:35 - 2014-05-18 00:02 - 00000000 ____D () C:\ProgramData\hps 2014-05-18 00:39 - 2014-05-18 00:39 - 00000000 ____D () C:\Users\Claudia\restore 2014-05-18 00:01 - 2014-05-18 00:01 - 00001106 _____ () C:\Users\Public\Desktop\OnlineFotoservice.lnk 2014-05-18 00:01 - 2014-05-18 00:01 - 00001091 _____ () C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk 2014-05-18 00:01 - 2014-05-18 00:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OnlineFotoservice 2014-05-17 23:20 - 2014-05-17 23:20 - 00000000 ____D () C:\Program Files\OnlineFotoservice 2014-05-16 20:11 - 2014-05-16 20:11 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER Files to move or delete: ==================== C:\Users\Claudia\AppData\Roaming\desktop.ini Some content of TEMP: ==================== C:\Users\Claudia\AppData\Local\Temp\ABD2BC~1.exe C:\Users\Claudia\AppData\Local\Temp\AdobeUpdater12345.exe C:\Users\Claudia\AppData\Local\Temp\AskSLib.dll C:\Users\Claudia\AppData\Local\Temp\avgnt.exe C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuztmgc.dll C:\Users\Claudia\AppData\Local\Temp\ffunzip.exe C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate.exe C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate01.exe C:\Users\Claudia\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe C:\Users\Claudia\AppData\Local\Temp\GDM272F.exe C:\Users\Claudia\AppData\Local\Temp\GDM34A6.exe C:\Users\Claudia\AppData\Local\Temp\GLF3BB0.tmp.ConduitEngineSetup.exe C:\Users\Claudia\AppData\Local\Temp\GoogleChromeInstaller.exe C:\Users\Claudia\AppData\Local\Temp\IcqUpdater.exe C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssa_aih[1].exe C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssd_aih[1].exe C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10_mssd_aih.exe C:\Users\Claudia\AppData\Local\Temp\JiveXViewerStart1363355292.exe C:\Users\Claudia\AppData\Local\Temp\Opera_1150_int_Setup.exe C:\Users\Claudia\AppData\Local\Temp\prxGLF3BB0.tmp.tbDVDV.dll C:\Users\Claudia\AppData\Local\Temp\SearchWithGoogleUpdate.exe C:\Users\Claudia\AppData\Local\Temp\tbDVDV.dll C:\Users\Claudia\AppData\Local\Temp\unwise.exe C:\Users\Claudia\AppData\Local\Temp\VisusClient.dll C:\Users\Claudia\AppData\Local\Temp\wpsetup.exe C:\Users\Claudia\AppData\Local\Temp\_is30.exe C:\Users\Claudia\AppData\Local\Temp\_is6CF6.exe C:\Users\Claudia\AppData\Local\Temp\_is92AD.exe C:\Users\Claudia\AppData\Local\Temp\{1167C4F7-64B6-4A1D-A0A5-B605C6CDE10F}-26.0.1410.64_25.0.1364.172_chrome_updater.exe C:\Users\Claudia\AppData\Local\Temp\{5A7A4717-CEF4-4E4A-B23E-0838114D47F8}-chrome_installer.exe C:\Users\Claudia\AppData\Local\Temp\{C2722232-3395-42BA-9B03-4B2C787E8081}-chrome_installer.exe C:\Users\Claudia\AppData\Local\Temp\{D2416B08-7E6C-4C05-B27E-05A6DEC53BCD}-30.0.1599.69_29.0.1547.76_chrome_updater.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-15 00:39 ==================== End Of Log ============================ Additional scan result of Farbar Recovery Scan Tool (x86) Version:12- 06-2014 02 Ran by Claudia at 2014-06-15 02:15:54 Running from C:\Users\Claudia\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768- AAE50FA36859} AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4- 06B3-7FA0-3AB1-6E49CB52ECD9} AV: Kaspersky Anti-Virus (Enabled - Up to date) {179979E8-273D-D14E- 0543-2861940E4886} AS: Kaspersky Anti-Virus (Enabled - Up to date) {ACF8980C-0107-DEC0- 3FF3-1313EF89023B} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8- 9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44 -DA132C1ACF46} AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120- 2089-702E-0001-553BB0D5A664} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{90120000- 0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0C5823AA-7B6F-44E1-8D5B- 8FD1FF0E6438}) (Version: - Microsoft) Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{91120000- 002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-7B6F-44E1-8D5B- 8FD1FF0E6438}) (Version: - Microsoft) 1&1 Surf-Stick (HKLM\...\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.2 - ) 3531-W-D (HKLM\...\{BD1587F7-B8D0-4111-8F1F-3327628AB02F}) (Version: 1.5.18 - Silicon Image) AAC Decoder (HKLM\...\{AEF9DC35ADDF4825B049ACBFD1C6EB37}) (Version: 7.1.0 - DivX, Inc.) ABBYY FineReader 6.0 Sprint (HKLM\...\{ACF60000-22B9-4CE9-98D6- 2CCF359BAC07}) (Version: 6.00.1395.4512 - ABBYY Software House) ABBYY FineReader 9.0 Sprint (HKLM\...\ABBYY FineReader 9.0 Sprint) (Version: 9.01.513.58212 - ABBYY) ABBYY FineReader 9.0 Sprint (Version: 9.01.513.58212 - ABBYY) Hidden Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 13 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Reader 8.3.0 - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44- A83000000003}) (Version: 8.3.0 - Adobe Systems Incorporated) Adobe Shockwave Player (HKLM\...\Adobe Shockwave Player) (Version: 11 - Adobe Systems, Inc.) Agere Systems HDA Modem (HKLM\...\Agere Systems Soft Modem) (Version: - Agere Systems) ArcSoft MediaConverter 2 (HKLM\...\{83DA46EC-2CB1-4649-9100- C4F98D8DA8CD}) (Version: - ArcSoft) ArcSoft PhotoImpression 5 (HKLM\...\{4FE82F4B-B7D8-4E65-84AD- E0436CDE57DD}) (Version: - ArcSoft) ArcSoft ShowBiz DVD 2 (HKLM\...\{E883DCB3-766D-4166-8B28- 33C8FE451F2B}) (Version: - ArcSoft) ArcSoft TotalMedia 3.5 (HKLM\...\{29E44E9D-ACB2-4D2D-849F- 5361C941B7E1}) (Version: 3.5.7.362 - ArcSoft) AutoUpdate (HKLM\...\{18D10072035C4515918F7E37EAFAACFC}) (Version: 1.1 - ) AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4592 - AVG Technologies) AVG 2014 (Version: 14.0.3964 - AVG Technologies) Hidden AVG 2014 (Version: 14.0.4592 - AVG Technologies) Hidden Avira (HKLM\...\{68e29fba-92b1-4f6f-a604-1d8679da3a9f}) (Version: 1.1.13.24161 - Avira Operations GmbH & Co. KG) Avira (Version: 1.1.13.24161 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.4.642 - Avira) Camera RAW Plug-In for EPSON Creativity Suite (HKLM\...\{93EA9C3E- BDFD-4309-A605-9B5BBC0CCEFD}) (Version: 2.2.0.0 - SEIKO EPSON CORPORATION) Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020- 0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Conduit Engine (HKLM\...\conduitEngine) (Version: - Conduit Ltd.) <==== ATTENTION Corel MediaOne (HKLM\...\{A062A15F-9CAC-4B88-98DF-87628A0BD721}) (Version: 2.00.0000 - Corel Corporation) Corel Paint Shop Pro Photo X2 (HKLM\...\{64E72FB1-2343-4977-B4A8- 262CD53D0BD3}) (Version: 12.010.0000 - Corel Corporation) Digital Video (HKLM\...\{C833C7B6-1140-471D-932B-391B5CA66D7D}) (Version: 1.00.000 - ) DivX Codec (HKLM\...\{7B63B2922B174135AFC0E1377DD81EC2}) (Version: 6.8.5 - DivX, Inc.) DivX Converter (HKLM\...\{13F3917B56CD4C25848BDC69916971BB}) (Version: 7.0.0 - DivX, Inc.) DivX Converter (HKLM\...\{B13A7C41581B411290FBC0395694E2A9}) (Version: 7.0.0 - DivX, Inc.) DivX Player (HKLM\...\{8ADFC4160D694100B5B8A22DE9DCABD9}) (Version: 7.0.0 - DivX, Inc.) DivX Plus DirectShow Filters (HKLM\...\DivX Plus DirectShow Filters) (Version: - DivX, Inc.) DivX Version Checker (HKLM\...\{3FC7CBBC4C1E11DCA1A752EA55D89593}) (Version: 7.0.0.19 - DivX, Inc.) DivX Web Player (HKLM\...\{B7050CBDB2504B34BC2A9CA0A692CC29}) (Version: 1.4.2 - DivX,Inc.) Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.) DVDVideoSoft Toolbar (HKLM\...\DVDVideoSoft Toolbar) (Version: - ) DVDVideoSoftTB Toolbar (HKLM\...\DVDVideoSoftTB Toolbar) (Version: 6.3.3.3 - DVDVideoSoftTB) EPSON Attach To Email (HKLM\...\InstallShield_{20C45B32-5AB6-46A4- 94EF-58950CAF05E5}) (Version: 1.01.0000 - SEIKO EPSON) EPSON Attach To Email (Version: 1.01.0000 - SEIKO EPSON) Hidden EPSON Copy Utility 3 (HKLM\...\{67EDD823-135A-4D59-87BD-950616D6E857}) (Version: 3.3.0.0 - ) EPSON Easy Photo Print (HKLM\...\{3D78F2A2-C893-4ABD-B5FE- AD7011837755}) (Version: 1.5.0.0 - SEIKO EPSON CORPORATION) Epson Easy Photo Print 2 (HKLM\...\{39F58DDB-B2B8-4B86-AF20- 4706A80EB30D}) (Version: 2.2.0.0 - SEIKO EPSON CORPORATION) Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION) Epson Event Manager (HKLM\...\{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}) (Version: 2.40.0001 - SEIKO EPSON CORPORATION) EPSON File Manager (HKLM\...\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}) (Version: 1.3.0.0 - ) EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON Scan Assistant (HKLM\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - ) EPSON Stylus CX7300_CX8300_DX7400_DX8400 Handbuch (HKLM\...\EPSON Stylus CX7300_CX8300_DX7400_DX8400 Benutzerhandbuch) (Version: - ) EPSON SX420W Series Handbuch (HKLM\...\EPSON SX420W Series Manual) (Version: - ) EPSON SX420W Series Netzwerk-Handbuch (HKLM\...\EPSON SX420W Series Network Guide) (Version: - ) EPSON SX420W Series Printer Uninstall (HKLM\...\EPSON SX420W Series) (Version: - SEIKO EPSON Corporation) EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version: - SEIKO EPSON Corporation) EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.4i - SEIKO EPSON CORPORATION) EpsonNet Setup 3.2 (HKLM\...\{C9D8A041-2963-4B31-8FFC-1500F3DB9293}) (Version: 3.2a - SEIKO EPSON CORPORATION) Firebird SQL Server - MAGIX Edition (HKLM\...\Firebird SQL Server D) (Version: 2.0.1.8 - MAGIX AG) Free Audio CD Burner version 1.2 (HKLM\...\Free Audio CD Burner_is1) (Version: - DVDVideoSoft Limited.) Free YouTube Download version 3.0.16.923 (HKLM\...\Free YouTube Download_is1) (Version: - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.11.37.1212 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.37.1212 - DVDVideoSoft Ltd.) GMX MediaCenter 1.5.1765.0 (HKCU\...\GMX Application {sync-000021}) (Version: 1.5.1765.0 - 1&1 Mail & Media GmbH) Google Chrome (HKLM\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.) Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (Version: 1.3.24.7 - Google Inc.) Hidden H.264 Decoder (HKLM\...\{A96E97134CA649888820BCDE5E300BBD}) (Version: 1.0.0 - DivX, Inc.) ICQ7.4 (HKLM\...\{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37}) (Version: 7.4 - ICQ) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation) Intel(R) Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C- 5E35E2C0E09E}) (Version: - ) InterVideo WinDVD 8 (HKLM\...\InstallShield_{20471B27-D702-4FE8-8DEC- 0702CC8C0A85}) (Version: 8.0-B9.385 - InterVideo Inc.) InterVideo WinDVD 8 (Version: 8.0-B9.385 - InterVideo Inc.) Hidden IPTInstaller (HKLM\...\{6965F2F4-1CD2-4F42-A8EF-9EF433F9AA72}) (Version: 4.0.4 - HTC) Java(TM) 6 Update 5 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160050}) (Version: 1.6.0.50 - Sun Microsystems, Inc.) Kaspersky Anti-Virus (HKLM\...\InstallWIX_{6F6873E3-5C92-4049-B511- 231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab) Kaspersky Anti-Virus (Version: 14.0.0.4651 - Kaspersky Lab) Hidden Launch Manager V1.4.9 (HKLM\...\{D0846526-66DD-4DC9-A02C- 98F9A2806812}) (Version: 1.4.9 - Wistron Corp.) LG PC Suite II (HKLM\...\{14DCD95A-EBA3-4BF0-B7EF-533852E99BE6}) (Version: 2.00.0000 - LG PC Suite) LG PC Suite II (Version: 2.00.0000 - LG PC Suite) Hidden LG USB Modem driver (HKLM\...\{C3ABE126-2BB2-4246-BFE1-6797679B3579}) (Version: 4.9.4 - LG Electronics) MD86351 Driver Install (HKLM\...\InstallShield_{B3A9DC22-6162-4844- BEB3-853BAFB980E0}) (Version: 6.3.6.1 - Ihr Firmenname) MD86351 Driver Install (Version: 6.3.6.1 - Ihr Firmenname) Hidden MEDION Fotos auf CD Nord (HKLM\...\MEDION Fotos auf CD Nord D) (Version: 6.0.2.0 - MAGIX AG) Medion Media Center 0 (Version: 1.0.12.0 - Medion) Hidden MEDIONbox (HKLM\...\{27FDF949-69CE-435A-8372-339F72336AC5}) (Version: 1.09.0000.00052 - Medion) Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - ) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685- 45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20- CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030- 0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB- 199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F- 0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB- 199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000 -0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24- 7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Picture It! Foto Premium 9 (HKLM\...\PictureIt_v9) (Version: 9.0.0.0000 - Microsoft Corporation) Microsoft Picture It! Foto Premium 9 (Version: 9.0.0.0000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8- 2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18- 4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30- 493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Microsoft XML Parser (Version: 8.20.8730.4 - Microsoft Corporation) Hidden MindManager Smart (HKLM\...\MindManager Smart) (Version: 2.1.3 - Mindjet LLC) MKV Splitter (HKLM\...\{AAC389499AEF40428987B3D30CFC76C9}) (Version: 1.0.0 - DivX, Inc.) Move Networks Media Player for Internet Explorer (HKCU\...\Move Networks Player - IE) (Version: - ) Mozilla Firefox (3.0) (HKLM\...\Mozilla Firefox (3.0)) (Version: 3.0 (de) - Mozilla) MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9- 6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A- F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72- 8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E- 8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nero 8 Essentials (HKLM\...\{47948554-90C6-4AAC-8CFA-D23CE11C1031}) (Version: 8.3.124 - Nero AG) neroxml (Version: 1.0.0 - Nero AG) Hidden OnlineFotoservice (HKLM\...\OnlineFotoservice) (Version: 5.1.5 - CEWE Stiftung u Co. KGaA) Opera 12.12 (HKLM\...\Opera 12.12.1707) (Version: 12.12.1707 - Opera Software ASA) PDF24 Creator 6.3.2 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576} _is1) (Version: - PDF24.org) PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 0.9.8 - Frank Heindörfer, Philip Chinery) Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.) Ralink Wireless LAN (HKLM\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.00.0000 - RaLink) Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE- 8A7C-958108FE7DBC}) (Version: 6.0.1.5595 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM\...\{DC24971E-1946-445D-8A82- CE685433FA7D}) (Version: - Realtek Semiconductor Corp.) Rossmann Fotoservice 2.6 (HKLM\...\Rossmann Fotoservice_is1) (Version: - ) Sceneo AbsolutTV (HKLM\...\{4C73B683-B15D-4B94-AC7A-520B70C4FFE9}) (Version: - ) Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Switch Sound File Converter (HKLM\...\Switch) (Version: - NCH Software) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.0.14.0 - Synaptics) TV IR (HKLM\...\InstallShield_{8CFE319F-DC08-48BA-B011-37ED5C9733B5}) (Version: 1.00.0000 - Ihr Firmenname) TV IR (Version: 1.00.0000 - Ihr Firmenname) Hidden Ulead DVD MovieFactory 5 (HKLM\...\{FF164702-AF8B-4F2F-8038- 74A4C536866B}) (Version: 5.3 - Ulead Systems, Inc.) Ulead PhotoImpact 12 (HKLM\...\{11AFE21E-B193-430D-B57A-DFF7815BB962}) (Version: 12.0 - Ulead System) Uninstall 1.0.0.1 (HKLM\...\Uninstall_is1) (Version: - ) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D -5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_ {C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{AB365889 -0395-4FAD-B702-CA5985D53D42}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B -77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_ {A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0 -3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_ {CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945 -BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_ {E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office Access 2007 Help (KB963663) (HKLM\...\{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{6B76A18A -AA1E-42AB-A7AD-6C84BBB43987}) (Version: - Microsoft) Update for Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{199DF7B6 -169C-448C-B511-1054101BE9C9}) (Version: - Microsoft) Update for Microsoft Office Infopath 2007 Help (KB963662) (HKLM\...\{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{716B81B8 -B13C-41DF-8EAC-7A2F656CAB63}) (Version: - Microsoft) Update for Microsoft Office OneNote 2007 Help (KB963670) (HKLM\...\{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2744EF05 -38E1-4D5D-B333-E021EDAEA245}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{ED38F8A3 -4F61-494E-8BCA-E3AC7760C924}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068 -4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{0451F231 -E3E3-4943-AB9F-58EB96171784}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2881065) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE} _ENTERPRISE_{B7EF38F7-1D58-4085-A9A4-0F6C69A5AA1E}) (Version: - Microsoft) Update for Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{397B1D4F -ED7B-4ACA-A637-43B670843876}) (Version: - Microsoft) Update for Microsoft Office Publisher 2007 Help (KB963667) (HKLM\...\{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2E40DE55 -B289-4C8B-8901-5D369B16814F}) (Version: - Microsoft) Update for Microsoft Office Script Editor Help (KB963671) (HKLM\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{CD11C6A2 -FFC6-4271-8EAB-79C3582F505C}) (Version: - Microsoft) Update for Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{80E762AA -C921-4839-9D7D-DB62A72C0726}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_ {BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_ {EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_ {38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) USB Video Device (HKLM\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.18100.101 - Sonix) VC80CRTRedist - 8.0.50727.762 (Version: 1.0.0 - DivX, Inc) Hidden VCRedistSetup (Version: 1.0.0 - Nero AG) Hidden Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B -B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player 1.1.10 (HKLM\...\VLC media player) (Version: 1.1.10 - VideoLAN) WavePad Sound Editor (HKLM\...\WavePad) (Version: - NCH Software) Windows Live Messenger (HKLM\...\{279DB581-239C-4E13-97F8- 0F48E40BE75C}) (Version: 8.1.0178.00 - Microsoft Corporation) WinRAR (HKLM\...\WinRAR archiver) (Version: - ) WISO Mein Geld 2008 Professional (HKLM\...\{D8D22773-14BF-4178-A683- 3DBA515C2A26}) (Version: 9.00.01.0023 - Buhl Data Service GmbH) XVID Codec Installation (HKLM\...\{534C6D59-D6E3-48A6-AD0B- 747799019960}) (Version: - ) ==================== Restore Points ========================= 04-06-2014 17:38:03 Geplanter Prüfpunkt 07-06-2014 18:44:11 Windows Update 08-06-2014 10:42:59 Gerätetreiber-Paketinstallation: HTC, Corporation 08-06-2014 10:46:45 Gerätetreiber-Paketinstallation: HTC Corporation Netzwerkadapter 08-06-2014 10:49:34 Gerätetreiber-Paketinstallation: HTC Corporation Tragbare Geräte 08-06-2014 10:54:49 Gerätetreiber-Paketinstallation: HTC Netzwerkprotokoll 11-06-2014 17:26:28 Windows Update 11-06-2014 18:00:59 Windows Update 13-06-2014 20:48:59 Installed AVG 2014 13-06-2014 20:50:05 Installed AVG 2014 14-06-2014 11:59:34 Gerätetreiber-Paketinstallation: Kaspersky Lab Netzwerkdienst ==================== Hosts content: ========================== 2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0D4A3951-D115-4E17-9495-26DC510E1359} - System32 \Tasks\{19864B7B-6EBE-4684-9FF9-DD775F771854} => C:\Program Files\Skype\\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32 \Tasks\Microsoft\Windows\MobilePC\TMM Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32 \Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32 \Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32 \Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32 \RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {574969E9-0C4A-4A75-A6C7-549B08CDB6C6} - System32 \Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-06-05] (Google Inc.) Task: {8AC7F5E7-9061-45A6-95FE-B269516DA561} - System32 \Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-06-05] (Google Inc.) Task: {B7794283-DDB2-48C6-9B9B-3AC33999A0C1} - System32 \Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32 \Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {EEEAB8B8-067F-4F56-8432-3BBC88C3CC8F} - System32 \Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32 \netsh.exe [2006-11-02] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2009-09-04 19:29 - 2001-10-28 17:42 - 00116224 _____ () C:\Windows\System32\pdfcmnnt.dll 2009-10-03 11:47 - 2005-06-28 13:59 - 00053248 _____ () C:\Program Files\ArcSoft\PhotoImpression 5\Share\PIHook.dll 2010-01-11 21:06 - 2009-12-12 16:12 - 00141824 _____ () C:\Program Files\WinRAR\rarext.dll 2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\dblite.dll 2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\kpcengine.2.3.dll 2013-07-21 20:03 - 2013-07-21 20:03 - 03391488 _____ () c:\windows\assembly\nativeimages1_v1.1.4322 \mscorlib\1.0.5000.0__b77a5c561934e089_b0c6b048\mscorlib.dll 2013-07-21 20:02 - 2013-07-21 20:02 - 01966080 _____ () c:\windows\assembly\nativeimages1_v1.1.4322 \system\1.0.5000.0__b77a5c561934e089_c7c004ef\system.dll 2013-07-21 20:02 - 2013-07-21 20:02 - 03035136 _____ () c:\windows\assembly\nativeimages1_v1.1.4322 \system.windows.forms\1.0.5000.0__b77a5c561934e089_5c188a8d\system.win dows.forms.dll 2013-07-21 20:02 - 2013-07-21 20:02 - 02088960 _____ () c:\windows\assembly\nativeimages1_v1.1.4322 \system.xml\1.0.5000.0__b77a5c561934e089_821dd40b\system.xml.dll 2008-04-22 08:37 - 2007-04-19 12:11 - 00006656 _____ () c:\program files\medion\medionbox\program\structconverter.dll 2009-08-18 20:24 - 2009-04-11 08:28 - 00368640 _____ () C:\Windows\system32\msjetoledb40.dll 2012-10-08 17:04 - 2012-10-08 17:04 - 00166912 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe 2008-04-21 09:37 - 2007-09-01 14:03 - 00032768 _____ () C:\Program Files\Launch Manager\LaunchAp.exe 2007-06-05 13:20 - 2007-06-05 13:20 - 00177704 _____ () C:\Windows\system32\PSIService.exe 2007-10-30 19:52 - 2007-10-30 19:52 - 00016200 _____ () C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe 2008-04-22 08:30 - 2007-05-16 22:48 - 00421955 _____ () C:\Program Files\Sceneo\AbsolutTV\Services\PVR\tvtvRemote.dll 2011-01-08 16:14 - 2007-02-12 15:50 - 00020480 _____ () C:\Windows\FixCamera.exe 2011-01-08 16:14 - 2007-12-04 19:28 - 00249856 _____ () C:\Windows\tsnp2uvc.exe 2011-08-06 14:59 - 2010-09-30 14:00 - 00253264 _____ () C:\Program Files\1&1 Surf-Stick\AssistantServices.exe 2011-08-06 14:59 - 2010-09-30 14:00 - 00139088 _____ () C:\Program Files\1&1 Surf-Stick\UIExec.exe 2010-12-22 11:27 - 2010-12-22 11:27 - 00692318 _____ () C:\Program Files\TV IR\TV IR.exe 2010-06-18 00:09 - 2010-06-18 00:09 - 00167936 _____ () C:\Program Files\TV IR\RmCard.dll 2008-01-15 00:40 - 2008-01-15 00:40 - 00053248 _____ () C:\Program Files\TV IR\LWExt.dll 2009-03-09 11:52 - 2009-03-09 11:52 - 00053248 _____ () C:\Program Files\TV IR\tmir.dll 2012-10-21 13:31 - 2007-04-19 09:33 - 00035584 _____ () C:\Program Files\ArcSoft\TotalMedia 3.5\uPiApi.dll 2014-06-15 00:34 - 2014-06-15 00:34 - 00043008 _____ () C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext. {5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuztmgc.dll 2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Claudia\AppData\Roaming\Dropbox\bin\libcef.dll 2011-08-14 15:39 - 2012-12-19 20:32 - 00835584 _____ () C:\Program Files\Opera\gstreamer\gstreamer.dll 2011-08-14 15:39 - 2012-12-19 20:32 - 00093696 _____ () C:\Program Files\Opera\gstreamer\plugins\gstaudioconvert.dll 2011-08-14 15:39 - 2012-12-19 20:32 - 00094208 _____ () C:\Program Files\Opera\gstreamer\plugins\gstaudioresample.dll 2011-08-14 15:39 - 2012-12-19 20:32 - 00057344 _____ () C:\Program Files\Opera\gstreamer\plugins\gstautodetect.dll 2011-12-11 13:21 - 2012-12-19 20:32 - 00096256 _____ () C:\Program Files\Opera\gstreamer\plugins\gstcoreplugins.dll 2011-08-14 15:39 - 2012-12-19 20:32 - 00062976 _____ () C:\Program Files\Opera\gstreamer\plugins\gstdecodebin2.dll 2011-08-14 15:39 - 2012-12-19 20:32 - 00067072 _____ () C:\Program Files\Opera\gstreamer\plugins\gstdirectsound.dll 2011-08-14 15:39 - 2012-12-19 20:32 - 00158208 _____ () C:\Program Files\Opera\gstreamer\plugins\gstffmpegcolorspace.dll 2011-08-14 15:39 - 2012-12-19 20:32 - 00312832 _____ () C:\Program Files\Opera\gstreamer\plugins\gstoggdec.dll 2011-08-14 15:39 - 2012-12-19 20:32 - 00038912 _____ () C:\Program Files\Opera\gstreamer\plugins\gstwaveform.dll 2011-08-14 15:39 - 2012-12-19 20:32 - 00073728 _____ () C:\Program Files\Opera\gstreamer\plugins\gstwavparse.dll 2011-08-14 15:39 - 2012-12-19 20:32 - 00101888 _____ () C:\Program Files\Opera\gstreamer\plugins\gstwebmdec.dll 2014-06-07 20:25 - 2014-06-07 20:25 - 16361136 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll 2014-05-14 14:27 - 2014-05-14 14:27 - 00137296 _____ () C:\Program Files\Avira\My Avira\Avira.OE.NativeCore.dll 2014-05-14 14:27 - 2014-05-14 14:27 - 00065616 _____ () C:\Program Files\Avira\My Avira\Avira.OE.AvConnectorNative.