|
Log-Analyse und Auswertung: Benötige Hilfe zur Entfernung eines TrojanersWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
30.06.2014, 18:54 | #1 |
| Benötige Hilfe zur Entfernung eines Trojaners Hallo. Ich habe folgendes Problem: Auf meinem Laptop ist die Datei "c:\windows\temp\winupdater.exe" durch den Trojaner "TR/Dropper.Gen" befallen. Ich wäre sehr dankbar, wenn mir jemand erklären könnte wie ich diesen Trojaner entfernen kann. Danke |
30.06.2014, 19:44 | #2 |
/// TB-Ausbilder /// Anleitungs-Guru | Benötige Hilfe zur Entfernung eines TrojanersMein Name ist Jürgen und ich werde Dir bei Deinem Problem behilflich sein. Zusammen schaffen wir das...
Hinweis: Ich kann Dir niemals eine Garantie geben, dass wir alle schädlichen Dateien finden werden. Eine Formatierung ist meist der schnellere und immer der sicherste Weg, aber auch nur bei wirklicher Malware empfehlenswert. Adware & Co. können wir sehr gut entfernen. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Du mein clean bekommst. Los geht's: Schritt 1 Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff Posten in CODE-Tags: So gehts... Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert uns massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
30.06.2014, 20:38 | #3 |
| Benötige Hilfe zur Entfernung eines Trojaners FRST.txt:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-06-2014 02 Ran by Sebastian (administrator) on BASTI-SCHLEPPI on 30-06-2014 21:11:09 Running from C:\Users\Sebastian\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe () C:\Users\Sebastian\AppData\LocalLow\QuickTime\IE\QuickTimeUpdater.exe () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe () C:\Program Files (x86)\Show-Password-soft\Show-Passwordd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe () C:\Program Files (x86)\Show-Password-soft\Show-Passwordnm161.exe () C:\Program Files (x86)\Tor\tor.exe () C:\Program Files (x86)\WinUpd\WinUpd.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11046504 2010-07-14] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2149160 2010-05-21] (Synaptics Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-27] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [455512 2014-05-28] (DivX, LLC) HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512 2013-06-22] (RealNetworks, Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1758160 2014-02-13] (APN) HKLM-x32\...\Run: [Aimersoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe [1666560 2012-02-20] (AimerSoft) HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\.DEFAULT\...\Run: [SearchProtect] => \SearchProtect\bin\cltmng.exe HKU\S-1-5-21-76830181-1066914796-2057996457-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3514176 2011-11-10] (DT Soft Ltd) HKU\S-1-5-21-76830181-1066914796-2057996457-1000\...\Run: [ccleaner] => C:\Program Files\CCleaner\CCleaner64.exe [5435744 2012-10-24] (Piriform Ltd) HKU\S-1-5-21-76830181-1066914796-2057996457-1000\...\Run: [] => [X] HKU\S-1-5-21-76830181-1066914796-2057996457-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.) HKU\S-1-5-21-76830181-1066914796-2057996457-1000\...\Run: [se] => C:\Users\user\AppData\Roaming\SkypEmoticons\SE.exe /minimized HKU\S-1-5-21-76830181-1066914796-2057996457-1000\...\MountPoints2: {2053f697-db98-11e0-8251-001bb16640c8} - F:\_AUTORUN\AUTORUN.EXE HKU\S-1-5-21-76830181-1066914796-2057996457-1000\...\MountPoints2: {ed22ed00-a265-11e0-8aa8-001bb16640c8} - H:\Startme.exe HKU\S-1-5-21-76830181-1066914796-2057996457-1000\...0c966feabec1\InprocServer32: [Default-shell32] C:\Users\Sebastian\AppData\Local\{3137ec37-8634-c619-3470-34d1b8cd37bc}\n. ATTENTION! ====> ZeroAccess/Alureon? AppInit_DLLs-x32: C:\Users\SEBAST~1\AppData\Local\DProtect\eBP.dll => "C:\Users\SEBAST~1\AppData\Local\DProtect\eBP.dll" File Not Found AppInit_DLLs-x32: ,C:\Users\SEBAST~1\AppData\Local\DProtect\eBPSD.dll => "C:\Users\SEBAST~1\AppData\Local\DProtect\eBPSD.dll" File Not Found Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SRS Premium Sound.lnk ShortcutTarget: SRS Premium Sound.lnk -> C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut11_C03C290FA6F54A2B8A2DFE2786A1E275.exe (Acresso Software Inc.) ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File BootExecute: autocheck autochk * sdnclean64.