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Claudia\Beweis.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Beweis.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Beweis.png: {4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Desktop\Foto20103.jpg:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Desktop\Foto20103.jpg:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia \Desktop\Foto20103.jpg:{4c8cc155-6c1e-11d1-8e41- 00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:{4c8cc155-6c1e -11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:{4c8cc155-6c1e -11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\ebay lederjacke.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\ebay lederjacke.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\ebay lederjacke.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:{4c8cc155-6c1e-11d1-8e41- 00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\Muster Inspektion VW.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Muster Inspektion VW.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Muster Inspektion VW.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\pikante spaghetti.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\pikante spaghetti.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\pikante spaghetti.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:SummaryInformation AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:Updt_SummaryInformation AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:{4c8cc155- 6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:SummaryInformation AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:Updt_SummaryInformation AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:{4c8cc155- 6c1e-11d1-8e41-00c04fb9386d} ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/15/2014 00:33:52 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/15/2014 00:27:44 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/15/2014 00:26:54 AM) (Source: EventSystem) (EventID: 4609) (User: ) Description: d:\longhorn\com\complus\src\events\tier1 \eventsystemobj.cpp458007043c Error: (06/14/2014 11:59:38 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung NMIndexStoreSvr.exe, Version 3.3.3.0, Zeitstempel 0x47c6bd1b, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000, Ausnahmecode 0xc0000005, Fehleroffset 0x17271727, Prozess-ID 0xecc, Anwendungsstartzeit NMIndexStoreSvr.exe0. Error: (06/14/2014 11:57:39 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/14/2014 11:52:43 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm nero.exe, Version 8.3.2.2 arbeitet nicht mehr mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem zu suchen. Prozess-ID: 10e8 Anfangszeit: 01cf881a8af268df Zeitpunkt der Beendigung: 52 Error: (06/14/2014 05:32:32 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Eintrag <C:\USERS\CLAUDIA\{C00C4FB5-D3BF- 4E0A-B53C-B250F89CE13C}\KLIM6.SYS> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (06/14/2014 05:32:32 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Eintrag <C:\USERS\CLAUDIA\{C00C4FB5-D3BF- 4E0A-B53C-B250F89CE13C}\KLIM6.INF> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (06/14/2014 03:06:46 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/14/2014 02:33:58 PM) (Source: MsiInstaller) (EventID: 1023) (User: NT-AUTORITÄT) Description: Produkt: Kaspersky Anti-Virus - Update "Kaspersky Internet Security 2014 (Patch c)" konnte nicht installiert werden. Fehlercode 1603. Weitere Informationen sind in der Protokolldatei C:\Windows\TEMP\MSI9a992.LOG enthalten. System errors: ============= Microsoft Office Sessions: ========================= Error: (05/07/2013 08:37:08 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 810 seconds with 720 seconds of active time. This session ended with a crash. Error: (05/13/2011 02:44:54 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1089 seconds with 120 seconds of active time. This session ended with a crash. Error: (03/20/2011 05:35:34 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4422 seconds with 900 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-06-15 02:15:27.775 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kneps.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-15 02:15:26.317 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kneps.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-15 02:15:24.992 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kneps.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-15 02:15:23.672 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kneps.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-15 02:15:22.062 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\klkbdflt.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-15 02:15:20.637 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\klkbdflt.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-15 02:15:19.107 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\klkbdflt.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-15 02:15:17.767 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\klkbdflt.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-15 02:15:16.515 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\klif.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-15 02:15:15.147 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\klif.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 71% Total physical RAM: 3061.69 MB Available physical RAM: 885.3 MB Total Pagefile: 6335.64 MB Available Pagefile: 3489.04 MB Total Virtual: 2047.88 MB Available Virtual: 1890.87 MB ==================== Drives ================================ Drive c: (BOOT) (Fixed) (Total:207.5 GB) (Free:101.39 GB) NTFS ==> [Drive with boot components (obtained from BCD)] Drive d: (RECOVER) (Fixed) (Total:25.37 GB) (Free:5.96 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: 4B64DFC2) Partition 1: (Active) - (Size=207 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=25 GB) - (Type=OF Extended) ==================== End Of Log ============================[/CODE] Vielen, vielen Dank! |
15.06.2014, 19:35 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Avira durch Gruppenrichtlinie geblockt - Trojaner? Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\McAfee <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\Avira <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Avira <====== ATTENTION C:\Users\Claudia\AppData\Local\Temp\ABD2BC~1.exe C:\Users\Claudia\AppData\Local\Temp\AdobeUpdater12345.exe C:\Users\Claudia\AppData\Local\Temp\AskSLib.dll C:\Users\Claudia\AppData\Local\Temp\avgnt.exe C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuztmgc.dll C:\Users\Claudia\AppData\Local\Temp\ffunzip.exe C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate.exe C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate01.exe C:\Users\Claudia\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe C:\Users\Claudia\AppData\Local\Temp\GDM272F.exe C:\Users\Claudia\AppData\Local\Temp\GDM34A6.exe C:\Users\Claudia\AppData\Local\Temp\GLF3BB0.tmp.ConduitEngineSetup.exe C:\Users\Claudia\AppData\Local\Temp\GoogleChromeInstaller.exe C:\Users\Claudia\AppData\Local\Temp\IcqUpdater.exe C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssa_aih[1].exe C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssd_aih[1].exe C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10_mssd_aih.exe C:\Users\Claudia\AppData\Local\Temp\JiveXViewerStart1363355292.exe C:\Users\Claudia\AppData\Local\Temp\Opera_1150_int_Setup.exe C:\Users\Claudia\AppData\Local\Temp\prxGLF3BB0.tmp.tbDVDV.dll C:\Users\Claudia\AppData\Local\Temp\SearchWithGoogleUpdate.exe C:\Users\Claudia\AppData\Local\Temp\tbDVDV.dll C:\Users\Claudia\AppData\Local\Temp\unwise.exe C:\Users\Claudia\AppData\Local\Temp\VisusClient.dll C:\Users\Claudia\AppData\Local\Temp\wpsetup.exe C:\Users\Claudia\AppData\Local\Temp\_is30.exe C:\Users\Claudia\AppData\Local\Temp\_is6CF6.exe C:\Users\Claudia\AppData\Local\Temp\_is92AD.exe C:\Users\Claudia\AppData\Local\Temp\{1167C4F7-64B6-4A1D-A0A5-B605C6CDE10F}-26.0.1410.64_25.0.1364.172_chrome_updater.exe C:\Users\Claudia\AppData\Local\Temp\{5A7A4717-CEF4-4E4A-B23E-0838114D47F8}-chrome_installer.exe C:\Users\Claudia\AppData\Local\Temp\{C2722232-3395-42BA-9B03-4B2C787E8081}-chrome_installer.exe C:\Users\Claudia\AppData\Local\Temp\{D2416B08-7E6C-4C05-B27E-05A6DEC53BCD}-30.0.1599.69_29.0.1547.76_chrome_updater.exe Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
16.06.2014, 22:46 | #5 |
| Avira durch Gruppenrichtlinie geblockt - Trojaner? Danke für deine Hilfe. Nachfolgend der Inhalt von Fixlog: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:16-06-2014 Ran by Claudia at 2014-06-16 23:38:49 Run:1 Running from C:\Users\Claudia\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\McAfee <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\Avira <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Avira <====== ATTENTION C:\Users\Claudia\AppData\Local\Temp\ABD2BC~1.exe C:\Users\Claudia\AppData\Local\Temp\AdobeUpdater12345.exe C:\Users\Claudia\AppData\Local\Temp\AskSLib.dll C:\Users\Claudia\AppData\Local\Temp\avgnt.exe C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuztmgc.dll C:\Users\Claudia\AppData\Local\Temp\ffunzip.exe C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate.exe C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate01.exe C:\Users\Claudia\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe C:\Users\Claudia\AppData\Local\Temp\GDM272F.exe C:\Users\Claudia\AppData\Local\Temp\GDM34A6.exe C:\Users\Claudia\AppData\Local\Temp\GLF3BB0.tmp.ConduitEngineSetup.exe C:\Users\Claudia\AppData\Local\Temp\GoogleChromeInstaller.exe C:\Users\Claudia\AppData\Local\Temp\IcqUpdater.exe C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssa_aih[1].exe C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssd_aih[1].exe C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10_mssd_aih.exe C:\Users\Claudia\AppData\Local\Temp\JiveXViewerStart1363355292.exe C:\Users\Claudia\AppData\Local\Temp\Opera_1150_int_Setup.exe C:\Users\Claudia\AppData\Local\Temp\prxGLF3BB0.tmp.tbDVDV.dll C:\Users\Claudia\AppData\Local\Temp\SearchWithGoogleUpdate.exe C:\Users\Claudia\AppData\Local\Temp\tbDVDV.dll C:\Users\Claudia\AppData\Local\Temp\unwise.exe C:\Users\Claudia\AppData\Local\Temp\VisusClient.dll C:\Users\Claudia\AppData\Local\Temp\wpsetup.exe C:\Users\Claudia\AppData\Local\Temp\_is30.exe C:\Users\Claudia\AppData\Local\Temp\_is6CF6.exe C:\Users\Claudia\AppData\Local\Temp\_is92AD.exe C:\Users\Claudia\AppData\Local\Temp\{1167C4F7-64B6-4A1D-A0A5-B605C6CDE10F}-26.0.1410.64_25.0.1364.172_chrome_updater.exe C:\Users\Claudia\AppData\Local\Temp\{5A7A4717-CEF4-4E4A-B23E-0838114D47F8}-chrome_installer.exe C:\Users\Claudia\AppData\Local\Temp\{C2722232-3395-42BA-9B03-4B2C787E8081}-chrome_installer.exe C:\Users\Claudia\AppData\Local\Temp\{D2416B08-7E6C-4C05-B27E-05A6DEC53BCD}-30.0.1599.69_29.0.1547.76_chrome_updater.exe ***************** HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. C:\Users\Claudia\AppData\Local\Temp\ABD2BC~1.exe => Moved successfully. C:\Users\Claudia\AppData\Local\Temp\AdobeUpdater12345.exe => Moved successfully. C:\Users\Claudia\AppData\Local\Temp\AskSLib.dll => Moved successfully. |
16.06.2014, 22:53 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Avira durch Gruppenrichtlinie geblockt - Trojaner? Adware/Junkware/Toolbars entfernen 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ --> Avira durch Gruppenrichtlinie geblockt - Trojaner? |
17.06.2014, 19:32 | #7 |
| Avira durch Gruppenrichtlinie geblockt - Trojaner? Hallo, den adwCleander musste ich dreimal neu starten, weil keine Rückmeldung vorhanden war bzw. habe ich nach jeweils 10 Minuten "keine Rückmeldung" das Programm über den TaskManager geschlossen, da mir leider die Geduld fehlte. Beim dritten Mal habe ich länger abgewartet und dann hat er sich irgendwann wieder gefangen. Hoffe, die zwei Abbrüche haben keine Auswirkungen gehabt. Bei FRST hat er keinen Addition-Log erstellt. Habe dann gesehen, dass das Häkchen bei "Addition" irgendwie nicht angehakt gewesen ist. Soll ich FRST nochmal starten mit dem Häkchen "Addition"? Hier sind die Logs: AdwCleaner: Code:
ATTFilter # AdwCleaner v3.212 - Bericht erstellt am 17/06/2014 um 18:52:03 # Aktualisiert 05/06/2014 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : Claudia - CLAUDIA1 # Gestartet von : C:\Users\Claudia\Desktop\adwcleaner_3.212.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\CLAUDI~1\AppData\Local\Temp\CT2269050 Ordner Gelöscht : C:\Users\Claudia\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\Claudia\AppData\LocalLow\ConduitEngine Ordner Gelöscht : C:\Users\Claudia\AppData\LocalLow\DVDVideoSoftTB Ordner Gelöscht : C:\Users\Claudia\AppData\LocalLow\PriceGong Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\dvdvideosoftiehelpers Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\ConduitCommon Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\ICQToolbarData Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\CT2269050 Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07} Ordner Gelöscht : C:\Program Files\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07} Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C} Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} Ordner Gelöscht : C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp Datei Gelöscht : C:\Program Files\Mozilla Firefox\.autoreg Datei Gelöscht : C:\Program Files\Mozilla Firefox\Components\AskSearch.js Datei Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\Ask.xml Datei Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\icqplugin.xml Datei Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\icqplugin-1.xml ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\blbkdnmdcafmfhinpmnlhhddbepgkeaa Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Conduit.Engine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2269050 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7EEF445-225F-4684-B155-FB4DE7B6AFFB} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E7EEF445-225F-4684-B155-FB4DE7B6AFFB} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A16010A2-0CC9-46A1-98D2-8EFBD1D813B2} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{75A1D390-381B-47EC-A560-46E874AD9393} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8F31308-FAEB-45B6-B3FE-DEBCBA33FB65} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\conduitEngine Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DVDVideoSoftTB Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\Software\conduitEngine Schlüssel Gelöscht : HKLM\Software\DVDVideoSoftTB Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Conduit Engine Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DVDVideoSoftTB Toolbar ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16555 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] -\\ Mozilla Firefox v3.0 (de) [ Datei : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\prefs.js ] Zeile gelöscht : user_pref("CT2269050..clientLogIsEnabled", false); Zeile gelöscht : user_pref("CT2269050..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent"); Zeile gelöscht : user_pref("CT2269050..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation"); Zeile gelöscht : user_pref("CT2269050.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/default.aspx"); Zeile gelöscht : user_pref("CT2269050.AppTrackingLastCheckTime", "Mon Mar 18 2013 18:49:50 GMT+0100"); Zeile gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_129575150554007677", true); Zeile gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_129681780741097243", true); Zeile gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_129853623028165512", true); Zeile gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_129881141106886992", true); Zeile gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_129977890572899945", true); Zeile gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_130100683276316706", true); Zeile gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_1359634297000", true); Zeile gelöscht : user_pref("CT2269050.CTID", "CT2269050"); Zeile gelöscht : user_pref("CT2269050.CurrentServerDate", "22-1-2014"); Zeile gelöscht : user_pref("CT2269050.DialogsAlignMode", "LTR"); Zeile gelöscht : user_pref("CT2269050.DialogsGetterLastCheckTime", "Mon Jan 20 2014 18:43:31 GMT+0100"); Zeile gelöscht : user_pref("CT2269050.DownloadReferralCookieData", ""); Zeile gelöscht : user_pref("CT2269050.EMailNotifierPollDate", "Sun Jun 15 2014 00:40:27 GMT+0200"); Zeile gelöscht : user_pref("CT2269050.ExternalComponentPollDate8877840225553681985", "Sat May 15 2010 17:16:19 GMT+0200"); Zeile gelöscht : user_pref("CT2269050.FirstServerDate", "19-2-2012"); Zeile gelöscht : user_pref("CT2269050.FirstTime", true); Zeile gelöscht : user_pref("CT2269050.FirstTimeFF3", true); Zeile gelöscht : user_pref("CT2269050.FixPageNotFoundErrors", true); Zeile gelöscht : user_pref("CT2269050.GroupingServerCheckInterval", 1440); Zeile gelöscht : user_pref("CT2269050.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Zeile gelöscht : user_pref("CT2269050.HasUserGlobalKeys", true); Zeile gelöscht : user_pref("CT2269050.HomePageProtectorEnabled", false); Zeile gelöscht : user_pref("CT2269050.HomepageBeforeUnload", "hxxp://www.hiergehtslos.de"); Zeile gelöscht : user_pref("CT2269050.Initialize", true); Zeile gelöscht : user_pref("CT2269050.InitializeCommonPrefs", true); Zeile gelöscht : user_pref("CT2269050.InstallationAndCookieDataSentCount", 3); Zeile gelöscht : user_pref("CT2269050.InstallationType", "UnknownIntegration"); Zeile gelöscht : user_pref("CT2269050.InstalledDate", "Fri Dec 18 2009 22:19:24 GMT+0100"); Zeile gelöscht : user_pref("CT2269050.InvalidateCache", false); Zeile gelöscht : user_pref("CT2269050.IsAlertDBUpdated", true); Zeile gelöscht : user_pref("CT2269050.IsGrouping", false); Zeile gelöscht : user_pref("CT2269050.IsMulticommunity", false); Zeile gelöscht : user_pref("CT2269050.IsOpenThankYouPage", false); Zeile gelöscht : user_pref("CT2269050.IsOpenUninstallPage", false); Zeile gelöscht : user_pref("CT2269050.LanguagePackLastCheckTime", "Sun Jun 15 2014 00:40:26 GMT+0200"); Zeile gelöscht : user_pref("CT2269050.LanguagePackReloadIntervalMM", 1440); Zeile gelöscht : user_pref("CT2269050.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx"); Zeile gelöscht : user_pref("CT2269050.LastLogin_2.4.0.4", "Sun Jun 15 2014 00:40:26 GMT+0200"); Zeile gelöscht : user_pref("CT2269050.LastLogin_3.7.0.6", "Tue Jan 21 2014 22:04:01 GMT+0100"); Zeile gelöscht : user_pref("CT2269050.LatestVersion", "3.20.0.4"); Zeile gelöscht : user_pref("CT2269050.Locale", "en"); Zeile gelöscht : user_pref("CT2269050.LoginCache", 4); Zeile gelöscht : user_pref("CT2269050.MCDetectTooltipHeight", "83"); Zeile gelöscht : user_pref("CT2269050.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Zeile gelöscht : user_pref("CT2269050.MCDetectTooltipWidth", "295"); Zeile gelöscht : user_pref("CT2269050.MyStuffEnabledAtInstallation", true); Zeile gelöscht : user_pref("CT2269050.RadioIsPodcast", false); Zeile gelöscht : user_pref("CT2269050.RadioLastCheckTime", "Sun Jun 15 2014 00:40:26 GMT+0200"); Zeile gelöscht : user_pref("CT2269050.RadioLastUpdateIPServer", "3"); Zeile gelöscht : user_pref("CT2269050.RadioLastUpdateServer", "129132338014870000"); Zeile gelöscht : user_pref("CT2269050.RadioMediaID", "12473383"); Zeile gelöscht : user_pref("CT2269050.RadioMediaType", "Media Player"); Zeile gelöscht : user_pref("CT2269050.RadioMenuSelectedID", "EBRadioMenu_CT226905012473383"); Zeile gelöscht : user_pref("CT2269050.RadioShrinkedFromSetup", false); Zeile gelöscht : user_pref("CT2269050.RadioStationName", "Hotmix%20108"); Zeile gelöscht : user_pref("CT2269050.RadioStationURL", "hxxp://67.202.67.18:8082"); Zeile gelöscht : user_pref("CT2269050.SHRINK_TOOLBAR", 1); Zeile gelöscht : user_pref("CT2269050.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2269050&octid=EB_ORIGINAL_CTID&SearchSource=1&CUI=SB_CUI&UM=UM_ID"); Zeile gelöscht : user_pref("CT2269050.SearchEngineBeforeUnload", "ICQ Search"); Zeile gelöscht : user_pref("CT2269050.SearchFromAddressBarIsInit", true); Zeile gelöscht : user_pref("CT2269050.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q="); Zeile gelöscht : user_pref("CT2269050.SearchInNewTabEnabled", true); Zeile gelöscht : user_pref("CT2269050.SearchInNewTabIntervalMM", 1440); Zeile gelöscht : user_pref("CT2269050.SearchInNewTabLastCheckTime", "Sun Jun 15 2014 00:40:24 GMT+0200"); Zeile gelöscht : user_pref("CT2269050.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID&UM=UM_ID"); Zeile gelöscht : user_pref("CT2269050.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usage.ashx?ctid=EB_TOOLBAR_ID"); Zeile gelöscht : user_pref("CT2269050.SearchProtectorEnabled", false); Zeile gelöscht : user_pref("CT2269050.SearchProtectorToolbarDisabled", false); Zeile gelöscht : user_pref("CT2269050.ServiceMapLastCheckTime", "Tue Jan 21 2014 22:04:00 GMT+0100"); Zeile gelöscht : user_pref("CT2269050.SettingsCheckIntervalMin", 120); Zeile gelöscht : user_pref("CT2269050.SettingsLastCheckTime", "Sun Jun 15 2014 00:40:24 GMT+0200"); Zeile gelöscht : user_pref("CT2269050.SettingsLastUpdate", "1389625828"); Zeile gelöscht : user_pref("CT2269050.ThirdPartyComponentsInterval", 504); Zeile gelöscht : user_pref("CT2269050.ThirdPartyComponentsLastCheck", "Fri Jun 13 2014 22:42:45 GMT+0200"); Zeile gelöscht : user_pref("CT2269050.ThirdPartyComponentsLastUpdate", "1331805997"); Zeile gelöscht : user_pref("CT2269050.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID"); Zeile gelöscht : user_pref("CT2269050.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...] Zeile gelöscht : user_pref("CT2269050.UserID", "UN55505124345968816"); Zeile gelöscht : user_pref("CT2269050.WeatherNetwork", ""); Zeile gelöscht : user_pref("CT2269050.WeatherPollDate", "Sun Jun 15 2014 00:40:27 GMT+0200"); Zeile gelöscht : user_pref("CT2269050.WeatherUnit", "C"); Zeile gelöscht : user_pref("CT2269050.[object Object]", "696E6B72403E72717A6F7846494A7D7B7C204D217C"); Zeile gelöscht : user_pref("CT2269050.alertChannelId", "666138"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B474953462D584D503D263F2D2E3135443B464E4F5B565E695B426D6265523B544243464959505B637D737B6E55217578654E675[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C4748402C574C4F3C253E2C2E2B2F433A454E59505B57676A66426D62455E69543D56444643465B525D66716C216E6B587D73675[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462B554A4D4B4749594D33535D4F432C45333439344A414C565B5E6C656E706C7164736D4D786D705D465F4D4E534D645B66705[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e.:2z527", "247E707273303C3833477B473C3F2C742E7E7D792022342B36282A2B474A545D4B585553553762575A4730493A3A3D3B3F4F46514345465E47494A657576747B767154796F634C65565[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F564654524C474A595A4851505E51523964595C49324B393C3B3E5047525D6C6A6B6F786D68506A6F7171742256227679664F6[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C4343534E2D585B3C253E2C302E34433A45515862695E675A416C6164513A5341454348584F5A666D7B7C7174726E702174745B2[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e06cg5el8:", "6E6D6B6B73716C737571"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737171797772797B77242F4B49474F42357D5D5C3D"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E41295547484D515A4E5A59325D5255422B443237303749404B585E685E706E6E6674626E696B4D786D705D465F4D524B51645B66732[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473E454745482F5A4F523F2841302D2F33463D48566265685C6B675F6D70604873686B58415A4946484B5F56616F7C217D74747[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D3229344356554E472E594E51325E4F412A4335373231483F4A59655F5F626C5B717369756975744D786D70517E6B60496252505451675[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352C37474B59574B4A4858584E5E3762573A535E49324B3A3D3F3B504752626C625D75786D766A7C517C7174614A63525557526[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A522B55553A233C2B2F282941384354515E5D56615F56685C426D6265523B544346494A59505B6C697A7E21702370765925797[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D49564A50592E594E314A55402942322E332F473E495B5D595A6A5E58707262674974696C59425B4B474B51605762747C2473737[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B364953545259585A5A50524E36615659462F4838353D3C4D444F626C6D6B72716A77614D786D705D465F4F4C5451645B66797[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347513F445559424C5A315C5154412A4333323037483F4A5E68565B5970606E6C666164734C776C6F5C455E4E4D4B51635A6579247[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E782332293449565540472E594E513E274030323533453C475C5558636A656E625E6C616B7068734B766B6E5B445D4D4F524F6259647927767[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4F44504C4754585C5048345F5457442D46373135344B424D636B5D5F5F73696B4A756A6D5A435C4D474B4961586379226F742[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A30273249485545442C574C4F3C253E2F2A2D2D433A455C67555B5E3F6A5F624F3851423D403F564D586F7A68786C717154207477644D66575[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354D462C574C4F3C253E2F2B2B31433A455D6356575C5C5A416C6164513A5344404045584F5A7273717A786D2256227679664F6[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352C37502E4F4747315C5154412A4334313738483F4A635F5A6A645E625A4772676A5740594A474D4D5E55607971246E7778257[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B36505459574C554F515B345F5457442D46373637384B424D676B706E606F61666B63664D786D705D465F504F5050645B66212[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A35504F5346482F5A4F523F28413233342F463D48635C5D66626A436E6366533C55464748425A515C77707773202371215925797[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3652504C5249555256525C35605558452E47383B38364C434E6A706F5F65635D736F677578684C65706B54207477644D66575[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2A554A2D46513C253E302B332C433A45626756516259655F5F436E63465F6A553E5749444C445C535E7B21747C7821745A267[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A52404548564F58315C5154412A4335342F37483F4A68646B645D5E626462616D6971726B6C786A517C7174614A6355544F566[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B265146492965504656496571734D334B57"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352C37565949484E4F51525C4E4C55535B54605A5A3E695E614E37503B3D41544B567575656D7367796D6D7C55217578654E675[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E3128335351565551575A4F584C5E335E5356432C4534383649404B6B59566C686B46716669563F58474B485C535E7E6C6956227679664F6[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C484A2C574C2F48533E27403233433A45665B68505C5E406B6E4F38514343544B56776C79616D6F517C71547873634C6557566[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C32293423524C5457474A4E50565D4A61515F5D575255643D685D604D364F3D3E3E3D544B5645486A736D696F527D7275624B645253535[...] Zeile gelöscht : user_pref("CT2269050.backendstorage./9b-0?3g>d", "3D3D3C3E6B4240707A45454875207A484E4F254E7C53232A515524292B59262E595F292B"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b-0?3g@6:5;", ""); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F297B7E7D21202F26313E4249357D37382F3A494D5D513F283338435D6554695B65546D57695D5D686365533C70766C66755E"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484776213F3E484F4E4D4648502B564B4E2E5959595F4C564F3764535750"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b5ba==9cjag", "6B6A6E3D736E72747A7172727A747D777E7C7E4E24"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6B6B73716C73746F727A79"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b9643g3/9e", "6A"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b;45>:bi9i7ie", "2B2E2C3D"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b<:222h64<", "393F352F3E"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b=+03eh8h8j?:", "4443"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B2651464929655046566470727951555E5E52"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9b?b0d:8aj62<h", "6D"); Zeile gelöscht : user_pref("CT2269050.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B"); Zeile gelöscht : user_pref("CT2269050.backendstorage.hxxp://cmg1_conduit-widgets_com/pitsi.state", "4F50454E"); Zeile gelöscht : user_pref("CT2269050.backendstorage.hxxp://storage_conduit_com/marketplace/83/6d/8399d181-be98-42f2-b035-1616f617316d/.pricesparrowuuid", "31383639343833342D373033352D343944352D393343452D3634393236414[...] Zeile gelöscht : user_pref("CT2269050.backendstorage.pg_enable", "74727565"); Zeile gelöscht : user_pref("CT2269050.backendstorage.searchappstate", "32"); Zeile gelöscht : user_pref("CT2269050.backendstorage.searchapptracking", "73656E74"); Zeile gelöscht : user_pref("CT2269050.clientLogIsEnabled", false); Zeile gelöscht : user_pref("CT2269050.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent"); Zeile gelöscht : user_pref("CT2269050.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;services.apps.conduit.com\",\"AppsDetectionUrlPattern\":\"hxxp://appdown[...] Zeile gelöscht : user_pref("CT2269050.globalFirstTimeInfoLastCheckTime", "Mon Jan 20 2014 18:43:32 GMT+0100"); Zeile gelöscht : user_pref("CT2269050.homepageProtectorEnableByLogin", true); Zeile gelöscht : user_pref("CT2269050.initDone", true); Zeile gelöscht : user_pref("CT2269050.isAppTrackingManagerOn", false); Zeile gelöscht : user_pref("CT2269050.isFirstRadioInstallation", false); Zeile gelöscht : user_pref("CT2269050.myStuffEnabled", true); Zeile gelöscht : user_pref("CT2269050.myStuffPublihserMinWidth", 400); Zeile gelöscht : user_pref("CT2269050.myStuffSearchUrl", "hxxp://appstrm.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID"); Zeile gelöscht : user_pref("CT2269050.myStuffServiceIntervalMM", 1440); Zeile gelöscht : user_pref("CT2269050.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT"); Zeile gelöscht : user_pref("CT2269050.oldAppsList", "128834881989343894,128834881989343895,111,129466585399606892,129881140170815901,129391330693125668,129863783591067571,129881141106886992,129121052374999726,12995731[...] Zeile gelöscht : user_pref("CT2269050.revertSettingsEnabled", true); Zeile gelöscht : user_pref("CT2269050.searchProtectorDialogDelayInSec", 10); Zeile gelöscht : user_pref("CT2269050.searchProtectorEnableByLogin", true); Zeile gelöscht : user_pref("CT2269050.testingCtid", ""); Zeile gelöscht : user_pref("CT2269050.toolbarAppMetaDataLastCheckTime", "Tue Jan 21 2014 22:04:01 GMT+0100"); Zeile gelöscht : user_pref("CT2269050.toolbarContextMenuLastCheckTime", "Tue Jan 21 2014 22:04:01 GMT+0100"); Zeile gelöscht : user_pref("CT2269050.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation"); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2269050/CT2269050", "\"2563dd4b064526bd769907469114d1003\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/666138/661999/DE", "\"0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2269050", "\"1365594729\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en", "G9mW7heT/8xIX1frcduu0A=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en&ctid=CT2269050", "eSzELtoCN6VQCYiv1tPI+g=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en", "2E1/v7EfCEDbv3VaBQMELg=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en&ctid=CT2269050", "HYogGBUvv90IWu2NxeLYvA=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en", "UgzXjW7BIkfdx+x39Ruv3w=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en&ctid=CT2269050", "aXc5Vsxqu/hbyzW/5Q4N6w=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en", "4BgM4MhF/sOgPsDNmIs3Yw=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en&ctid=CT2269050", "ZI41WLbm1fFgx4gn0bs99Q=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en&ctid=CT2269050&UM=UM_UNINSTALL_ID", "9tP0a9tLQ7LYpUSrjHx9xA=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"c70353cabc2ce1:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.0.6", "\"dfe74040abc2ce1:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2269050", "\"7097fd37277b6a1b754b125bd11d0197\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2269050&octid=CT2269050", "\"ef808ae2fa8a68c5242bd2287b0ac9b41\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer_dead.gif", "\"0a8c48d3330c81:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.gif", "\"0e2106f3030c81:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif", "\"0f475394430c81:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif", "\"08d9ef44430c81:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif", "\"066e8863030c81:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE", "\"46d3090900b361b16f35d04d99e415ff\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"cac9bd75d98049295759dd50972793f2\""); Zeile gelöscht : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Claudia\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\mp504yaj.default\\conduitCommon\\modules\\3.7.0.6"); Zeile gelöscht : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.7.0.6"); Zeile gelöscht : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q="); Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList", "CT2269050"); Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList2", "CT2269050"); Zeile gelöscht : user_pref("CommunityToolbar.globalUserId", "09618dba-2061-4c2c-98ad-999d0e1bd89a"); Zeile gelöscht : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Zeile gelöscht : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Zeile gelöscht : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Mon Jan 20 2014 18:43:32 GMT+0100"); Zeile gelöscht : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); Zeile gelöscht : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Tue Jan 21 2014 22:04:08 GMT+0100"); Zeile gelöscht : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Zeile gelöscht : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true); Zeile gelöscht : user_pref("CommunityToolbar.notifications.locale", "en"); Zeile gelöscht : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Zeile gelöscht : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Tue Jan 21 2014 22:04:01 GMT+0100"); Zeile gelöscht : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Zeile gelöscht : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Zeile gelöscht : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Zeile gelöscht : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Zeile gelöscht : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Zeile gelöscht : user_pref("CommunityToolbar.notifications.userId", "4b508a22-e933-4bfd-9e1e-9bd7f9932079"); Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://www.hiergehtslos.de"); Zeile gelöscht : user_pref("extensions.snipit.askTbInstalled", true); Zeile gelöscht : user_pref("icqtoolbar.allowSendURL", false); Zeile gelöscht : user_pref("icqtoolbar.engineVerified", false); Zeile gelöscht : user_pref("icqtoolbar.geolastmodified", 1402785625); Zeile gelöscht : user_pref("icqtoolbar.hiddenElements", "itb_options"); Zeile gelöscht : user_pref("icqtoolbar.history", "lufthansa%20karriere%20cockpit||vox%20now%20||claudia%20nachname||zdf%20mediathek||web||air%20berlin%20counter%20card||dsb%20dm%202011%20limitzahlen||dsb%20dm%2020[...] Zeile gelöscht : user_pref("icqtoolbar.icqgeo", 49); Zeile gelöscht : user_pref("icqtoolbar.installTime", "1313249385"); Zeile gelöscht : user_pref("icqtoolbar.installsource", "1"); Zeile gelöscht : user_pref("icqtoolbar.newtab_state", "1"); Zeile gelöscht : user_pref("icqtoolbar.numberOfSearches", 0); Zeile gelöscht : user_pref("icqtoolbar.previousFFVersion", "3.0"); Zeile gelöscht : user_pref("icqtoolbar.skip_default_search", "no"); Zeile gelöscht : user_pref("icqtoolbar.suggestions", false); Zeile gelöscht : user_pref("icqtoolbar.uniqueID", "122669170112266906761229625558098"); Zeile gelöscht : user_pref("icqtoolbar.usageStatstTimestamp", 1402785628); Zeile gelöscht : user_pref("icqtoolbar.version", "1.1.9"); Zeile gelöscht : user_pref("icqtoolbar.voucherHideClicks", 0); Zeile gelöscht : user_pref("icqtoolbar.voucherMoreLinkClicks", 0); Zeile gelöscht : user_pref("icqtoolbar.voucherRedeemClicks", 0); Zeile gelöscht : user_pref("icqtoolbar.voucherWasShown", 0); Zeile gelöscht : user_pref("icqtoolbar.xmlEnableSuggestions", false); Zeile gelöscht : user_pref("icqtoolbar.xmlLanguage", "de"); -\\ Google Chrome v35.0.1916.153 [ Datei : C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [36836 octets] - [17/06/2014 18:22:20] AdwCleaner[R1].txt - [36528 octets] - [17/06/2014 18:34:30] AdwCleaner[R2].txt - [36648 octets] - [17/06/2014 18:50:52] AdwCleaner[S0].txt - [771 octets] - [17/06/2014 18:24:41] AdwCleaner[S1].txt - [394 octets] - [17/06/2014 18:35:37] AdwCleaner[S2].txt - [34110 octets] - [17/06/2014 18:52:03] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [34171 octets] ########## Der JRT-Log: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows Vista (TM) Home Premium x86 Ran by Claudia on 17.06.2014 at 19:57:52,17 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Successfully deleted the following from C:\Users\Claudia\AppData\Roaming\mozilla\firefox\profiles\mp504yaj.default\prefs.js user_pref("extensions.snipit.chromeURL", "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q={searchTerms}&crm=1"); user_pref("keyword.URL", "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q="); ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 17.06.2014 at 20:03:21,43 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Der FRST-Log: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:16-06-2014 Ran by Claudia (administrator) on CLAUDIA1 on 17-06-2014 20:05:39 Running from C:\Users\Claudia\Desktop Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (ABBYY) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (Google Inc.) C:\Program Files\Google\Update\1.3.24.15\GoogleCrashHandler.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPStart.exe () C:\Program Files\Launch Manager\LaunchAp.exe (Wistron) C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron Corp.) C:\Program Files\Launch Manager\OSD.exe (Wistron) C:\Program Files\Launch Manager\WButton.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe () C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe (Empolis GmbH) C:\Program Files\Common Files\Gnab\Service\ServiceController.exe (SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe (Sonix) C:\Windows\vsnp2uvc.exe () C:\Windows\FixCamera.exe () C:\Windows\tsnp2uvc.exe () C:\Program Files\1&1 Surf-Stick\UIExec.exe () C:\Program Files\TV IR\TV IR.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Google Inc.) C:\Program Files\Picasa2\PicasaMediaDetector.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGCE.EXE (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGCE.EXE (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Empolis GmbH) C:\Program Files\Medion\MEDIONbox\Program\GCS.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (1&1 Mail & Media GmbH) C:\Users\Claudia\AppData\Local\GMX Application {sync-000021}\gmx_mediacenter.exe (Microsoft Corporation) C:\Windows\System32\p2phost.exe (ArcSoft, Inc.) C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe (Dropbox, Inc.) C:\Users\Claudia\AppData\Roaming\Dropbox\bin\Dropbox.exe (InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe () C:\Windows\System32\PSIService.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Buhl Data Service GmbH) C:\Program Files\Sceneo\AbsolutTV\Services\PVR\pvrservice.exe () C:\Program Files\1&1 Surf-Stick\AssistantServices.exe (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Wistron Corp.) C:\Program Files\Launch Manager\WisLMSvc.exe (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation) C:\Windows\System32\sdclt.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [178712 2007-10-03] (Intel Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6025216 2008-04-01] (Realtek Semiconductor) HKLM\...\Run: [SynTPStart] => C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2007-08-31] (Synaptics, Inc.) HKLM\...\Run: [LaunchAp] => C:\Program Files\Launch Manager\LaunchAp.exe [32768 2007-09-01] () HKLM\...\Run: [HotkeyApp] => C:\Program Files\Launch Manager\HotkeyApp.exe [188416 2007-09-06] (Wistron) HKLM\...\Run: [CtrlVol] => "C:\Program Files\Launch Manager\CtrlVol.exe" HKLM\...\Run: [LMgrOSD] => C:\Program Files\Launch Manager\OSD.exe [180224 2006-12-26] (Wistron Corp.) HKLM\...\Run: [Wbutton] => C:\Program Files\Launch Manager\Wbutton.exe [86016 2007-09-07] (Wistron) HKLM\...\Run: [toolbar_eula_launcher] => C:\Program Files\GoogleEULA\EULALauncher.exe [16896 2007-02-09] ( ) HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [Corel Photo Downloader] => "C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel PhotoDownloader.exe" -startup HKLM\...\Run: [Corel File Shell Monitor] => C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe [16200 2007-10-30] () HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.) HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [976320 2009-12-03] (SEIKO EPSON CORPORATION) HKLM\...\Run: [snp2uvc] => C:\Windows\vsnp2uvc.exe [581632 2007-11-30] (Sonix) HKLM\...\Run: [FixCamera] => C:\Windows\FixCamera.exe [20480 2007-02-12] () HKLM\...\Run: [tsnp2uvc] => C:\Windows\tsnp2uvc.exe [249856 2007-12-04] () HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40368 2011-05-27] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-03-29] (Adobe Systems Incorporated) HKLM\...\Run: [UIExec] => C:\Program Files\1&1 Surf-Stick\UIExec.exe [139088 2010-09-30] () HKLM\...\Run: [TV IR] => C:\Program Files\TV IR\TV IR.exe [692318 2010-12-22] () HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [183376 2014-05-14] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-09] (Avira Operations GmbH & Co. KG) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [1828136 2008-02-28] (Nero AG) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Picasa Media Detector] => C:\Program Files\Picasa2\PicasaMediaDetector.exe [443968 2008-02-26] (Google Inc.) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [EPSON SX420W Series] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIGCE.EXE [200704 2009-09-14] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Epson Stylus SX420W(Netzwerk)] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIGCE.EXE [200704 2009-09-14] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Device Detection] => C:\Program Files\Lidl_Fotos\dd.exe HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [GMX Application {sync-000021}] => C:\Users\Claudia Grützmacher\AppData\Local\GMX Application {sync-000021}\gmx_mediacenter.exe [878080 2013-08-09] (1&1 Mail & Media GmbH) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [CollaborationHost] => C:\Windows\system32\p2phost.exe [192000 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\RunOnce: [Shockwave Updater] - C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1100429.exe [439736 2008-03-19] (Adobe Systems, Inc.) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\MountPoints2: {680ae5c9-5a41-11de-81b4-0015afb8023d} - G:\BlueJ.bat HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\MountPoints2: {b7bf007e-eef6-11e3-92c0-000ae4cddb4b} - F:\HTC_Sync_Manager_PC.exe AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL File Not Found Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk ShortcutTarget: TMMonitor.lnk -> C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.) Startup: C:\Users\Claudia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Claudia\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} URLSearchHook: HKLM - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File URLSearchHook: HKCU - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {01_TL-YODL-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_google&q={searchTerms} SearchScopes: HKCU - {03_TL-TELEFONBUCH-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_telefonbuch&q={searchTerms} SearchScopes: HKCU - {04_TL-AMAZON-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_amazon&q={searchTerms} SearchScopes: HKCU - {05_TL-EBAY-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_ebay&q={searchTerms} SearchScopes: HKCU - {06_TL-DISCOUNT24-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_discount24&q={searchTerms} SearchScopes: HKCU - {07_TL-CONRAD-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_conrad&q={searchTerms} SearchScopes: HKCU - {08_TL-OTTO-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_otto&q={searchTerms} SearchScopes: HKCU - {09_TL-CLIPFISH-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_clipfish&q={searchTerms} SearchScopes: HKCU - {10_TL-MYVIDEO-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_myvideo&q={searchTerms} SearchScopes: HKCU - {11_TL-MUSICLOAD-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_musicload&q={searchTerms} SearchScopes: HKCU - {DBAFD4EB-E4E1-4A25-97C2-D1CB5F7D0368} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=971163&p={searchTerms} BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.) BHO: No Name - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO: DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File Toolbar: HKLM - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - DVDVideoSoftTB Toolbar - {E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} hxxp://photoservice.fujicolor.de/ips-opdata/objects/jordan.