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== ProxyEnable: Internet Explorer proxy is enabled. ProxyServer: http=127.0.0.1:14352 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://websearch.fastsearchings.info/?pid=1249&r=2014/06/29&hid=6740810968012150956&lg=EN&cc=DE&unqvl=56 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://websearch.fastsearchings.info/?pid=1249&r=2014/06/29&hid=6740810968012150956&lg=EN&cc=DE&unqvl=56 URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} StartMenuInternet: IEXPLORE.EXE - c:\program files (x86)\internet explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {485E148E-19D8-760F-2840-63E276A4338B} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHM641JI_S26XJ9GZA00603&ts=1377264984 SearchScopes: HKLM-x32 - DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.fastsearchings.info/?l=1&q={searchTerms}&pid=1249&r=2014/06/29&hid=6740810968012150956&lg=EN&cc=DE&unqvl=56 SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.fastsearchings.info/?l=1&q={searchTerms}&pid=1249&r=2014/06/29&hid=6740810968012150956&lg=EN&cc=DE&unqvl=56 SearchScopes: HKCU - DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.fastsearchings.info/?l=1&q={searchTerms}&pid=1249&r=2014/06/29&hid=6740810968012150956&lg=EN&cc=DE&unqvl=56 SearchScopes: HKCU - {64989C4F-2B66-48BA-8D6F-F452CBD33249} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {88B97021-EFF3-4E8D-B8A2-0225C631E569} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.fastsearchings.info/?l=1&q={searchTerms}&pid=1249&r=2014/06/29&hid=6740810968012150956&lg=EN&cc=DE&unqvl=56 BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: QuickTime - {D4704207-C86B-4811-951E-6F322F9CEDE7} - C:\Users\Sebastian\AppData\LocalLow\QuickTime\IE\QuickTime.dll (Apple Inc.) BHO-x32: No Name - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{9B334387-B32E-40AA-A8DA-FFAAFCCB3AE5}: [NameServer]192.168.198.10 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Users\Sebastian\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\system32\Adobe\Director\np32dsw.dll No File FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @meadco.com/neptune plugin,version=2.0.0.29 - C:\OSA Kit Pro Player v4.0\npmeadax.dll (MeadCo Corp.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nokia.com/EnablerPlugin - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin-x32: @oberon-media.com/ONCAdapter - C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll (Oberon-Media ) FF Plugin-x32: @protectdisc.com/NPPDLicenseHelper - C:\Program Files (x86)\ProtectDisc\License Helper\NPPDLicenseHelper.dll () FF Plugin-x32: @real.com/nppl3260;version=16.0.2.32 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpplugin;version=16.0.2.32 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Sebastian\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: @www.flatcast.com/FlatViewer 5.2 - C:\Users\SEBAST~1\AppData\Roaming\Mozilla\plugins\NpFv530.dll (1 mal 1 Software GmbH) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NpFv530.dll (1 mal 1 Software GmbH) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npmeadax.dll (MeadCo Corp.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPPDLicenseHelper.dll () FF Plugin ProgramFiles/Appdata: C:\Users\Sebastian\AppData\Roaming\mozilla\plugins\NpFv530.dll (1 mal 1 Software GmbH) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrchddr.xml FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF HKLM-x32\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-06-22] FF HKLM-x32\...\Firefox\Extensions: [ext@VideoPlayerV3beta44.net] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta44\ff FF HKLM-x32\...\Firefox\Extensions: [ext@MediaPlayerV1alpha682.net] - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha682\ff FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewerV1alpha1582.net] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1582\ff FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha30.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha30\ff FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha2213.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha2213\ff FF HKLM-x32\...\Firefox\Extensions: [ext@MediaWatchV1home669.net] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home669\ff FF HKLM-x32\...\Firefox\Extensions: [ext@MediaBuzzV1mode2726.net] - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode2726\ff FF Extension: Media Buzz - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode2726\ff [2014-04-25] FF HKLM-x32\...