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 83.169.185.161 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default FF DefaultSearchEngine: ICQ Search FF SearchEngineOrder.1: Ask FF SelectedSearchEngine: ICQ Search FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdivx32.dll (DivX,Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\clipfish.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\conrad.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\discount24.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\ebay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\musicload.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\myvideo.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\otto.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\quelle.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\telefonbuch-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\webnews.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Microsoft .NET Framework Assistant - C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2009-08-13] FF Extension: Firefox Companion for eBay - C:\Program Files\Mozilla Firefox\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088} [2008-11-14] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKLM\...\Firefox\Extensions: - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: 卡巴斯基網址顧問 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-14] FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: 虛擬鍵盤 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-14] FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: 惡意網站攔截器 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-14] FF HKCU\...\Thunderbird\Extensions: [{0E810812-F4BB-4309-942A-755587587A5E}] - C:\Program Files\BullGuard Software\BullGuard\antispam\tbspamfilter Chrome: ======= CHR HomePage: CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll () CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (DivX Web Player) - C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll (DivX,Inc.) CHR Plugin: (DivX Player Netscape Plugin) - C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc) CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Plugin: (Picasa) - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (No Name) - C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2014-06-14] CHR Extension: (Google Wallet) - C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-14] CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] ========================== Services (Whitelisted) ================= R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY) R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [123984 2014-05-14] (Avira Operations GmbH & Co. KG) R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files\ALDI Foto Service Nord\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) [File not signed] R2 GnabService; c:\program files\common files\gnab\service\servicecontroller.exe [36864 2007-04-19] (Empolis GmbH) [File not signed] S2 gupdate1c9e6034feeea56; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-06-05] (Google Inc.) R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] () [File not signed] R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1801216 2008-02-28] (Buhl Data Service GmbH) [File not signed] R2 UI Assistant Service; C:\Program Files\1&1 Surf-Stick\AssistantServices.exe [253264 2010-09-30] () R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [61440 2006-06-14] (Ulead Systems, Inc.) [File not signed] S3 usnjsvc; C:\Program Files\MSN Messenger\usnsvc.exe [97136 2007-01-19] (Microsoft Corporation) R3 WisLMSvc; C:\Program Files\Launch Manager\WisLMSvc.exe [118784 2007-09-11] (Wistron Corp.) [File not signed] ==================== Drivers (Whitelisted) ==================== R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) [File not signed] R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [93528 2014-05-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-05-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2014-05-09] (Avira Operations GmbH & Co. KG) S3 DVC; C:\Windows\System32\Drivers\DVC.sys [38401 2001-09-09] (Samsung Electronics) [File not signed] R1 Hotkey; C:\Windows\system32\Drivers\Hotkey.sys [9867 2003-04-28] () [File not signed] R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-06-14] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576608 2014-06-14] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-06-14] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2014-06-14] (Kaspersky Lab ZAO) R0 Si3531; C:\Windows\System32\DRIVERS\Si3531.sys [212008 2008-07-25] (Silicon Image, Inc) R0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [17064 2008-07-25] (Silicon Image, Inc.) R0 SiRemFil; C:\Windows\System32\DRIVERS\SiRemFil.sys [12200 2008-07-25] (Silicon Image, Inc.) S3 smsbda; C:\Windows\System32\drivers\smsbda.sys [45440 2011-03-06] (Siano) S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [9610880 2007-11-29] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2014-05-09] (Avira GmbH) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] U5 klflt; C:\Windows\System32\Drivers\klflt.sys [94304 2014-06-14] (Kaspersky Lab ZAO) S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-17 20:03 - 2014-06-17 20:03 - 00001033 _____ () C:\Users\Claudia\Desktop\JRT.txt 2014-06-17 19:57 - 2014-06-17 19:57 - 01016261 _____ (Thisisu) C:\Users\Claudia\Desktop\JRT.exe 2014-06-17 19:57 - 2014-06-17 19:57 - 00000000 ____D () C:\Windows\ERUNT 2014-06-17 18:23 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll 2014-06-17 18:22 - 2014-06-17 19:06 - 00000000 ____D () C:\AdwCleaner 2014-06-17 18:20 - 2014-06-17 18:20 - 01333465 _____ () C:\Users\Claudia\Desktop\adwcleaner_3.212.exe 2014-06-16 23:37 - 2014-06-16 23:37 - 00000000 ____D () C:\Users\Claudia\Desktop\FRST-OlderVersion 2014-06-16 21:59 - 2014-06-16 21:59 - 00002812 _____ () C:\Users\Claudia\Desktop\Fixlist.txt 2014-06-15 10:35 - 2014-06-15 10:35 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Claudia\Desktop\mbam-setup-2.0.2.1012.exe 2014-06-15 03:23 - 2014-06-15 03:23 - 00055613 _____ () C:\Users\Claudia\Desktop\FRST ohne Nachname.txt 2014-06-15 03:23 - 2014-06-15 03:23 - 00043788 _____ () C:\Users\Claudia\Desktop\Addition ohne Nachname.txt 2014-06-15 02:15 - 2014-06-15 02:29 - 00044164 _____ () C:\Users\Claudia\Desktop\Addition.txt 2014-06-15 02:11 - 2014-06-17 20:05 - 00029574 _____ () C:\Users\Claudia\Desktop\FRST.txt 2014-06-15 02:05 - 2014-06-17 20:05 - 00000000 ____D () C:\FRST 2014-06-15 02:03 - 2014-06-16 23:37 - 01072640 _____ (Farbar) C:\Users\Claudia\Desktop\FRST.exe 2014-06-15 00:42 - 2014-06-15 00:42 - 00001006 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-06-15 00:42 - 2014-06-15 00:42 - 00000000 ____D () C:\ProgramData\Package Cache 2014-06-15 00:41 - 2014-06-15 00:41 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Claudia\Desktop\avira_de_av_4019404326__ws.exe 2014-06-14 22:13 - 2014-06-14 22:13 - 00227096 _____ () C:\Users\Claudia\Desktop\avira_registry_cleaner_de.exe 2014-06-14 14:46 - 2014-06-14 14:46 - 00262144 _____ () C:\Windows\system32\config\elam 2014-06-14 14:04 - 2014-06-14 14:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus 2014-06-14 14:04 - 2014-06-14 14:02 - 00000970 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2014-06-14 13:57 - 2014-06-17 19:50 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-06-14 13:57 - 2014-06-14 14:31 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-06-14 13:57 - 2014-06-14 14:31 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-06-14 13:57 - 2014-06-14 13:57 - 00000000 ____D () C:\Program Files\Kaspersky Lab 2014-06-14 01:15 - 2014-06-14 01:15 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\PeerNetworking 2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\TuneUp Software 2014-06-13 22:47 - 2014-06-17 19:45 - 00000000 ____D () C:\ProgramData\MFAData 2014-06-13 22:47 - 2014-06-13 22:47 - 00000000 ____D () C:\Users\Claudia\AppData\Local\MFAData 2014-06-13 22:42 - 2014-06-13 22:45 - 164819976 _____ (AVG Technologies) C:\Users\Claudia\Desktop\avg_free_x64_all_2014_4592a7484.exe 2014-06-13 21:56 - 2014-06-13 22:41 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Nico Mak Computing 2014-06-11 19:28 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-11 19:27 - 2014-05-28 18:48 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-11 19:27 - 2014-05-28 18:39 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-11 19:27 - 2014-05-28 18:38 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-11 19:27 - 2014-05-28 18:33 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-11 19:27 - 2014-05-28 18:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-11 19:27 - 2014-05-28 18:32 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-11 19:27 - 2014-05-28 18:31 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-06-11 19:27 - 2014-05-28 18:31 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-11 19:27 - 2014-05-28 18:30 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-06-11 19:27 - 2014-05-28 18:29 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-11 19:27 - 2014-05-28 18:29 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-11 19:27 - 2014-05-28 18:29 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-11 19:27 - 2014-05-28 18:29 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-06-11 19:27 - 2014-05-28 18:29 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-06-11 19:27 - 2014-05-28 18:28 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-11 19:27 - 2014-04-05 04:42 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-11 19:27 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-11 19:27 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-08 13:24 - 2014-06-08 13:24 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf 2014-06-08 12:54 - 2014-06-08 12:54 - 00000000 ____D () C:\Program Files\HTC 2014-06-08 12:45 - 2014-06-08 12:45 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Downloaded Installations 2014-06-08 12:42 - 2014-06-08 12:56 - 00000000 ____D () C:\Temp 2014-06-08 12:42 - 2014-06-08 12:42 - 00000000 ____D () C:\ProgramData\HTC 2014-06-08 12:42 - 2009-06-10 09:49 - 00024576 _____ (HTC, Corporation) C:\Windows\system32\Drivers\ANDROIDUSB.sys 2014-06-08 12:42 - 2009-06-09 07:41 - 01122664 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll 2014-06-07 20:30 - 2014-06-16 22:17 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Adobe 2014-06-07 19:59 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet (1).RequestDispatcherServlet 2014-06-07 19:56 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet.RequestDispatcherServlet 2014-05-18 00:39 - 2014-05-18 00:39 - 00000000 ____D () C:\Users\Claudia\restore 2014-05-18 00:02 - 2014-06-14 01:26 - 00000000 ____D () C:\ProgramData\tmp 2014-05-18 00:02 - 2014-05-18 16:35 - 00000000 ____D () C:\ProgramData\hps 2014-05-18 00:01 - 2014-05-18 00:01 - 00001106 _____ () C:\Users\Public\Desktop\OnlineFotoservice.lnk 2014-05-18 00:01 - 2014-05-18 00:01 - 00001091 _____ () C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk 2014-05-18 00:01 - 2014-05-18 00:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OnlineFotoservice ==================== One Month Modified Files and Folders ======= 2014-06-17 20:06 - 2014-06-15 02:11 - 00029574 _____ () C:\Users\Claudia\Desktop\FRST.txt 2014-06-17 20:06 - 2012-09-08 16:32 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Dropbox 2014-06-17 20:06 - 2008-08-07 14:00 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Temp 2014-06-17 20:05 - 2014-06-15 02:05 - 00000000 ____D () C:\FRST 2014-06-17 20:03 - 2014-06-17 20:03 - 00001033 _____ () C:\Users\Claudia\Desktop\JRT.txt 2014-06-17 19:57 - 2014-06-17 19:57 - 01016261 _____ (Thisisu) C:\Users\Claudia\Desktop\JRT.exe 2014-06-17 19:57 - 2014-06-17 19:57 - 00000000 ____D () C:\Windows\ERUNT 2014-06-17 19:55 - 2008-08-07 13:55 - 01578003 _____ () C:\Windows\WindowsUpdate.log 2014-06-17 19:50 - 2014-06-14 13:57 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-06-17 19:50 - 2014-05-13 22:19 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\DropboxMaster 2014-06-17 19:50 - 2012-09-08 16:36 - 00000000 ___RD () C:\Users\Claudia\Dropbox 2014-06-17 19:48 - 2006-11-02 14:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-17 19:48 - 2006-11-02 14:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-17 19:46 - 2009-06-30 19:24 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-17 19:46 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-17 19:45 - 2014-06-13 22:47 - 00000000 ____D () C:\ProgramData\MFAData 2014-06-17 19:45 - 2008-01-21 04:47 - 00526790 _____ () C:\Windows\PFRO.log 2014-06-17 19:45 - 2006-11-02 15:01 - 00032534 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-06-17 19:16 - 2009-06-30 19:24 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-17 19:06 - 2014-06-17 18:22 - 00000000 ____D () C:\AdwCleaner 2014-06-17 19:06 - 2008-11-14 21:23 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-06-17 18:24 - 2012-12-31 17:41 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft 2014-06-17 18:24 - 2008-08-07 14:18 - 00000000 ____D () C:\ProgramData\ICQ 2014-06-17 18:20 - 2014-06-17 18:20 - 01333465 _____ () C:\Users\Claudia\Desktop\adwcleaner_3.212.exe 2014-06-17 18:18 - 2009-08-24 13:59 - 00000000 ____D () C:\Users\Claudia\Documents\Bewerbung 2014-06-17 18:15 - 2008-11-30 15:45 - 00002627 _____ () C:\Users\Claudia\Desktop\Microsoft Office Word 2007.lnk 2014-06-16 23:37 - 2014-06-16 23:37 - 00000000 ____D () C:\Users\Claudia\Desktop\FRST-OlderVersion 2014-06-16 23:37 - 2014-06-15 02:03 - 01072640 _____ (Farbar) C:\Users\Claudia\Desktop\FRST.exe 2014-06-16 22:17 - 2014-06-07 20:30 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Adobe 2014-06-16 22:06 - 2008-01-21 09:16 - 01643446 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-16 22:02 - 2006-11-02 14:52 - 00162998 _____ () C:\Windows\setupact.log 2014-06-16 21:59 - 2014-06-16 21:59 - 00002812 _____ () C:\Users\Claudia\Desktop\Fixlist.txt 2014-06-15 10:35 - 2014-06-15 10:35 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Claudia\Desktop\mbam-setup-2.0.2.1012.exe 2014-06-15 03:23 - 2014-06-15 03:23 - 00055613 _____ () C:\Users\Claudia\Desktop\FRST ohne Nachname.txt 2014-06-15 03:23 - 2014-06-15 03:23 - 00043788 _____ () C:\Users\Claudia\Desktop\Addition ohne Nachname.txt 2014-06-15 02:29 - 2014-06-15 02:15 - 00044164 _____ () C:\Users\Claudia\Desktop\Addition.txt 2014-06-15 00:42 - 2014-06-15 00:42 - 00001006 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-06-15 00:42 - 2014-06-15 00:42 - 00000000 ____D () C:\ProgramData\Package Cache 2014-06-15 00:42 - 2012-11-25 22:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-06-15 00:42 - 2012-10-23 16:35 - 00000000 ____D () C:\ProgramData\Avira 2014-06-15 00:42 - 2012-10-23 16:35 - 00000000 ____D () C:\Program Files\Avira 2014-06-15 00:41 - 2014-06-15 00:41 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Claudia Grützmacher\Desktop\avira_de_av_4019404326__ws.exe 2014-06-14 22:13 - 2014-06-14 22:13 - 00227096 _____ () C:\Users\Claudia\Desktop\avira_registry_cleaner_de.exe 2014-06-14 19:19 - 2012-11-17 22:37 - 00001967 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-06-14 14:46 - 2014-06-14 14:46 - 00262144 _____ () C:\Windows\system32\config\elam 2014-06-14 14:31 - 2014-06-14 13:57 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-06-14 14:31 - 2014-06-14 13:57 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-06-14 14:31 - 2013-10-17 15:47 - 00135776 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2014-06-14 14:31 - 2013-10-17 15:47 - 00025184 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys 2014-06-14 14:31 - 2013-06-06 17:38 - 00144992 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys 2014-06-14 14:04 - 2014-06-14 14:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus 2014-06-14 14:02 - 2014-06-14 14:04 - 00000970 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2014-06-14 14:01 - 2008-08-07 14:00 - 00000000 ____D () C:\Users\Claudia 2014-06-14 13:57 - 2014-06-14 13:57 - 00000000 ____D () C:\Program Files\Kaspersky Lab 2014-06-14 01:26 - 2014-05-18 00:02 - 00000000 ____D () C:\ProgramData\tmp 2014-06-14 01:15 - 2014-06-14 01:15 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\PeerNetworking 2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\TuneUp Software 2014-06-13 22:47 - 2014-06-13 22:47 - 00000000 ____D () C:\Users\Claudia\AppData\Local\MFAData 2014-06-13 22:45 - 2014-06-13 22:42 - 164819976 _____ (AVG Technologies) C:\Users\Claudia\Desktop\avg_free_x64_all_2014_4592a7484.exe 2014-06-13 22:41 - 2014-06-13 21:56 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Nico Mak Computing 2014-06-11 20:10 - 2008-04-21 14:41 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-06-11 20:05 - 2013-08-06 20:05 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-11 20:05 - 2006-11-02 12:24 - 92708840 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-06-09 01:59 - 2008-08-07 18:11 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Corel 2014-06-09 00:54 - 2008-08-07 19:39 - 00000000 ____D () C:\Users\Claudia\Documents\My PSP Files 2014-06-09 00:54 - 2008-08-07 18:12 - 00004182 ___SH () C:\Windows\system32\KGyGaAvL.sys 2014-06-08 13:24 - 2014-06-08 13:24 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf 2014-06-08 12:56 - 2014-06-08 12:42 - 00000000 ____D () C:\Temp 2014-06-08 12:54 - 2014-06-08 12:54 - 00000000 ____D () C:\Program Files\HTC 2014-06-08 12:54 - 2008-04-21 09:32 - 00025966 _____ () C:\Windows\DPINST.LOG 2014-06-08 12:45 - 2014-06-08 12:45 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Downloaded Installations 2014-06-08 12:42 - 2014-06-08 12:42 - 00000000 ____D () C:\ProgramData\HTC 2014-06-07 20:25 - 2012-07-08 20:11 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-06-07 20:25 - 2011-07-13 22:41 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-06-07 19:59 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet (1).RequestDispatcherServlet 2014-06-07 19:59 - 2014-06-07 19:56 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet.RequestDispatcherServlet 2014-06-07 19:57 - 2008-04-21 10:34 - 00000000 ____D () C:\ProgramData\Adobe 2014-05-28 18:48 - 2014-06-11 19:27 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-28 18:39 - 2014-06-11 19:27 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-05-28 18:38 - 2014-06-11 19:27 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-05-28 18:33 - 2014-06-11 19:27 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-05-28 18:32 - 2014-06-11 19:27 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-05-28 18:32 - 2014-06-11 19:27 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-05-28 18:31 - 2014-06-11 19:27 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-05-28 18:31 - 2014-06-11 19:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-05-28 18:30 - 2014-06-11 19:27 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-05-28 18:29 - 2014-06-11 19:27 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-28 18:29 - 2014-06-11 19:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-05-28 18:29 - 2014-06-11 19:27 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-28 18:29 - 2014-06-11 19:27 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-05-28 18:29 - 2014-06-11 19:27 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-05-28 18:28 - 2014-06-11 19:27 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-05-24 12:35 - 2012-09-08 16:36 - 00000965 _____ () C:\Users\Claudia\Desktop\Dropbox.lnk 2014-05-24 12:35 - 2012-09-08 16:33 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-05-18 21:51 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-05-18 19:45 - 2009-06-08 18:48 - 00000000 ____D () C:\Program Files\Picasa2 2014-05-18 19:10 - 2009-11-15 15:52 - 00130060 _____ () C:\Users\Claudia\AppData\Roaming\mdbu.bin 2014-05-18 16:35 - 2014-05-18 00:02 - 00000000 ____D () C:\ProgramData\hps 2014-05-18 00:39 - 2014-05-18 00:39 - 00000000 ____D () C:\Users\Claudia\restore 2014-05-18 00:01 - 2014-05-18 00:01 - 00001106 _____ () C:\Users\Public\Desktop\OnlineFotoservice.lnk 2014-05-18 00:01 - 2014-05-18 00:01 - 00001091 _____ () C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk 2014-05-18 00:01 - 2014-05-18 00:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OnlineFotoservice Files to move or delete: ==================== C:\Users\Claudia\AppData\Roaming\desktop.ini Some content of TEMP: ==================== C:\Users\Claudia\AppData\Local\Temp\avgnt.exe C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpv7f1bw.dll C:\Users\Claudia\AppData\Local\Temp\ffunzip.exe C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate.exe C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate01.exe C:\Users\Claudia\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe C:\Users\Claudia\AppData\Local\Temp\GDM272F.exe C:\Users\Claudia\AppData\Local\Temp\GDM34A6.exe C:\Users\Claudia\AppData\Local\Temp\GLF3BB0.tmp.ConduitEngineSetup.exe C:\Users\Claudia\AppData\Local\Temp\GoogleChromeInstaller.exe C:\Users\Claudia\AppData\Local\Temp\IcqUpdater.exe C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssa_aih[1].exe C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssd_aih[1].exe C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10_mssd_aih.exe C:\Users\Claudia\AppData\Local\Temp\JiveXViewerStart1363355292.exe C:\Users\Claudia\AppData\Local\Temp\Opera_1150_int_Setup.exe C:\Users\Claudia\AppData\Local\Temp\prxGLF3BB0.tmp.tbDVDV.dll C:\Users\Claudia\AppData\Local\Temp\Quarantine.exe C:\Users\Claudia\AppData\Local\Temp\SearchWithGoogleUpdate.exe C:\Users\Claudia\AppData\Local\Temp\tbDVDV.dll C:\Users\Claudia\AppData\Local\Temp\unwise.exe C:\Users\Claudia\AppData\Local\Temp\VisusClient.dll C:\Users\Claudia\AppData\Local\Temp\wpsetup.exe C:\Users\Claudia\AppData\Local\Temp\_is30.exe C:\Users\Claudia\AppData\Local\Temp\_is6CF6.exe C:\Users\Claudia\AppData\Local\Temp\_is92AD.exe C:\Users\Claudia\AppData\Local\Temp\{1167C4F7-64B6-4A1D-A0A5-B605C6CDE10F}-26.0.1410.64_25.0.1364.172_chrome_updater.exe C:\Users\Claudia\AppData\Local\Temp\{5A7A4717-CEF4-4E4A-B23E-0838114D47F8}-chrome_installer.exe C:\Users\Claudia\AppData\Local\Temp\{C2722232-3395-42BA-9B03-4B2C787E8081}-chrome_installer.exe C:\Users\Claudia\AppData\Local\Temp\{D2416B08-7E6C-4C05-B27E-05A6DEC53BCD}-30.0.1599.69_29.0.1547.76_chrome_updater.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-17 19:55 ==================== End Of Log ============================ |
17.06.2014, 21:03 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Avira durch Gruppenrichtlinie geblockt - Trojaner? Bitte auch ne neue Addition.txt erstellen, dazu FRST starten und einen Haken setzen bei Addition.txt, dann auf Scan klicken.