\Firefox\Extensions: [ext@RichMediaViewV1release1602.net] - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release1602\ff FF HKCU\...\Firefox\Extensions: [{B89E5135-AE18-31EF-AF34-85C4C7FF027A}] - C:\Program Files (x86)\Show-Password-soft\161.xpi FF Extension: Show-Password - C:\Program Files (x86)\Show-Password-soft\161.xpi [2014-04-27] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-27] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-27] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-05-27] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] (APN LLC.) R2 QuickTimeUpdater; C:\Users\Sebastian\AppData\LocalLow\QuickTime\IE\QuickTimeUpdater.exe [18432 2011-07-12] () [File not signed] R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] () R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-07] () S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) R2 Show-Password; C:\Program Files (x86)\Show-Password-soft\Show-Passwordnm161.exe [143872 2014-04-27] () [File not signed] R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-08-31] () [File not signed] R2 WinUpd; C:\Program Files (x86)\WinUpd\WinUpd.exe [59904 2014-05-14] () [File not signed] ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2011-11-27] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-27] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-27] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-10] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [279616 2012-06-12] (DT Soft Ltd) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2011-11-27] () S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2010-11-04] (Windows (R) 2003 DDK 3790 provider) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [530488 2011-12-09] () [File not signed] R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] () R1 {552199fb-9890-4055-9aaf-b2f6d51d46e9}Gw64; C:\Windows\System32\drivers\{552199fb-9890-4055-9aaf-b2f6d51d46e9}Gw64.sys [61112 2014-05-22] (StdLib) R1 {552199fb-9890-4055-9aaf-b2f6d51d46e9}w64; C:\Windows\System32\drivers\{552199fb-9890-4055-9aaf-b2f6d51d46e9}w64.sys [61112 2014-04-24] (StdLib) U3 aflw01lo; C:\Windows\System32\Drivers\aflw01lo.sys [0 ] (Advanced Micro Devices) S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-30 21:11 - 2014-06-30 21:13 - 00022918 _____ () C:\Users\Sebastian\Desktop\FRST.txt 2014-06-30 21:10 - 2014-06-30 21:11 - 00000000 ____D () C:\FRST 2014-06-30 21:08 - 2014-06-30 21:08 - 02083328 _____ (Farbar) C:\Users\Sebastian\Desktop\FRST64.exe 2014-06-30 19:57 - 2014-06-30 21:02 - 00000143 _____ () C:\Users\Sebastian\Desktop\Trojaner-Board.txt 2014-06-29 16:29 - 2014-06-29 16:29 - 00000000 ____D () C:\Users\Sebastian\AppData\Roaming\SkypEmoticons 2014-06-29 16:29 - 2014-06-29 16:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SkypEmoticons 2014-06-29 16:27 - 2014-06-29 16:27 - 00000000 ____D () C:\Program Files\Level Quality Watcher 2014-06-29 14:35 - 2014-06-29 14:35 - 00000000 _____ () C:\autoexec.bat 2014-06-29 14:34 - 2014-06-29 14:34 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-06-29 14:33 - 2014-06-29 16:35 - 00000000 ____D () C:\windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP 2014-06-29 14:14 - 2014-06-29 14:14 - 00000000 ____D () C:\Users\Sebastian\AppData\Roaming\TestApp 2014-06-29 14:14 - 2014-06-29 14:14 - 00000000 ____D () C:\ProgramData\PC Tools 2014-06-28 16:58 - 2014-06-29 07:24 - 00000452 _____ () C:\Users\Sebastian\Desktop\Zed.txt 2014-06-27 23:28 - 2014-06-27 23:29 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-27 23:28 - 2014-06-27 23:28 - 00000000 ____D () C:\Users\Sebastian\ Malwarebytes Anti-Malware 2014-06-27 23:28 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-06-27 23:28 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-06-27 23:28 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-06-27 23:25 - 2014-06-27 23:26 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sebastian\Downloads\mbam-setup-2.0.2.1012.exe 2014-06-27 15:54 - 2014-06-27 15:55 - 636661760 _____ () C:\Users\Sebastian\Desktop\Avira_Notfall_CD.iso 2014-06-27 15:29 - 2014-06-27 15:46 - 638438160 _____ (Avira GmbH) C:\Users\Sebastian\Downloads\rescue-system.exe 2014-06-25 16:33 - 2014-06-27 15:34 - 00000694 _____ () C:\Users\Sebastian\Desktop\Avira_Rescue_System.txt 2014-06-22 11:33 - 2014-06-30 19:22 - 00002016 _____ () C:\windows\setupact.log 2014-06-22 11:33 - 2014-06-29 19:17 - 00001960 _____ () C:\windows\PFRO.log 2014-06-22 11:33 - 2014-06-22 11:33 - 00000000 _____ () C:\windows\setuperr.log 2014-06-22 09:20 - 2014-06-30 19:29 - 00264451 _____ () C:\windows\WindowsUpdate.log 2014-06-20 15:36 - 2014-06-20 15:36 - 00001062 _____ () C:\Users\Public\Desktop\DivX Player.lnk 2014-06-15 11:24 - 2014-06-24 15:32 - 00001654 _____ () C:\Users\Sebastian\Desktop\Avira_Answers_Frage.txt 2014-06-15 11:08 - 2014-06-15 11:25 - 00000151 _____ () C:\Users\Sebastian\Desktop\Avira_Answers.txt 2014-06-14 22:52 - 2014-06-28 11:14 - 00000728 _____ () C:\Users\Sebastian\Desktop\Avira.txt 2014-06-14 07:46 - 2014-06-14 07:50 - 00000000 ____D () C:\Users\Sebastian\AppData\Local\DownBooster 2014-06-14 07:46 - 2014-06-14 07:50 - 00000000 ____D () C:\Program Files (x86)\WinUpd 2014-06-13 21:03 - 2014-06-13 21:03 - 00000000 ____D () C:\Users\Sebastian\Documents\StreamTransport 2014-06-13 15:41 - 2014-06-13 15:41 - 00002428 _____ () C:\windows\SysWOW64\qtplugin.log 2014-06-13 15:41 - 2014-06-13 15:41 - 00001049 _____ () C:\Users\Sebastian\Desktop\QuickTime Player.lnk 2014-06-13 15:41 - 2014-06-13 15:41 - 00000000 ____D () C:\windows\SysWOW64\QuickTime 2014-06-13 15:41 - 2014-06-13 15:41 - 00000000 ____D () C:\ProgramData\QuickTime 2014-06-13 15:41 - 2014-06-13 15:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-06-13 15:41 - 2014-06-13 15:41 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-06-13 15:41 - 2014-06-13 15:41 - 00000000 _____ () C:\windows\SysWOW64\QuickTime.qtp 2014-06-13 15:41 - 1999-11-10 11:05 - 00086016 _____ (MindVision) C:\windows\unvise32qt.exe 2014-06-12 15:42 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-06-12 15:42 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-06-12 15:42 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-06-12 15:42 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-06-12 15:42 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2014-06-12 15:42 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-06-12 15:42 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-06-12 15:42 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-06-12 15:42 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-06-12 15:42 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-06-12 15:42 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-06-12 15:42 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-06-12 15:42 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-06-12 15:42 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-06-12 15:42 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-06-12 15:42 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-06-12 15:42 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-06-12 15:42 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-06-12 15:42 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2014-06-12 15:42 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-06-12 15:42 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-06-12 15:42 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2014-06-12 15:42 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-06-12 15:42 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2014-06-12 15:42 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-06-12 15:42 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-06-12 15:42 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-06-12 15:42 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-06-12 15:42 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-06-12 15:42 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2014-06-12 15:42 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-06-12 15:42 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-06-12 15:42 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2014-06-12 15:42 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2014-06-12 15:42 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-06-12 15:42 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-06-12 15:42 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-06-12 15:42 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-06-12 15:42 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-06-12 15:42 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-06-12 15:42 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-06-12 15:42 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-06-12 15:42 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-06-12 