__________________ Logfiles bitte immer in CODE-Tags posten |
17.06.2014, 22:05 | #9 |
| Avira durch Gruppenrichtlinie geblockt - Trojaner? Ich musste vorhin auch AVG deinstallieren, da ich den Schutz nicht deaktivieren konnte. Habe zwar mehrmals draufgeklickt, aber in der AVG-Historie wurde keine Abschaltung vermerkt. Vielen Dank für deine Hilfe. Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:16-06-2014 Ran by Claudia at 2014-06-17 22:52:42 Running from C:\Users\Claudia\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Kaspersky Anti-Virus (Disabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Anti-Virus (Disabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0C5823AA-7B6F- 44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft) Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA- 7B6F-44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft) 1&1 Surf-Stick (HKLM\...\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.2 - ) 3531-W-D (HKLM\...\{BD1587F7-B8D0-4111-8F1F-3327628AB02F}) (Version: 1.5.18 - Silicon Image) AAC Decoder (HKLM\...\{AEF9DC35ADDF4825B049ACBFD1C6EB37}) (Version: 7.1.0 - DivX, Inc.) ABBYY FineReader 6.0 Sprint (HKLM\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1395.4512 - ABBYY Software House) ABBYY FineReader 9.0 Sprint (HKLM\...\ABBYY FineReader 9.0 Sprint) (Version: 9.01.513.58212 - ABBYY) ABBYY FineReader 9.0 Sprint (Version: 9.01.513.58212 - ABBYY) Hidden Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 13 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Reader 8.3.0 - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-A83000000003}) (Version: 8.3.0 - Adobe Systems Incorporated) Adobe Shockwave Player (HKLM\...\Adobe Shockwave Player) (Version: 11 - Adobe Systems, Inc.) Agere Systems HDA Modem (HKLM\...\Agere Systems Soft Modem) (Version: - Agere Systems) ArcSoft MediaConverter 2 (HKLM\...\{83DA46EC-2CB1-4649-9100-C4F98D8DA8CD}) (Version: - ArcSoft) ArcSoft PhotoImpression 5 (HKLM\...\{4FE82F4B-B7D8-4E65-84AD-E0436CDE57DD}) (Version: - ArcSoft) ArcSoft ShowBiz DVD 2 (HKLM\...\{E883DCB3-766D-4166-8B28-33C8FE451F2B}) (Version: - ArcSoft) ArcSoft TotalMedia 3.5 (HKLM\...\{29E44E9D-ACB2-4D2D-849F-5361C941B7E1}) (Version: 3.5.7.362 - ArcSoft) AutoUpdate (HKLM\...\{18D10072035C4515918F7E37EAFAACFC}) (Version: 1.1 - ) Avira (HKLM\...\{68e29fba-92b1-4f6f-a604-1d8679da3a9f}) (Version: 1.1.13.24161 - Avira Operations GmbH & Co. KG) Avira (Version: 1.1.13.24161 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.4.672 - Avira) Camera RAW Plug-In for EPSON Creativity Suite (HKLM\...\{93EA9C3E-BDFD-4309-A605-9B5BBC0CCEFD}) (Version: 2.2.0.0 - SEIKO EPSON CORPORATION) Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Corel MediaOne (HKLM\...\{A062A15F-9CAC-4B88-98DF-87628A0BD721}) (Version: 2.00.0000 - Corel Corporation) Corel Paint Shop Pro Photo X2 (HKLM\...\{64E72FB1-2343-4977-B4A8-262CD53D0BD3}) (Version: 12.010.0000 - Corel Corporation) Digital Video (HKLM\...\{C833C7B6-1140-471D-932B-391B5CA66D7D}) (Version: 1.00.000 - ) DivX Codec (HKLM\...\{7B63B2922B174135AFC0E1377DD81EC2}) (Version: 6.8.5 - DivX, Inc.) DivX Converter (HKLM\...\{13F3917B56CD4C25848BDC69916971BB}) (Version: 7.0.0 - DivX, Inc.) DivX Converter (HKLM\...\{B13A7C41581B411290FBC0395694E2A9}) (Version: 7.0.0 - DivX, Inc.) DivX Player (HKLM\...\{8ADFC4160D694100B5B8A22DE9DCABD9}) (Version: 7.0.0 - DivX, Inc.) DivX Plus DirectShow Filters (HKLM\...\DivX Plus DirectShow Filters) (Version: - DivX, Inc.) DivX Version Checker (HKLM\...\{3FC7CBBC4C1E11DCA1A752EA55D89593}) (Version: 7.0.0.19 - DivX, Inc.) DivX Web Player (HKLM\...\{B7050CBDB2504B34BC2A9CA0A692CC29}) (Version: 1.4.2 - DivX,Inc.) Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.) DVDVideoSoft Toolbar (HKLM\...\DVDVideoSoft Toolbar) (Version: - ) EPSON Attach To Email (HKLM\...\InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}) (Version: 1.01.0000 - SEIKO EPSON) EPSON Attach To Email (Version: 1.01.0000 - SEIKO EPSON) Hidden EPSON Copy Utility 3 (HKLM\...\{67EDD823-135A-4D59-87BD-950616D6E857}) (Version: 3.3.0.0 - ) EPSON Easy Photo Print (HKLM\...\{3D78F2A2-C893-4ABD-B5FE-AD7011837755}) (Version: 1.5.0.0 - SEIKO EPSON CORPORATION) Epson Easy Photo Print 2 (HKLM\...\{39F58DDB-B2B8-4B86-AF20-4706A80EB30D}) (Version: 2.2.0.0 - SEIKO EPSON CORPORATION) Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION) Epson Event Manager (HKLM\...\{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}) (Version: 2.40.0001 - SEIKO EPSON CORPORATION) EPSON File Manager (HKLM\...\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}) (Version: 1.3.0.0 - ) EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON Scan Assistant (HKLM\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - ) EPSON Stylus CX7300_CX8300_DX7400_DX8400 Handbuch (HKLM\...\EPSON Stylus CX7300_CX8300_DX7400_DX8400 Benutzerhandbuch) (Version: - ) EPSON SX420W Series Handbuch (HKLM\...\EPSON SX420W Series Manual) (Version: - ) EPSON SX420W Series Netzwerk-Handbuch (HKLM\...\EPSON SX420W Series Network Guide) (Version: - ) EPSON SX420W Series Printer Uninstall (HKLM\...\EPSON SX420W Series) (Version: - SEIKO EPSON Corporation) EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version: - SEIKO EPSON Corporation) EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.4i - SEIKO EPSON CORPORATION) EpsonNet Setup 3.2 (HKLM\...\{C9D8A041-2963-4B31-8FFC-1500F3DB9293}) (Version: 3.2a - SEIKO EPSON CORPORATION) Firebird SQL Server - MAGIX Edition (HKLM\...\Firebird SQL Server D) (Version: 2.0.1.8 - MAGIX AG) Free Audio CD Burner version 1.2 (HKLM\...\Free Audio CD Burner_is1) (Version: - DVDVideoSoft Limited.) Free YouTube Download version 3.0.16.923 (HKLM\...\Free YouTube Download_is1) (Version: - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.11.37.1212 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.37.1212 - DVDVideoSoft Ltd.) GMX MediaCenter 1.5.1765.0 (HKCU\...\GMX Application {sync-000021}) (Version: 1.5.1765.0 - 1&1 Mail & Media GmbH) Google Chrome (HKLM\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.) Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden H.264 Decoder (HKLM\...\{A96E97134CA649888820BCDE5E300BBD}) (Version: 1.0.0 - DivX, Inc.) ICQ7.4 (HKLM\...\{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37}) (Version: 7.4 - ICQ) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation) Intel(R) Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - ) InterVideo WinDVD 8 (HKLM\...\InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}) (Version: 8.0-B9.385 - InterVideo Inc.) InterVideo WinDVD 8 (Version: 8.0-B9.385 - InterVideo Inc.) Hidden IPTInstaller (HKLM\...\{6965F2F4-1CD2-4F42-A8EF-9EF433F9AA72}) (Version: 4.0.4 - HTC) Java(TM) 6 Update 5 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160050}) (Version: 1.6.0.50 - Sun Microsystems, Inc.) Kaspersky Anti-Virus (HKLM\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab) Kaspersky Anti-Virus (Version: 14.0.0.4651 - Kaspersky Lab) Hidden Launch Manager V1.4.9 (HKLM\...\{D0846526-66DD-4DC9-A02C-98F9A2806812}) (Version: 1.4.9 - Wistron Corp.) LG PC Suite II (HKLM\...\{14DCD95A-EBA3-4BF0-B7EF-533852E99BE6}) (Version: 2.00.0000 - LG PC Suite) LG PC Suite II (Version: 2.00.0000 - LG PC Suite) Hidden LG USB Modem driver (HKLM\...\{C3ABE126-2BB2-4246-BFE1-6797679B3579}) (Version: 4.9.4 - LG Electronics) MD86351 Driver Install (HKLM\...\InstallShield_{B3A9DC22-6162-4844-BEB3-853BAFB980E0}) (Version: 6.3.6.1 - Ihr Firmenname) MD86351 Driver Install (Version: 6.3.6.1 - Ihr Firmenname) Hidden MEDION Fotos auf CD Nord (HKLM\...\MEDION Fotos auf CD Nord D) (Version: 6.0.2.0 - MAGIX AG) Medion Media Center 0 (Version: 1.0.12.0 - Medion) Hidden MEDIONbox (HKLM\...\{27FDF949-69CE-435A-8372-339F72336AC5}) (Version: 1.09.0000.00052 - Medion) Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - ) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55- 48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55- 48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Picture It! Foto Premium 9 (HKLM\...\PictureIt_v9) (Version: 9.0.0.0000 - Microsoft Corporation) Microsoft Picture It! Foto Premium 9 (Version: 9.0.0.0000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Microsoft XML Parser (Version: 8.20.8730.4 - Microsoft Corporation) Hidden MindManager Smart (HKLM\...\MindManager Smart) (Version: 2.1.3 - Mindjet LLC) MKV Splitter (HKLM\...\{AAC389499AEF40428987B3D30CFC76C9}) (Version: 1.0.0 - DivX, Inc.) Move Networks Media Player for Internet Explorer (HKCU\...\Move Networks Player - IE) (Version: - ) Mozilla Firefox (3.0) (HKLM\...\Mozilla Firefox (3.0)) (Version: 3.0 (de) - Mozilla) MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nero 8 Essentials (HKLM\...\{47948554-90C6-4AAC-8CFA-D23CE11C1031}) (Version: 8.3.124 - Nero AG) neroxml (Version: 1.0.0 - Nero AG) Hidden OnlineFotoservice (HKLM\...\OnlineFotoservice) (Version: 5.1.5 - CEWE Stiftung u Co. KGaA) Opera 12.12 (HKLM\...\Opera 12.12.1707) (Version: 12.12.1707 - Opera Software ASA) PDF24 Creator 6.3.2 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 0.9.8 - Frank Heindörfer, Philip Chinery) Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.) Ralink Wireless LAN (HKLM\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.00.0000 - RaLink) Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista (HKLM\...\{8833FFB6-5B0C-4764-81AA- 06DFEED9A476}) (Version: 1.00.0000 - Realtek) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5595 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM\...\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version: - Realtek Semiconductor Corp.) Rossmann Fotoservice 2.6 (HKLM\...\Rossmann Fotoservice_is1) (Version: - ) Sceneo AbsolutTV (HKLM\...\{4C73B683-B15D-4B94-AC7A-520B70C4FFE9}) (Version: - ) Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Switch Sound File Converter (HKLM\...\Switch) (Version: - NCH Software) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.0.14.0 - Synaptics) TV IR (HKLM\...\InstallShield_{8CFE319F-DC08-48BA-B011-37ED5C9733B5}) (Version: 1.00.0000 - Ihr Firmenname) TV IR (Version: 1.00.0000 - Ihr Firmenname) Hidden Ulead DVD MovieFactory 5 (HKLM\...\{FF164702-AF8B-4F2F-8038-74A4C536866B}) (Version: 5.3 - Ulead Systems, Inc.) Ulead PhotoImpact 12 (HKLM\...\{11AFE21E-B193-430D-B57A-DFF7815BB962}) (Version: 12.0 - Ulead System) Uninstall 1.0.0.1 (HKLM\...\Uninstall_is1) (Version: - ) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D- 5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_ {C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM\...\{90120000-006E-0409-0000-0000000FF1CE} _ENTERPRISE_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE} _ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE} _HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE} _ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE} _HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE} _ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE} _HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office Access 2007 Help (KB963663) (HKLM\...\{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_ {6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}) (Version: - Microsoft) Update for Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_ {199DF7B6-169C-448C-B511-1054101BE9C9}) (Version: - Microsoft) Update for Microsoft Office Infopath 2007 Help (KB963662) (HKLM\...\{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_ {716B81B8-B13C-41DF-8EAC-7A2F656CAB63}) (Version: - Microsoft) Update for Microsoft Office OneNote 2007 Help (KB963670) (HKLM\...\{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_ {2744EF05-38E1-4D5D-B333-E021EDAEA245}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE} _ENTERPRISE_{ED38F8A3-4F61-494E-8BCA-E3AC7760C924}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE} _ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_ {0451F231-E3E3-4943-AB9F-58EB96171784}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2881065) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000- 0000000FF1CE}_ENTERPRISE_{B7EF38F7-1D58-4085-A9A4-0F6C69A5AA1E}) (Version: - Microsoft) Update for Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_ {397B1D4F-ED7B-4ACA-A637-43B670843876}) (Version: - Microsoft) Update for Microsoft Office Publisher 2007 Help (KB963667) (HKLM\...\{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_ {2E40DE55-B289-4C8B-8901-5D369B16814F}) (Version: - Microsoft) Update for Microsoft Office Script Editor Help (KB963671) (HKLM\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_ {CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version: - Microsoft) Update for Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_ {80E762AA-C921-4839-9D7D-DB62A72C0726}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_ {BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE} _HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_ {38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) USB Video Device (HKLM\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.18100.101 - Sonix) VC80CRTRedist - 8.0.50727.762 (Version: 1.0.0 - DivX, Inc) Hidden VCRedistSetup (Version: 1.0.0 - Nero AG) Hidden Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player 1.1.10 (HKLM\...\VLC media player) (Version: 1.1.10 - VideoLAN) WavePad Sound Editor (HKLM\...\WavePad) (Version: - NCH Software) Windows Live Messenger (HKLM\...\{279DB581-239C-4E13-97F8-0F48E40BE75C}) (Version: 8.1.0178.00 - Microsoft Corporation) WinRAR (HKLM\...\WinRAR archiver) (Version: - ) WISO Mein Geld 2008 Professional (HKLM\...\{D8D22773-14BF-4178-A683-3DBA515C2A26}) (Version: 9.00.01.0023 - Buhl Data Service GmbH) XVID Codec Installation (HKLM\...\{534C6D59-D6E3-48A6-AD0B-747799019960}) (Version: - ) ==================== Restore Points ========================= 04-06-2014 17:38:03 Geplanter Prüfpunkt 07-06-2014 18:44:11 Windows Update 08-06-2014 10:42:59 Gerätetreiber-Paketinstallation: HTC, Corporation 08-06-2014 10:46:45 Gerätetreiber-Paketinstallation: HTC Corporation Netzwerkadapter 08-06-2014 10:49:34 Gerätetreiber-Paketinstallation: HTC Corporation Tragbare Geräte 08-06-2014 10:54:49 Gerätetreiber-Paketinstallation: HTC Netzwerkprotokoll 11-06-2014 17:26:28 Windows Update 11-06-2014 18:00:59 Windows Update 13-06-2014 20:48:59 Installed AVG 2014 13-06-2014 20:50:05 Installed AVG 2014 14-06-2014 11:59:34 Gerätetreiber-Paketinstallation: Kaspersky Lab Netzwerkdienst 17-06-2014 17:36:53 Removed AVG 2014 17-06-2014 17:41:24 Removed AVG 2014 ==================== Hosts content: ========================== 2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0D4A3951-D115-4E17-9495-26DC510E1359} - System32\Tasks\{19864B7B-6EBE-4684-9FF9-DD775F771854} => C:\Program Files\Skype\\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32 \RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {574969E9-0C4A-4A75-A6C7-549B08CDB6C6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-06-05] (Google Inc.) Task: {8AC7F5E7-9061-45A6-95FE-B269516DA561} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-06-05] (Google Inc.) Task: {B7794283-DDB2-48C6-9B9B-3AC33999A0C1} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {EEEAB8B8-067F-4F56-8432-3BBC88C3CC8F} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32 \netsh.exe [2006-11-02] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2009-09-04 19:29 - 2001-10-28 17:42 - 00116224 _____ () C:\Windows\System32\pdfcmnnt.dll 2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0 \kpcengine.2.3.dll 2009-10-03 11:47 - 2005-06-28 13:59 - 00053248 _____ () C:\Program Files\ArcSoft\PhotoImpression 5\Share\PIHook.dll 2013-07-21 20:03 - 2013-07-21 20:03 - 03391488 _____ () c:\windows\assembly\nativeimages1_v1.1.4322 \mscorlib\1.0.5000.0__b77a5c561934e089_b0c6b048\mscorlib.dll 2013-07-21 20:02 - 2013-07-21 20:02 - 01966080 _____ () c:\windows\assembly\nativeimages1_v1.1.4322 \system\1.0.5000.0__b77a5c561934e089_c7c004ef\system.dll 2013-07-21 20:02 - 2013-07-21 20:02 - 03035136 _____ () c:\windows\assembly\nativeimages1_v1.1.4322 \system.windows.forms\1.0.5000.0__b77a5c561934e089_5c188a8d\system.windows.forms.dll 2013-07-21 20:02 - 2013-07-21 20:02 - 02088960 _____ () c:\windows\assembly\nativeimages1_v1.1.4322 \system.xml\1.0.5000.0__b77a5c561934e089_821dd40b\system.xml.dll 2008-04-21 09:37 - 2007-09-01 14:03 - 00032768 _____ () C:\Program Files\Launch Manager\LaunchAp.exe 2007-10-30 19:52 - 2007-10-30 19:52 - 00016200 _____ () C:\Program Files\Corel\Corel Paint Shop Pro Photo X2 \CorelIOMonitor.exe 2011-01-08 16:14 - 2007-02-12 15:50 - 00020480 _____ () C:\Windows\FixCamera.exe 2011-01-08 16:14 - 2007-12-04 19:28 - 00249856 _____ () C:\Windows\tsnp2uvc.exe 2008-04-22 08:37 - 2007-04-19 12:11 - 00006656 _____ () c:\program files\medion\medionbox\program\structconverter.dll 2009-08-18 20:24 - 2009-04-11 08:28 - 00368640 _____ () C:\Windows\system32\msjetoledb40.dll 2011-08-06 14:59 - 2010-09-30 14:00 - 00139088 _____ () C:\Program Files\1&1 Surf-Stick\UIExec.exe 2010-12-22 11:27 - 2010-12-22 11:27 - 00692318 _____ () C:\Program Files\TV IR\TV IR.exe 2010-06-18 00:09 - 2010-06-18 00:09 - 00167936 _____ () C:\Program Files\TV IR\RmCard.dll 2008-01-15 00:40 - 2008-01-15 00:40 - 00053248 _____ () C:\Program Files\TV IR\LWExt.dll 2009-03-09 11:52 - 2009-03-09 11:52 - 00053248 _____ () C:\Program Files\TV IR\tmir.dll 2012-10-08 17:04 - 2012-10-08 17:04 - 00166912 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe 2014-06-17 18:10 - 2014-05-14 14:27 - 00049744 _____ () C:\Users\Claudia\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll 2012-10-21 13:31 - 2007-04-19 09:33 - 00035584 _____ () C:\Program Files\ArcSoft\TotalMedia 3.5\uPiApi.dll 2014-06-17 22:47 - 2014-06-17 22:47 - 00043008 _____ () C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153- 5bce-5766-8f84-3e3e7ecf0d81}.tmp0paq4m.dll 2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Claudia\AppData\Roaming\Dropbox\bin\libcef.dll 2007-06-05 13:20 - 2007-06-05 13:20 - 00177704 _____ () C:\Windows\system32\PSIService.exe 2008-04-22 08:30 - 2007-05-16 22:48 - 00421955 _____ () C:\Program Files\Sceneo\AbsolutTV\Services\PVR\tvtvRemote.dll 2011-08-06 14:59 - 2010-09-30 14:00 - 00253264 _____ () C:\Program Files\1&1 Surf-Stick\AssistantServices.exe 2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0 \dblite.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Claudia\Beweis.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Beweis.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Beweis.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Desktop\Funde Kaspersky.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Desktop\Funde Kaspersky.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Desktop\Funde Kaspersky.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\ebay lederjacke.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\ebay lederjacke.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\ebay lederjacke.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\Muster Inspektion VW.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Muster Inspektion VW.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Muster Inspektion VW.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\pikante spaghetti.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\pikante spaghetti.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\pikante spaghetti.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:SummaryInformation AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:Updt_SummaryInformation AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:SummaryInformation AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:Updt_SummaryInformation AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/17/2014 10:45:49 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (06/17/2014 10:46:42 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: 30000Avira Service Host Error: (06/17/2014 10:46:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Windows Search%%1053 Error: (06/17/2014 10:46:12 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: 30000Windows Search Error: (06/17/2014 10:45:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Microsoft Office Sessions: ========================= Error: (05/07/2013 08:37:08 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 810 seconds with 720 seconds of active time. This session ended with a crash. Error: (05/13/2011 02:44:54 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1089 seconds with 120 seconds of active time. This session ended with a crash. Error: (03/20/2011 05:35:34 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4422 seconds with 900 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-06-17 22:52:26.481 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-17 22:52:25.545 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-17 22:52:24.562 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-17 22:52:23.470 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-17 22:51:46.326 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-17 22:51:45.515 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-17 22:51:44.719 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-17 22:51:43.783 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-17 20:07:15.026 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kneps.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-17 20:07:14.309 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kneps.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 48% Total physical RAM: 3061.69 MB Available physical RAM: 1563.23 MB Total Pagefile: 6339.64 MB Available Pagefile: 4521.53 MB Total Virtual: 2047.88 MB Available Virtual: 1907.03 MB ==================== Drives ================================ Drive c: (BOOT) (Fixed) (Total:207.5 GB) (Free:100.29 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (RECOVER) (Fixed) (Total:25.37 GB) (Free:5.96 GB) FAT32 Drive g: () (Removable) (Total:1.84 GB) (Free:0 GB) FAT ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: 4B64DFC2) Partition 1: (Active) - (Size=207 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=25 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 2 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ |
17.06.2014, 22:09 | #10 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Avira durch Gruppenrichtlinie geblockt - Trojaner?Zitat:
Wieso knallst du dir das System mit Virenscanner zu, damit erreichst du nur das Gegenteil! Alle runter, bis auf einen!Am besten AntiVir deinstallieren.
__________________ Logfiles bitte immer in CODE-Tags posten |
18.06.2014, 17:46 | #11 |
| Avira durch Gruppenrichtlinie geblockt - Trojaner? AntiVir (Avira) ist jetzt deinstalliert. Habe jetzt nur noch Kaspersky drauf. Sorry. Als sich letzte Woche AntiVir weder starten noch deinstallieren ließ, habe ich gehofft, dass irgendein anderer Virenscanner den Virus erkennt und vernichtet... Eigentlich weiß ich auch, dass man nicht mehr als einen Virenscanner haben sollte... für mich zählte in dem Moment nur, den Virus irgendwie zu erkennen und zu löschen... Was soll ich als nächstes machen? |
18.06.2014, 19:50 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Avira durch Gruppenrichtlinie geblockt - Trojaner? Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Scan klicken
__________________ Logfiles bitte immer in CODE-Tags posten |
18.06.2014, 21:57 | #13 |
| Avira durch Gruppenrichtlinie geblockt - Trojaner?FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:18-06-2014 Ran by Claudia (administrator) on CLAUDIA1 on 18-06-2014 22:26:03 Running from C:\Users\Claudia\Desktop Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Google Inc.) C:\Program Files\Google\Update\1.3.24.15\GoogleCrashHandler.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (ABBYY) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe (Empolis GmbH) C:\Program Files\Common Files\Gnab\Service\ServiceController.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Empolis GmbH) C:\Program Files\Medion\MEDIONbox\Program\GCS.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe () C:\Windows\System32\PSIService.exe (Buhl Data Service GmbH) C:\Program Files\Sceneo\AbsolutTV\Services\PVR\pvrservice.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe () C:\Program Files\1&1 Surf-Stick\AssistantServices.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPStart.exe () C:\Program Files\Launch Manager\LaunchAp.exe (Wistron) C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron Corp.) C:\Program Files\Launch Manager\OSD.exe (Wistron) C:\Program Files\Launch Manager\WButton.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Wistron Corp.) C:\Program Files\Launch Manager\WisLMSvc.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe () C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe (SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe (Sonix) C:\Windows\vsnp2uvc.exe () C:\Windows\FixCamera.exe () C:\Windows\tsnp2uvc.exe () C:\Program Files\1&1 Surf-Stick\UIExec.exe () C:\Program Files\TV IR\TV IR.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Google Inc.) C:\Program Files\Picasa2\PicasaMediaDetector.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGCE.EXE (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGCE.EXE (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (1&1 Mail & Media GmbH) C:\Users\Claudia\AppData\Local\GMX Application {sync-000021}\gmx_mediacenter.exe (Microsoft Corporation) C:\Windows\System32\p2phost.exe (ArcSoft, Inc.) C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Dropbox, Inc.) C:\Users\Claudia\AppData\Roaming\Dropbox\bin\Dropbox.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [178712 2007-10-03] (Intel Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6025216 2008-04-01] (Realtek Semiconductor) HKLM\...\Run: [SynTPStart] => C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2007-08-31] (Synaptics, Inc.) HKLM\...\Run: [LaunchAp] => C:\Program Files\Launch Manager\LaunchAp.exe [32768 2007-09-01] () HKLM\...\Run: [HotkeyApp] => C:\Program Files\Launch Manager\HotkeyApp.exe [188416 2007-09-06] (Wistron) HKLM\...\Run: [CtrlVol] => "C:\Program Files\Launch Manager\CtrlVol.exe" HKLM\...\Run: [LMgrOSD] => C:\Program Files\Launch Manager\OSD.exe [180224 2006-12-26] (Wistron Corp.) HKLM\...\Run: [Wbutton] => C:\Program Files\Launch Manager\Wbutton.exe [86016 2007-09-07] (Wistron) HKLM\...\Run: [toolbar_eula_launcher] => C:\Program Files\GoogleEULA\EULALauncher.exe [16896 2007-02-09] ( ) HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [Corel Photo Downloader] => "C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel PhotoDownloader.exe" -startup HKLM\...\Run: [Corel File Shell Monitor] => C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe [16200 2007-10-30] () HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.) HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [976320 2009-12-03] (SEIKO EPSON CORPORATION) HKLM\...\Run: [snp2uvc] => C:\Windows\vsnp2uvc.exe [581632 2007-11-30] (Sonix) HKLM\...\Run: [FixCamera] => C:\Windows\FixCamera.exe [20480 2007-02-12] () HKLM\...\Run: [tsnp2uvc] => C:\Windows\tsnp2uvc.exe [249856 2007-12-04] () HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40368 2011-05-27] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-03-29] (Adobe Systems Incorporated) HKLM\...\Run: [UIExec] => C:\Program Files\1&1 Surf-Stick\UIExec.exe [139088 2010-09-30] () HKLM\...\Run: [TV IR] => C:\Program Files\TV IR\TV IR.exe [692318 2010-12-22] () HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [1828136 2008-02-28] (Nero AG) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Picasa Media Detector] => C:\Program Files\Picasa2 \PicasaMediaDetector.exe [443968 2008-02-26] (Google Inc.) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [EPSON SX420W Series] => C:\Windows\system32 \spool\DRIVERS\W32X86\3\E_FATIGCE.EXE [200704 2009-09-14] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Epson Stylus SX420W(Netzwerk)] => C:\Windows\system32 \spool\DRIVERS\W32X86\3\E_FATIGCE.EXE [200704 2009-09-14] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01- 21] (Microsoft Corporation) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Device Detection] => C:\Program Files\Lidl_Fotos\dd.exe HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [GMX Application {sync-000021}] => C:\Users\Claudia Grützmacher\AppData\Local\GMX Application {sync-000021}\gmx_mediacenter.exe [878080 2013-08-09] (1&1 Mail & Media GmbH) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [CollaborationHost] => C:\Windows\system32\p2phost.exe [192000 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\RunOnce: [Shockwave Updater] - C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1100429.exe [439736 2008-03-19] (Adobe Systems, Inc.) HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\MountPoints2: {680ae5c9-5a41-11de-81b4-0015afb8023d} - G:\BlueJ.bat HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\MountPoints2: {b7bf007e-eef6-11e3-92c0-000ae4cddb4b} - F:\HTC_Sync_Manager_PC.exe AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL File Not Found Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk ShortcutTarget: TMMonitor.lnk -> C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.) Startup: C:\Users\Claudia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Claudia\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} URLSearchHook: HKLM - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File URLSearchHook: HKCU - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {01_TL-YODL-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_google&q= {searchTerms} SearchScopes: HKCU - {03_TL-TELEFONBUCH-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF- splug_telefonbuch&q={searchTerms} SearchScopes: HKCU - {04_TL-AMAZON-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_amazon&q= {searchTerms} SearchScopes: HKCU - {05_TL-EBAY-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_ebay&q={searchTerms} SearchScopes: HKCU - {06_TL-DISCOUNT24-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_discount24&q= {searchTerms} SearchScopes: HKCU - {07_TL-CONRAD-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_conrad&q= {searchTerms} SearchScopes: HKCU - {08_TL-OTTO-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_otto&q={searchTerms} SearchScopes: HKCU - {09_TL-CLIPFISH-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_clipfish&q= {searchTerms} SearchScopes: HKCU - {10_TL-MYVIDEO-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_myvideo&q= {searchTerms} SearchScopes: HKCU - {11_TL-MUSICLOAD-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_musicload&q= {searchTerms} SearchScopes: HKCU - {DBAFD4EB-E4E1-4A25-97C2-D1CB5F7D0368} URL = hxxp://de.search.yahoo.com/search?fr=chr- greentree_ie&ei=utf-8&type=971163&p={searchTerms} BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12 \GrooveShellExtensions.dll (Microsoft Corporation) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Anti- Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.) BHO: No Name - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO: DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File Toolbar: HKLM - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - DVDVideoSoftTB Toolbar - {E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} hxxp://photoservice.fujicolor.de/ips-opdata/objects/jordan.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12 \GrooveSystemServices.dll (Microsoft Corporation) Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 83.169.185.161 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default FF DefaultSearchEngine: ICQ Search FF SearchEngineOrder.1: Ask FF SelectedSearchEngine: ICQ Search FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdivx32.dll (DivX,Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\clipfish.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\conrad.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\discount24.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\ebay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\musicload.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\myvideo.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\otto.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\quelle.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\telefonbuch-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\webnews.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Microsoft .NET Framework Assistant - C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{20a82645-c095-46ed-80e3- 08825760534b} [2009-08-13] FF Extension: Firefox Companion for eBay - C:\Program Files\Mozilla Firefox\extensions\{62760FD6-B943-48C9-AB09- F99C6FE96088} [2008-11-14] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKLM\...\Firefox\Extensions: - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0 \FFExt\url_advisor@kaspersky.com FF Extension: 卡巴斯基網址顧問 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-14] FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: 虛擬鍵盤 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-14] FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: 惡意網站攔截器 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-14] FF HKCU\...\Thunderbird\Extensions: [{0E810812-F4BB-4309-942A-755587587A5E}] - C:\Program Files\BullGuard Software\BullGuard\antispam\tbspamfilter Chrome: ======= CHR HomePage: CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll () CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (DivX Web Player) - C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll (DivX,Inc.) CHR Plugin: (DivX Player Netscape Plugin) - C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc) CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Plugin: (Picasa) - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (No Name) - C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2014-06-14] CHR Extension: (Google Wallet) - C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-14] CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] ========================== Services (Whitelisted) ================= R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00 \Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY) R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files\ALDI Foto Service Nord\Common\Database\bin\fbserver.exe [1527900 2005-11 -17] (MAGIX®) [File not signed] R2 GnabService; c:\program files\common files\gnab\service\servicecontroller.exe [36864 2007-04-19] (Empolis GmbH) [File not signed] S2 gupdate1c9e6034feeea56; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-06-05] (Google Inc.) R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] () [File not signed] R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1801216 2008-02-28] (Buhl Data Service GmbH) [File not signed] R2 UI Assistant Service; C:\Program Files\1&1 Surf-Stick\AssistantServices.exe [253264 2010-09-30] () R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [61440 2006-06-14] (Ulead Systems, Inc.) [File not signed] S3 usnjsvc; C:\Program Files\MSN Messenger\usnsvc.exe [97136 2007-01-19] (Microsoft Corporation) R3 WisLMSvc; C:\Program Files\Launch Manager\WisLMSvc.exe [118784 2007-09-11] (Wistron Corp.) [File not signed] ==================== Drivers (Whitelisted) ==================== R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) [File not signed] S3 DVC; C:\Windows\System32\Drivers\DVC.sys [38401 2001-09-09] (Samsung Electronics) [File not signed] R1 Hotkey; C:\Windows\system32\Drivers\Hotkey.sys [9867 2003-04-28] () [File not signed] R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-06-14] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576608 2014-06-14] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-06-14] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2014-06-14] (Kaspersky Lab ZAO) R0 Si3531; C:\Windows\System32\DRIVERS\Si3531.sys [212008 2008-07-25] (Silicon Image, Inc) R0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [17064 2008-07-25] (Silicon Image, Inc.) R0 SiRemFil; C:\Windows\System32\DRIVERS\SiRemFil.sys [12200 2008-07-25] (Silicon Image, Inc.) S3 smsbda; C:\Windows\System32\drivers\smsbda.sys [45440 2011-03-06] (Siano) S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [9610880 2007-11-29] () S3 IpInIp; system32\DRIVERS\ipinip.sys [X] U5 klflt; C:\Windows\System32\Drivers\klflt.sys [94304 2014-06-14] (Kaspersky Lab ZAO) S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-17 20:03 - 2014-06-17 20:03 - 00001033 _____ () C:\Users\Claudia\Desktop\JRT.txt 2014-06-17 19:57 - 2014-06-17 19:57 - 01016261 _____ (Thisisu) C:\Users\Claudia\Desktop\JRT.exe 2014-06-17 19:57 - 2014-06-17 19:57 - 00000000 ____D () C:\Windows\ERUNT 2014-06-17 18:23 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll 2014-06-17 18:22 - 2014-06-17 19:06 - 00000000 ____D () C:\AdwCleaner 2014-06-17 18:20 - 2014-06-17 18:20 - 01333465 _____ () C:\Users\Claudia\Desktop\adwcleaner_3.212.exe 2014-06-16 23:37 - 2014-06-18 22:25 - 00000000 ____D () C:\Users\Claudia\Desktop\FRST-OlderVersion 2014-06-16 21:59 - 2014-06-16 21:59 - 00002812 _____ () C:\Users\Claudia\Desktop\Fixlist.txt 2014-06-15 10:35 - 2014-06-15 10:35 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Claudia\Desktop\mbam-setup- 2.0.2.1012.exe 2014-06-15 03:23 - 2014-06-15 03:23 - 00055613 _____ () C:\Users\Claudia\Desktop\FRST ohne Nachname.txt 2014-06-15 03:23 - 2014-06-15 03:23 - 00043788 _____ () C:\Users\Claudia\Desktop\Addition ohne Nachname.txt 2014-06-15 02:15 - 2014-06-17 22:55 - 00039907 _____ () C:\Users\Claudia\Desktop\Addition.txt 2014-06-15 02:11 - 2014-06-18 22:26 - 00027693 _____ () C:\Users\Claudia\Desktop\FRST.txt 2014-06-15 02:05 - 2014-06-18 22:26 - 00000000 ____D () C:\FRST 2014-06-15 02:03 - 2014-06-18 22:25 - 01072128 _____ (Farbar) C:\Users\Claudia\Desktop\FRST.exe 2014-06-14 22:13 - 2014-06-14 22:13 - 00227096 _____ () C:\Users\Claudia\Desktop\avira_registry_cleaner_de.exe 2014-06-14 14:46 - 2014-06-14 14:46 - 00262144 _____ () C:\Windows\system32\config\elam 2014-06-14 14:04 - 2014-06-14 14:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus 2014-06-14 14:04 - 2014-06-14 14:02 - 00000970 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2014-06-14 13:57 - 2014-06-18 22:20 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-06-14 13:57 - 2014-06-14 14:31 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-06-14 13:57 - 2014-06-14 14:31 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-06-14 13:57 - 2014-06-14 13:57 - 00000000 ____D () C:\Program Files\Kaspersky Lab 2014-06-14 01:15 - 2014-06-14 01:15 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\PeerNetworking 2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\TuneUp Software 2014-06-13 22:47 - 2014-06-17 19:45 - 00000000 ____D () C:\ProgramData\MFAData 2014-06-13 22:47 - 2014-06-13 22:47 - 00000000 ____D () C:\Users\Claudia\AppData\Local\MFAData 2014-06-13 22:42 - 2014-06-13 22:45 - 164819976 _____ (AVG Technologies) C:\Users\Claudia\Desktop\avg_free_x64_all_2014_4592a7484.exe 2014-06-13 21:56 - 2014-06-13 22:41 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Nico Mak Computing 2014-06-11 19:28 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-11 19:27 - 2014-05-28 18:48 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-11 19:27 - 2014-05-28 18:39 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-11 19:27 - 2014-05-28 18:38 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-11 19:27 - 2014-05-28 18:33 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-11 19:27 - 2014-05-28 18:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-11 19:27 - 2014-05-28 18:32 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-11 19:27 - 2014-05-28 18:31 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-06-11 19:27 - 2014-05-28 18:31 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-11 19:27 - 2014-05-28 18:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-11 19:27 - 2014-05-28 18:30 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-06-11 19:27 - 2014-05-28 18:29 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-11 19:27 - 2014-05-28 18:29 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-11 19:27 - 2014-05-28 18:29 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-11 19:27 - 2014-05-28 18:29 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-06-11 19:27 - 2014-05-28 18:29 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-06-11 19:27 - 2014-05-28 18:28 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-11 19:27 - 2014-04-05 04:42 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-11 19:27 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-11 19:27 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-08 13:24 - 2014-06-08 13:24 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf 2014-06-08 12:54 - 2014-06-08 12:54 - 00000000 ____D () C:\Program Files\HTC 2014-06-08 12:45 - 2014-06-08 12:45 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Downloaded Installations 2014-06-08 12:42 - 2014-06-08 12:56 - 00000000 ____D () C:\Temp 2014-06-08 12:42 - 2014-06-08 12:42 - 00000000 ____D () C:\ProgramData\HTC 2014-06-08 12:42 - 2009-06-10 09:49 - 00024576 _____ (HTC, Corporation) C:\Windows\system32\Drivers\ANDROIDUSB.sys 2014-06-08 12:42 - 2009-06-09 07:41 - 01122664 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll 2014-06-07 20:30 - 2014-06-16 22:17 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Adobe 2014-06-07 19:59 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet (1).RequestDispatcherServlet 2014-06-07 19:56 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet.RequestDispatcherServlet ==================== One Month Modified Files and Folders ======= 2014-06-18 22:26 - 2014-06-15 02:11 - 00027693 _____ () C:\Users\Claudia\Desktop\FRST.txt 2014-06-18 22:26 - 2014-06-15 02:05 - 00000000 ____D () C:\FRST 2014-06-18 22:25 - 2014-06-16 23:37 - 00000000 ____D () C:\Users\Claudia\Desktop\FRST-OlderVersion 2014-06-18 22:25 - 2014-06-15 02:03 - 01072128 _____ (Farbar) C:\Users\Claudia\Desktop\FRST.exe 2014-06-18 22:24 - 2008-08-07 13:55 - 01607600 _____ () C:\Windows\WindowsUpdate.log 2014-06-18 22:23 - 2012-09-08 16:32 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Dropbox 2014-06-18 22:22 - 2014-05-13 22:19 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\DropboxMaster 2014-06-18 22:22 - 2012-09-08 16:36 - 00000000 ___RD () C:\Users\Claudia\Dropbox 2014-06-18 22:20 - 2014-06-14 13:57 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-06-18 22:19 - 2009-06-30 19:24 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-18 22:19 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-18 22:19 - 2006-11-02 14:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P- 1.C7483456-A289-439d-8115-601632D005A0 2014-06-18 22:19 - 2006-11-02 14:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P- 0.C7483456-A289-439d-8115-601632D005A0 2014-06-18 18:49 - 2006-11-02 15:01 - 00032534 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-06-18 18:22 - 2008-01-21 04:47 - 00527116 _____ () C:\Windows\PFRO.log 2014-06-18 18:17 - 2009-06-30 19:24 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-17 22:55 - 2014-06-15 02:15 - 00039907 _____ () C:\Users\Claudia\Desktop\Addition.txt 2014-06-17 20:03 - 2014-06-17 20:03 - 00001033 _____ () C:\Users\Claudia\Desktop\JRT.txt 2014-06-17 19:57 - 2014-06-17 19:57 - 01016261 _____ (Thisisu) C:\Users\Claudia\Desktop\JRT.exe 2014-06-17 19:57 - 2014-06-17 19:57 - 00000000 ____D () C:\Windows\ERUNT 2014-06-17 19:45 - 2014-06-13 22:47 - 00000000 ____D () C:\ProgramData\MFAData 2014-06-17 19:06 - 2014-06-17 18:22 - 00000000 ____D () C:\AdwCleaner 2014-06-17 19:06 - 2008-11-14 21:23 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-06-17 18:24 - 2012-12-31 17:41 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft 2014-06-17 18:24 - 2008-08-07 14:18 - 00000000 ____D () C:\ProgramData\ICQ 2014-06-17 18:20 - 2014-06-17 18:20 - 01333465 _____ () C:\Users\Claudia\Desktop\adwcleaner_3.212.exe 2014-06-17 18:18 - 2009-08-24 13:59 - 00000000 ____D () C:\Users\Claudia\Documents\Bewerbung 2014-06-17 18:15 - 2008-11-30 15:45 - 00002627 _____ () C:\Users\Claudia\Desktop\Microsoft Office Word 2007.lnk 2014-06-16 22:17 - 2014-06-07 20:30 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Adobe 2014-06-16 22:06 - 2008-01-21 09:16 - 01643446 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-16 22:02 - 2006-11-02 14:52 - 00162998 _____ () C:\Windows\setupact.log 2014-06-16 21:59 - 2014-06-16 21:59 - 00002812 _____ () C:\Users\Claudia\Desktop\Fixlist.txt 2014-06-15 10:35 - 2014-06-15 10:35 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Claudia Grützmacher\Desktop\mbam-setup-2.0.2.1012.exe 2014-06-15 03:23 - 2014-06-15 03:23 - 00055613 _____ () C:\Users\Claudia\Desktop\FRST ohne Nachname.txt 2014-06-15 03:23 - 2014-06-15 03:23 - 00043788 _____ () C:\Users\Claudia\Desktop\Addition ohne Nachname.txt 2014-06-14 22:13 - 2014-06-14 22:13 - 00227096 _____ () C:\Users\Claudia\Desktop\avira_registry_cleaner_de.exe 2014-06-14 19:19 - 2012-11-17 22:37 - 00001967 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-06-14 14:46 - 2014-06-14 14:46 - 00262144 _____ () C:\Windows\system32\config\elam 2014-06-14 14:31 - 2014-06-14 13:57 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-06-14 14:31 - 2014-06-14 13:57 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-06-14 14:31 - 2013-10-17 15:47 - 00135776 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2014-06-14 14:31 - 2013-10-17 15:47 - 00025184 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys 2014-06-14 14:31 - 2013-06-06 17:38 - 00144992 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys 2014-06-14 14:04 - 2014-06-14 14:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus 2014-06-14 14:02 - 2014-06-14 14:04 - 00000970 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2014-06-14 14:01 - 2008-08-07 14:00 - 00000000 ____D () C:\Users\Claudia 2014-06-14 13:57 - 2014-06-14 13:57 - 00000000 ____D () C:\Program Files\Kaspersky Lab 2014-06-14 01:26 - 2014-05-18 00:02 - 00000000 ____D () C:\ProgramData\tmp 2014-06-14 01:15 - 2014-06-14 01:15 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\PeerNetworking 2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\TuneUp Software 2014-06-13 22:47 - 2014-06-13 22:47 - 00000000 ____D () C:\Users\Claudia\AppData\Local\MFAData 2014-06-13 22:45 - 2014-06-13 22:42 - 164819976 _____ (AVG Technologies) C:\Users\Claudia\Desktop\avg_free_x64_all_2014_4592a7484.exe 2014-06-13 22:41 - 2014-06-13 21:56 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Nico Mak Computing 2014-06-11 20:10 - 2008-04-21 14:41 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-06-11 20:05 - 2013-08-06 20:05 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-11 20:05 - 2006-11-02 12:24 - 92708840 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-06-09 01:59 - 2008-08-07 18:11 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Corel 2014-06-09 00:54 - 2008-08-07 19:39 - 00000000 ____D () C:\Users\Claudia\Documents\My PSP Files 2014-06-09 00:54 - 2008-08-07 18:12 - 00004182 ___SH () C:\Windows\system32\KGyGaAvL.sys 2014-06-08 13:24 - 2014-06-08 13:24 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf 2014-06-08 12:56 - 2014-06-08 12:42 - 00000000 ____D () C:\Temp 2014-06-08 12:54 - 2014-06-08 12:54 - 00000000 ____D () C:\Program Files\HTC 2014-06-08 12:54 - 2008-04-21 09:32 - 00025966 _____ () C:\Windows\DPINST.LOG 2014-06-08 12:45 - 2014-06-08 12:45 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Downloaded Installations 2014-06-08 12:42 - 2014-06-08 12:42 - 00000000 ____D () C:\ProgramData\HTC 2014-06-07 20:25 - 2012-07-08 20:11 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-06-07 20:25 - 2011-07-13 22:41 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32 \FlashPlayerCPLApp.cpl 2014-06-07 19:59 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet (1).RequestDispatcherServlet 2014-06-07 19:59 - 2014-06-07 19:56 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet.RequestDispatcherServlet 2014-06-07 19:57 - 2008-04-21 10:34 - 00000000 ____D () C:\ProgramData\Adobe 2014-05-28 18:48 - 2014-06-11 19:27 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-28 18:39 - 2014-06-11 19:27 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-05-28 18:38 - 2014-06-11 19:27 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-05-28 18:33 - 2014-06-11 19:27 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-05-28 18:32 - 2014-06-11 19:27 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-05-28 18:32 - 2014-06-11 19:27 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-05-28 18:31 - 2014-06-11 19:27 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-05-28 18:31 - 2014-06-11 19:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-05-28 18:30 - 2014-06-11 19:27 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-05-28 18:30 - 2014-06-11 19:27 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-05-28 18:29 - 2014-06-11 19:27 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-28 18:29 - 2014-06-11 19:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-05-28 18:29 - 2014-06-11 19:27 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-28 18:29 - 2014-06-11 19:27 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-05-28 18:29 - 2014-06-11 19:27 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-05-28 18:28 - 2014-06-11 19:27 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-05-24 12:35 - 2012-09-08 16:36 - 00000965 _____ () C:\Users\Claudia\Desktop\Dropbox.lnk 2014-05-24 12:35 - 2012-09-08 16:33 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox Files to move or delete: ==================== C:\Users\Claudia\AppData\Roaming\desktop.ini Some content of TEMP: ==================== C:\Users\Claudia\AppData\Local\Temp\avgnt.exe C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp_32ceb.dll C:\Users\Claudia\AppData\Local\Temp\ffunzip.exe C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate.exe C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate01.exe C:\Users\Claudia\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe C:\Users\Claudia\AppData\Local\Temp\GDM272F.exe C:\Users\Claudia\AppData\Local\Temp\GDM34A6.exe C:\Users\Claudia\AppData\Local\Temp\GLF3BB0.tmp.ConduitEngineSetup.exe C:\Users\Claudia\AppData\Local\Temp\GoogleChromeInstaller.exe C:\Users\Claudia\AppData\Local\Temp\IcqUpdater.exe C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssa_aih[1].exe C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssd_aih[1].exe C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10_mssd_aih.exe C:\Users\Claudia\AppData\Local\Temp\JiveXViewerStart1363355292.exe C:\Users\Claudia\AppData\Local\Temp\Opera_1150_int_Setup.exe C:\Users\Claudia\AppData\Local\Temp\prxGLF3BB0.tmp.tbDVDV.dll C:\Users\Claudia\AppData\Local\Temp\Quarantine.exe C:\Users\Claudia\AppData\Local\Temp\SearchWithGoogleUpdate.exe C:\Users\Claudia\AppData\Local\Temp\tbDVDV.dll C:\Users\Claudia\AppData\Local\Temp\unwise.exe C:\Users\Claudia\AppData\Local\Temp\VisusClient.dll C:\Users\Claudia\AppData\Local\Temp\wpsetup.exe C:\Users\Claudia\AppData\Local\Temp\_is30.exe C:\Users\Claudia\AppData\Local\Temp\_is6CF6.exe C:\Users\Claudia\AppData\Local\Temp\_is92AD.exe C:\Users\Claudia\AppData\Local\Temp\{1167C4F7-64B6-4A1D-A0A5-B605C6CDE10F}-26.0.1410.64_25.0.1364.172_chrome_updater.exe C:\Users\Claudia\AppData\Local\Temp\{5A7A4717-CEF4-4E4A-B23E-0838114D47F8}-chrome_installer.exe C:\Users\Claudia\AppData\Local\Temp\{C2722232-3395-42BA-9B03-4B2C787E8081}-chrome_installer.exe C:\Users\Claudia\AppData\Local\Temp\{D2416B08-7E6C-4C05-B27E-05A6DEC53BCD}-30.0.1599.69_29.0.1547.76_chrome_updater.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-18 22:25 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:18-06-2014 Ran by Claudia at 2014-06-18 22:27:44 Running from C:\Users\Claudia\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Kaspersky Anti-Virus (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Anti-Virus (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0C5823AA-7B6F- 44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft) Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA- 7B6F-44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft) 1&1 Surf-Stick (HKLM\...\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.2 - ) 3531-W-D (HKLM\...\{BD1587F7-B8D0-4111-8F1F-3327628AB02F}) (Version: 1.5.18 - Silicon Image) AAC Decoder (HKLM\...\{AEF9DC35ADDF4825B049ACBFD1C6EB37}) (Version: 7.1.0 - DivX, Inc.) ABBYY FineReader 6.0 Sprint (HKLM\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1395.4512 - ABBYY Software House) ABBYY FineReader 9.0 Sprint (HKLM\...\ABBYY FineReader 9.0 Sprint) (Version: 9.01.513.58212 - ABBYY) ABBYY FineReader 9.0 Sprint (Version: 9.01.513.58212 - ABBYY) Hidden Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 13 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Reader 8.3.0 - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-A83000000003}) (Version: 8.3.0 - Adobe Systems Incorporated) Adobe Shockwave Player (HKLM\...\Adobe Shockwave Player) (Version: 11 - Adobe Systems, Inc.) Agere Systems HDA Modem (HKLM\...\Agere Systems Soft Modem) (Version: - Agere Systems) ArcSoft MediaConverter 2 (HKLM\...\{83DA46EC-2CB1-4649-9100-C4F98D8DA8CD}) (Version: - ArcSoft) ArcSoft PhotoImpression 5 (HKLM\...\{4FE82F4B-B7D8-4E65-84AD-E0436CDE57DD}) (Version: - ArcSoft) ArcSoft ShowBiz DVD 2 (HKLM\...\{E883DCB3-766D-4166-8B28-33C8FE451F2B}) (Version: - ArcSoft) ArcSoft TotalMedia 3.5 (HKLM\...\{29E44E9D-ACB2-4D2D-849F-5361C941B7E1}) (Version: 3.5.7.362 - ArcSoft) AutoUpdate (HKLM\...\{18D10072035C4515918F7E37EAFAACFC}) (Version: 1.1 - ) Camera RAW Plug-In for EPSON Creativity Suite (HKLM\...\{93EA9C3E-BDFD-4309-A605-9B5BBC0CCEFD}) (Version: 2.2.0.0 - SEIKO EPSON CORPORATION) Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Corel MediaOne (HKLM\...\{A062A15F-9CAC-4B88-98DF-87628A0BD721}) (Version: 2.00.0000 - Corel Corporation) Corel Paint Shop Pro Photo X2 (HKLM\...\{64E72FB1-2343-4977-B4A8-262CD53D0BD3}) (Version: 12.010.0000 - Corel Corporation) Digital Video (HKLM\...\{C833C7B6-1140-471D-932B-391B5CA66D7D}) (Version: 1.00.000 - ) DivX Codec (HKLM\...\{7B63B2922B174135AFC0E1377DD81EC2}) (Version: 6.8.5 - DivX, Inc.) DivX Converter (HKLM\...\{13F3917B56CD4C25848BDC69916971BB}) (Version: 7.0.0 - DivX, Inc.) DivX Converter (HKLM\...\{B13A7C41581B411290FBC0395694E2A9}) (Version: 7.0.0 - DivX, Inc.) DivX Player (HKLM\...\{8ADFC4160D694100B5B8A22DE9DCABD9}) (Version: 7.0.0 - DivX, Inc.) DivX Plus DirectShow Filters (HKLM\...\DivX Plus DirectShow Filters) (Version: - DivX, Inc.) DivX Version Checker (HKLM\...\{3FC7CBBC4C1E11DCA1A752EA55D89593}) (Version: 7.0.0.19 - DivX, Inc.) DivX Web Player (HKLM\...\{B7050CBDB2504B34BC2A9CA0A692CC29}) (Version: 1.4.2 - DivX,Inc.) Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.) DVDVideoSoft Toolbar (HKLM\...\DVDVideoSoft Toolbar) (Version: - ) EPSON Attach To Email (HKLM\...\InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}) (Version: 1.01.0000 - SEIKO EPSON) EPSON Attach To Email (Version: 1.01.0000 - SEIKO EPSON) Hidden EPSON Copy Utility 3 (HKLM\...\{67EDD823-135A-4D59-87BD-950616D6E857}) (Version: 3.3.0.0 - ) EPSON Easy Photo Print (HKLM\...\{3D78F2A2-C893-4ABD-B5FE-AD7011837755}) (Version: 1.5.0.0 - SEIKO EPSON CORPORATION) Epson Easy Photo Print 2 (HKLM\...\{39F58DDB-B2B8-4B86-AF20-4706A80EB30D}) (Version: 2.2.0.0 - SEIKO EPSON CORPORATION) Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION) Epson Event Manager (HKLM\...\{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}) (Version: 2.40.0001 - SEIKO EPSON CORPORATION) EPSON File Manager (HKLM\...\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}) (Version: 1.3.0.0 - ) EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON Scan Assistant (HKLM\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - ) EPSON Stylus CX7300_CX8300_DX7400_DX8400 Handbuch (HKLM\...\EPSON Stylus CX7300_CX8300_DX7400_DX8400 Benutzerhandbuch) (Version: - ) EPSON SX420W Series Handbuch (HKLM\...\EPSON SX420W Series Manual) (Version: - ) EPSON SX420W Series Netzwerk-Handbuch (HKLM\...\EPSON SX420W Series Network Guide) (Version: - ) EPSON SX420W Series Printer Uninstall (HKLM\...\EPSON SX420W Series) (Version: - SEIKO EPSON Corporation) EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version: - SEIKO EPSON Corporation) EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.4i - SEIKO EPSON CORPORATION) EpsonNet Setup 3.2 (HKLM\...\{C9D8A041-2963-4B31-8FFC-1500F3DB9293}) (Version: 3.2a - SEIKO EPSON CORPORATION) Firebird SQL Server - MAGIX Edition (HKLM\...\Firebird SQL Server D) (Version: 2.0.1.8 - MAGIX AG) Free Audio CD Burner version 1.2 (HKLM\...\Free Audio CD Burner_is1) (Version: - DVDVideoSoft Limited.) Free YouTube Download version 3.0.16.923 (HKLM\...\Free YouTube Download_is1) (Version: - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.11.37.1212 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.37.1212 - DVDVideoSoft Ltd.) GMX MediaCenter 1.5.1765.0 (HKCU\...\GMX Application {sync-000021}) (Version: 1.5.1765.0 - 1&1 Mail & Media GmbH) Google Chrome (HKLM\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.) Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden H.264 Decoder (HKLM\...\{A96E97134CA649888820BCDE5E300BBD}) (Version: 1.0.0 - DivX, Inc.) ICQ7.4 (HKLM\...\{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37}) (Version: 7.4 - ICQ) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation) Intel(R) Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - ) InterVideo WinDVD 8 (HKLM\...\InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}) (Version: 8.0-B9.385 - InterVideo Inc.) InterVideo WinDVD 8 (Version: 8.0-B9.385 - InterVideo Inc.) Hidden IPTInstaller (HKLM\...\{6965F2F4-1CD2-4F42-A8EF-9EF433F9AA72}) (Version: 4.0.4 - HTC) Java(TM) 6 Update 5 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160050}) (Version: 1.6.0.50 - Sun Microsystems, Inc.) Kaspersky Anti-Virus (HKLM\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab) Kaspersky Anti-Virus (Version: 14.0.0.4651 - Kaspersky Lab) Hidden Launch Manager V1.4.9 (HKLM\...\{D0846526-66DD-4DC9-A02C-98F9A2806812}) (Version: 1.4.9 - Wistron Corp.) LG PC Suite II (HKLM\...\{14DCD95A-EBA3-4BF0-B7EF-533852E99BE6}) (Version: 2.00.0000 - LG PC Suite) LG PC Suite II (Version: 2.00.0000 - LG PC Suite) Hidden LG USB Modem driver (HKLM\...\{C3ABE126-2BB2-4246-BFE1-6797679B3579}) (Version: 4.9.4 - LG Electronics) MD86351 Driver Install (HKLM\...\InstallShield_{B3A9DC22-6162-4844-BEB3-853BAFB980E0}) (Version: 6.3.6.1 - Ihr Firmenname) MD86351 Driver Install (Version: 6.3.6.1 - Ihr Firmenname) Hidden MEDION Fotos auf CD Nord (HKLM\...\MEDION Fotos auf CD Nord D) (Version: 6.0.2.0 - MAGIX AG) Medion Media Center 0 (Version: 1.0.12.0 - Medion) Hidden MEDIONbox (HKLM\...\{27FDF949-69CE-435A-8372-339F72336AC5}) (Version: 1.09.0000.00052 - Medion) Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - ) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55- 48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55- 48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Picture It! Foto Premium 9 (HKLM\...\PictureIt_v9) (Version: 9.0.0.0000 - Microsoft Corporation) Microsoft Picture It! Foto Premium 9 (Version: 9.0.0.0000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Microsoft XML Parser (Version: 8.20.8730.4 - Microsoft Corporation) Hidden MindManager Smart (HKLM\...\MindManager Smart) (Version: 2.1.3 - Mindjet LLC) MKV Splitter (HKLM\...\{AAC389499AEF40428987B3D30CFC76C9}) (Version: 1.0.0 - DivX, Inc.) Move Networks Media Player for Internet Explorer (HKCU\...\Move Networks Player - IE) (Version: - ) Mozilla Firefox (3.0) (HKLM\...\Mozilla Firefox (3.0)) (Version: 3.0 (de) - Mozilla) MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nero 8 Essentials (HKLM\...\{47948554-90C6-4AAC-8CFA-D23CE11C1031}) (Version: 8.3.124 - Nero AG) neroxml (Version: 1.0.0 - Nero AG) Hidden OnlineFotoservice (HKLM\...\OnlineFotoservice) (Version: 5.1.5 - CEWE Stiftung u Co. KGaA) Opera 12.12 (HKLM\...\Opera 12.12.1707) (Version: 12.12.1707 - Opera Software ASA) PDF24 Creator 6.3.2 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 0.9.8 - Frank Heindörfer, Philip Chinery) Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.) Ralink Wireless LAN (HKLM\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.00.0000 - RaLink) Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista (HKLM\...\{8833FFB6-5B0C-4764-81AA- 06DFEED9A476}) (Version: 1.00.0000 - Realtek) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5595 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM\...\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version: - Realtek Semiconductor Corp.) Rossmann Fotoservice 2.6 (HKLM\...\Rossmann Fotoservice_is1) (Version: - ) Sceneo AbsolutTV (HKLM\...\{4C73B683-B15D-4B94-AC7A-520B70C4FFE9}) (Version: - ) Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Switch Sound File Converter (HKLM\...\Switch) (Version: - NCH Software) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.0.14.0 - Synaptics) TV IR (HKLM\...\InstallShield_{8CFE319F-DC08-48BA-B011-37ED5C9733B5}) (Version: 1.00.0000 - Ihr Firmenname) TV IR (Version: 1.00.0000 - Ihr Firmenname) Hidden Ulead DVD MovieFactory 5 (HKLM\...\{FF164702-AF8B-4F2F-8038-74A4C536866B}) (Version: 5.3 - Ulead Systems, Inc.) Ulead PhotoImpact 12 (HKLM\...\{11AFE21E-B193-430D-B57A-DFF7815BB962}) (Version: 12.0 - Ulead System) Uninstall 1.0.0.1 (HKLM\...\Uninstall_is1) (Version: - ) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D- 5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_ {C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM\...\{90120000-006E-0409-0000-0000000FF1CE} _ENTERPRISE_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE} _ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE} _HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE} _ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE} _HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE} _ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE} _HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office Access 2007 Help (KB963663) (HKLM\...\{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_ {6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}) (Version: - Microsoft) Update for Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_ {199DF7B6-169C-448C-B511-1054101BE9C9}) (Version: - Microsoft) Update for Microsoft Office Infopath 2007 Help (KB963662) (HKLM\...\{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_ {716B81B8-B13C-41DF-8EAC-7A2F656CAB63}) (Version: - Microsoft) Update for Microsoft Office OneNote 2007 Help (KB963670) (HKLM\...\{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_ {2744EF05-38E1-4D5D-B333-E021EDAEA245}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE} _ENTERPRISE_{ED38F8A3-4F61-494E-8BCA-E3AC7760C924}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE} _ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_ {0451F231-E3E3-4943-AB9F-58EB96171784}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2881065) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000- 0000000FF1CE}_ENTERPRISE_{B7EF38F7-1D58-4085-A9A4-0F6C69A5AA1E}) (Version: - Microsoft) Update for Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_ {397B1D4F-ED7B-4ACA-A637-43B670843876}) (Version: - Microsoft) Update for Microsoft Office Publisher 2007 Help (KB963667) (HKLM\...\{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_ {2E40DE55-B289-4C8B-8901-5D369B16814F}) (Version: - Microsoft) Update for Microsoft Office Script Editor Help (KB963671) (HKLM\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_ {CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version: - Microsoft) Update for Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_ {80E762AA-C921-4839-9D7D-DB62A72C0726}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_ {BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE} _HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_ {38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) USB Video Device (HKLM\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.18100.101 - Sonix) VC80CRTRedist - 8.0.50727.762 (Version: 1.0.0 - DivX, Inc) Hidden VCRedistSetup (Version: 1.0.0 - Nero AG) Hidden Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player 1.1.10 (HKLM\...\VLC media player) (Version: 1.1.10 - VideoLAN) WavePad Sound Editor (HKLM\...\WavePad) (Version: - NCH Software) Windows Live Messenger (HKLM\...\{279DB581-239C-4E13-97F8-0F48E40BE75C}) (Version: 8.1.0178.00 - Microsoft Corporation) WinRAR (HKLM\...\WinRAR archiver) (Version: - ) WISO Mein Geld 2008 Professional (HKLM\...\{D8D22773-14BF-4178-A683-3DBA515C2A26}) (Version: 9.00.01.0023 - Buhl Data Service GmbH) XVID Codec Installation (HKLM\...\{534C6D59-D6E3-48A6-AD0B-747799019960}) (Version: - ) ==================== Restore Points ========================= 04-06-2014 17:38:03 Geplanter Prüfpunkt 07-06-2014 18:44:11 Windows Update 08-06-2014 10:42:59 Gerätetreiber-Paketinstallation: HTC, Corporation 08-06-2014 10:46:45 Gerätetreiber-Paketinstallation: HTC Corporation Netzwerkadapter 08-06-2014 10:49:34 Gerätetreiber-Paketinstallation: HTC Corporation Tragbare Geräte 08-06-2014 10:54:49 Gerätetreiber-Paketinstallation: HTC Netzwerkprotokoll 11-06-2014 17:26:28 Windows Update 11-06-2014 18:00:59 Windows Update 13-06-2014 20:48:59 Installed AVG 2014 13-06-2014 20:50:05 Installed AVG 2014 14-06-2014 11:59:34 Gerätetreiber-Paketinstallation: Kaspersky Lab Netzwerkdienst 17-06-2014 17:36:53 Removed AVG 2014 17-06-2014 17:41:24 Removed AVG 2014 ==================== Hosts content: ========================== 2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0D4A3951-D115-4E17-9495-26DC510E1359} - System32\Tasks\{19864B7B-6EBE-4684-9FF9-DD775F771854} => C:\Program Files\Skype\\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32 \RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {574969E9-0C4A-4A75-A6C7-549B08CDB6C6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-06-05] (Google Inc.) Task: {8AC7F5E7-9061-45A6-95FE-B269516DA561} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-06-05] (Google Inc.) Task: {B7794283-DDB2-48C6-9B9B-3AC33999A0C1} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {EEEAB8B8-067F-4F56-8432-3BBC88C3CC8F} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32 \netsh.exe [2006-11-02] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2009-09-04 19:29 - 2001-10-28 17:42 - 00116224 _____ () C:\Windows\System32\pdfcmnnt.dll 2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0 \dblite.dll 2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0 \kpcengine.2.3.dll 2013-07-21 20:03 - 2013-07-21 20:03 - 03391488 _____ () c:\windows\assembly\nativeimages1_v1.1.4322 \mscorlib\1.0.5000.0__b77a5c561934e089_b0c6b048\mscorlib.dll 2013-07-21 20:02 - 2013-07-21 20:02 - 01966080 _____ () c:\windows\assembly\nativeimages1_v1.1.4322 \system\1.0.5000.0__b77a5c561934e089_c7c004ef\system.dll 2013-07-21 20:02 - 2013-07-21 20:02 - 03035136 _____ () c:\windows\assembly\nativeimages1_v1.1.4322 \system.windows.forms\1.0.5000.0__b77a5c561934e089_5c188a8d\system.windows.forms.dll 2013-07-21 20:02 - 2013-07-21 20:02 - 02088960 _____ () c:\windows\assembly\nativeimages1_v1.1.4322 \system.xml\1.0.5000.0__b77a5c561934e089_821dd40b\system.xml.dll 2009-10-03 11:47 - 2005-06-28 13:59 - 00053248 _____ () C:\Program Files\ArcSoft\PhotoImpression 5\Share\PIHook.dll 2008-04-22 08:37 - 2007-04-19 12:11 - 00006656 _____ () c:\program files\medion\medionbox\program\structconverter.dll 2009-08-18 20:24 - 2009-04-11 08:28 - 00368640 _____ () C:\Windows\system32\msjetoledb40.dll 2012-10-08 17:04 - 2012-10-08 17:04 - 00166912 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe 2007-06-05 13:20 - 2007-06-05 13:20 - 00177704 _____ () C:\Windows\system32\PSIService.exe 2008-04-22 08:30 - 2007-05-16 22:48 - 00421955 _____ () C:\Program Files\Sceneo\AbsolutTV\Services\PVR\tvtvRemote.dll 2011-08-06 14:59 - 2010-09-30 14:00 - 00253264 _____ () C:\Program Files\1&1 Surf-Stick\AssistantServices.exe 2008-04-21 09:37 - 2007-09-01 14:03 - 00032768 _____ () C:\Program Files\Launch Manager\LaunchAp.exe 2007-10-30 19:52 - 2007-10-30 19:52 - 00016200 _____ () C:\Program Files\Corel\Corel Paint Shop Pro Photo X2 \CorelIOMonitor.exe 2011-01-08 16:14 - 2007-02-12 15:50 - 00020480 _____ () C:\Windows\FixCamera.exe 2011-01-08 16:14 - 2007-12-04 19:28 - 00249856 _____ () C:\Windows\tsnp2uvc.exe 2011-08-06 14:59 - 2010-09-30 14:00 - 00139088 _____ () C:\Program Files\1&1 Surf-Stick\UIExec.exe 2010-12-22 11:27 - 2010-12-22 11:27 - 00692318 _____ () C:\Program Files\TV IR\TV IR.exe 2010-06-18 00:09 - 2010-06-18 00:09 - 00167936 _____ () C:\Program Files\TV IR\RmCard.dll 2008-01-15 00:40 - 2008-01-15 00:40 - 00053248 _____ () C:\Program Files\TV IR\LWExt.dll 2009-03-09 11:52 - 2009-03-09 11:52 - 00053248 _____ () C:\Program Files\TV IR\tmir.dll 2012-10-21 13:31 - 2007-04-19 09:33 - 00035584 _____ () C:\Program Files\ArcSoft\TotalMedia 3.5\uPiApi.dll 2014-06-18 22:22 - 2014-06-18 22:22 - 00043008 _____ () C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153- 5bce-5766-8f84-3e3e7ecf0d81}.tmp_32ceb.dll 2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Claudia\AppData\Roaming\Dropbox\bin\libcef.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Claudia\Beweis.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Beweis.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Beweis.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Desktop\Funde Kaspersky.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Desktop\Funde Kaspersky.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Desktop\Funde Kaspersky.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\ebay lederjacke.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\ebay lederjacke.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\ebay lederjacke.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\Muster Inspektion VW.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Muster Inspektion VW.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\Muster Inspektion VW.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Claudia\Documents\pikante spaghetti.png:SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\pikante spaghetti.png:Updt_SummaryInformation AlternateDataStreams: C:\Users\Claudia\Documents\pikante spaghetti.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:SummaryInformation AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:Updt_SummaryInformation AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:SummaryInformation AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:Updt_SummaryInformation AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/18/2014 10:20:50 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung NMIndexStoreSvr.exe, Version 3.3.3.0, Zeitstempel 0x47c6bd1b, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000, Ausnahmecode 0xc0000005, Fehleroffset 0x17271727, Prozess-ID 0x100c, Anwendungsstartzeit NMIndexStoreSvr.exe0. Error: (06/18/2014 10:19:48 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/18/2014 06:25:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung NMIndexStoreSvr.exe, Version 3.3.3.0, Zeitstempel 0x47c6bd1b, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000, Ausnahmecode 0xc0000005, Fehleroffset 0x17271727, Prozess-ID 0x1248, Anwendungsstartzeit NMIndexStoreSvr.exe0. Error: (06/18/2014 06:23:52 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/18/2014 06:06:14 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/18/2014 06:05:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung NMIndexStoreSvr.exe, Version 3.3.3.0, Zeitstempel 0x47c6bd1b, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000, Ausnahmecode 0xc0000005, Fehleroffset 0x03030303, Prozess-ID 0xb18, Anwendungsstartzeit NMIndexStoreSvr.exe0. Error: (06/17/2014 10:45:49 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (06/18/2014 10:19:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Error: (06/18/2014 06:23:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Error: (06/18/2014 06:06:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Error: (06/17/2014 10:46:42 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: 30000Avira Service Host Error: (06/17/2014 10:46:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Windows Search%%1053 Error: (06/17/2014 10:46:12 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: 30000Windows Search Error: (06/17/2014 10:45:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Microsoft Office Sessions: ========================= Error: (05/07/2013 08:37:08 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 810 seconds with 720 seconds of active time. This session ended with a crash. Error: (05/13/2011 02:44:54 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1089 seconds with 120 seconds of active time. This session ended with a crash. Error: (03/20/2011 05:35:34 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4422 seconds with 900 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-06-18 22:27:18.072 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-18 22:27:17.246 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-18 22:27:16.419 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-18 22:27:15.592 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-18 22:26:34.611 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-18 22:26:33.722 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-18 22:26:32.817 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-18 22:26:31.912 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-17 22:52:26.481 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-17 22:52:25.545 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 48% Total physical RAM: 3061.69 MB Available physical RAM: 1576.18 MB Total Pagefile: 6325.64 MB Available Pagefile: 4708.42 MB Total Virtual: 2047.88 MB Available Virtual: 1902.56 MB ==================== Drives ================================ Drive c: (BOOT) (Fixed) (Total:207.5 GB) (Free:100.71 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (RECOVER) (Fixed) (Total:25.37 GB) (Free:5.96 GB) FAT32 Drive g: () (Removable) (Total:1.84 GB) (Free:0 GB) FAT ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: 4B64DFC2) Partition 1: (Active) - (Size=207 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=25 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 2 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ |
19.06.2014, 11:02 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Avira durch Gruppenrichtlinie geblockt - Trojaner? Okay, dann Kontrollscans mit MBAM und ESET bitte: Downloade Dir bitte Malwarebytes Anti-Malware
ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
20.06.2014, 04:14 | #15 |
| Avira durch Gruppenrichtlinie geblockt - Trojaner?Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 19.06.2014 Suchlauf-Zeit: 19:42:48 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.06.19.08 Rootkit Datenbank: v2014.06.02.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows Vista Service Pack 2 CPU: x86 Dateisystem: NTFS Benutzer: Claudia Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 265427 Verstrichene Zeit: 26 Min, 14 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 1 Rogue.PersonalAntiVirus, C:\Program Files\PersonalAV, In Quarantäne, [64f0df9bbfbc132396a1424004fe16ea], Dateien: 2 PUP.Optional.FreeTwitTube.A, C:\Users\Claudia\AppData\Local\Temp\ibtmpd366498\component_583, In Quarantäne, [401428522e4d64d2bf0fd7af1ee3d927], PUP.Optional.FileScout.A, C:\Users\Claudia\AppData\Local\Temp\ibtmpd366498\component_600, In Quarantäne, [82d2b9c138439c9a4a6fe12afc0532ce], Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7587 # api_version=3.0.2 # EOSSerial=4aa60037e628a54ab4c957fd7d7f1aa5 # engine=18789 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-06-19 11:02:48 # local_time=2014-06-20 01:02:48 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode_1='Kaspersky Anti-Virus' # compatibility_mode=1293 16777213 100 100 16254 34696988 0 0 # compatibility_mode_1='' # compatibility_mode=5892 16776574 100 100 526189 240751694 0 0 # scanned=281141 # found=16 # cleaned=0 # scan_time=15133 sh=A981E3D6F03D3BD57D1472F33A4093A01533F8A8 ft=1 fh=7aaf7b3d0491af48 vn="Variante von MSIL/AdvancedSystemProtector.A evtl. unerwünschte Anwendung" ac=I fn="C:\$Recycle.Bin\S-1-5-21-3856976919-2596979157-3738053339-1003\$R4GLCRP.exe" sh=8992F72873D09212597E582A16F8D9BC60E6A22A ft=1 fh=e21391a34e842ffc vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Common Files\DVDVideoSoft\TB\ConduitInstaller.exe.vir" sh=664270A860DDB3D6F23F617D0615070330A71A30 ft=1 fh=192f7aaecaa32147 vn="Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Conduit\Community Alerts\Alert.dll.vir" sh=6EEA45F0AC75053D955E44A1735997B263EDF882 ft=1 fh=be934e040f354c5e vn="Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Conduit\Community Alerts\Alert0.dll.vir" sh=57CD8DEAF43DF3A2F4703E5219A69935B119D0DB ft=1 fh=311781f1ea21501f vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\ConduitEngine\ConduitEngine.dll.vir" sh=57CD8DEAF43DF3A2F4703E5219A69935B119D0DB ft=1 fh=311781f1ea21501f vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\DVDVideoSoftTB\tbDVDV.dll.vir" sh=5101F30DCAB10FED68ECD473A99AEB523EF0DC44 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Claudia\AppData\Local\Temp\CT2269050\chrome\dvdvideosofttb.jar.vir" sh=57CD8DEAF43DF3A2F4703E5219A69935B119D0DB ft=1 fh=311781f1ea21501f vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Claudia\AppData\LocalLow\ConduitEngine\ConduitEngine.dll.vir" sh=57CD8DEAF43DF3A2F4703E5219A69935B119D0DB ft=1 fh=311781f1ea21501f vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Claudia\AppData\LocalLow\DVDVideoSoftTB\tbDVDV.dll.vir" sh=5101F30DCAB10FED68ECD473A99AEB523EF0DC44 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\chrome\dvdvideosofttb.jar.vir" sh=972A6701E512D4D717B91B1C8E0EC542BCCEB247 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\chrome\dvdvideosoft.jar.vir" sh=E5C5C36DDD3DC414086EB9EC20DCEF13C06DDD94 ft=1 fh=f4eb487f30a3126f vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Claudia\AppData\Local\Temp\tbDVDV.dll" sh=B5A6C2CFC53E52AD5DF76AD819AF9F53424C5E75 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Claudia\AppData\Local\Temp\tbff.xpi" sh=7A5B168BB2B8C06B2A9134B656BBF195830D21C2 ft=1 fh=55d4f387d8566cf4 vn="Variante von Win32/PriceGong.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Claudia\AppData\LocalLow\DVDVideoSoft\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.1.1\bin\PriceGongIE.dll" sh=66141F092657FC9801DCFED65C7B99A578B043D6 ft=1 fh=398a74cdcc9e1d42 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Claudia\Downloads\FreeYouTubeToMp3Converter.exe" sh=D03FB2F36539640C5C3C84686CBE465E6E466316 ft=1 fh=6ee776d5f517fb67 vn="Variante von Win32/KillProc.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\FixCamera.exe" |
Themen zu Avira durch Gruppenrichtlinie geblockt - Trojaner? |
avira anti virus trojaner, fehlermeldung, geblockt, gruppenrichtlinie, komplett, msil/advancedsystemprotector.a, neuinstallation, nicht mehr, pup.optional.filescout.a, pup.optional.freetwittube.a, registry, rogue.personalantivirus, trojaner?, win32/killproc.a, win32/pricegong.a, win32/toolbar.conduit, win32/toolbar.conduit.a, win32/toolbar.conduit.b, win32/toolbar.conduit.y, windows, windows vista, wirklich |