15:42 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2014-06-12 15:42 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-06-12 15:42 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-06-12 15:42 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-06-12 15:42 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-06-12 15:42 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-06-12 15:42 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-06-12 15:42 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-06-12 15:42 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-06-12 15:42 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll 2014-06-12 15:42 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll 2014-06-12 15:42 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys 2014-06-12 15:42 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS 2014-06-12 15:42 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll 2014-06-12 15:42 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll 2014-06-12 15:42 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll 2014-06-12 15:42 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll 2014-06-12 15:42 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll 2014-06-12 15:42 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll 2014-06-12 15:42 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll 2014-06-12 15:42 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll 2014-06-10 20:36 - 2014-06-10 20:36 - 00000000 __SHD () C:\Users\Sebastian\AppData\Local\EmieUserList 2014-06-10 20:36 - 2014-06-10 20:36 - 00000000 __SHD () C:\Users\Sebastian\AppData\Local\EmieSiteList 2014-06-08 16:43 - 2014-06-08 16:43 - 00000000 ____D () C:\Users\Sebastian\AppData\Local\PDF24 2014-06-08 16:41 - 2014-06-08 16:41 - 16311224 _____ (Geek Software GmbH ) C:\Users\Sebastian\Downloads\pdf24-creator-6.5.0.exe 2014-06-08 14:58 - 2014-06-08 15:22 - 00001578 _____ () C:\Users\Sebastian\Desktop\Karl_May.txt 2014-06-07 10:02 - 2014-06-07 10:02 - 00003190 _____ () C:\windows\System32\Tasks\{54A693F1-314E-4B96-8A6C-220FDD8C8C29} 2014-06-06 15:50 - 2014-06-06 15:50 - 00780704 _____ () C:\Users\Sebastian\Downloads\Player.exe 2014-06-04 22:18 - 2014-06-04 22:18 - 00668568 _____ () C:\Users\Sebastian\Downloads\Java.exe 2014-06-03 17:42 - 2014-06-03 17:42 - 00003860 _____ () C:\windows\System32\Tasks\Opera scheduled Autoupdate 1377950922 ==================== One Month Modified Files and Folders ======= 2014-06-30 21:13 - 2014-06-30 21:11 - 00022918 _____ () C:\Users\Sebastian\Desktop\FRST.txt 2014-06-30 21:11 - 2014-06-30 21:10 - 00000000 ____D () C:\FRST 2014-06-30 21:09 - 2009-07-14 06:45 - 00013936 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-30 21:09 - 2009-07-14 06:45 - 00013936 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-30 21:08 - 2014-06-30 21:08 - 02083328 _____ (Farbar) C:\Users\Sebastian\Desktop\FRST64.exe 2014-06-30 21:02 - 2014-06-30 19:57 - 00000143 _____ () C:\Users\Sebastian\Desktop\Trojaner-Board.txt 2014-06-30 20:49 - 2013-09-18 15:23 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-06-30 20:44 - 2011-01-17 17:15 - 00001116 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-30 20:04 - 2013-09-14 13:58 - 00000000 ____D () C:\ProgramData\Origin 2014-06-30 20:04 - 2013-09-14 13:58 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-06-30 19:38 - 2011-01-24 16:42 - 00000000 ____D () C:\Users\Sebastian\Textdokumente 2014-06-30 19:29 - 2014-06-22 09:20 - 00264451 _____ () C:\windows\WindowsUpdate.log 2014-06-30 19:23 - 2011-01-15 15:18 - 00000000 ____D () C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2014-06-30 19:22 - 2014-06-22 11:33 - 00002016 _____ () C:\windows\setupact.log 2014-06-30 19:22 - 2014-04-27 11:46 - 00000418 _____ () C:\windows\Tasks\Show-Password_wd.job 2014-06-30 19:22 - 2013-10-17 20:09 - 00001106 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore1cecb646eabf06.job 2014-06-30 19:22 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-06-30 15:26 - 2011-07-07 16:25 - 00000000 ____D () C:\Users\Sebastian\AppData\Local\CrashDumps 2014-06-29 19:17 - 2014-06-22 11:33 - 00001960 _____ () C:\windows\PFRO.log 2014-06-29 16:35 - 2014-06-29 14:33 - 00000000 ____D () C:\windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP 2014-06-29 16:29 - 2014-06-29 16:29 - 00000000 ____D () C:\Users\Sebastian\AppData\Roaming\SkypEmoticons 2014-06-29 16:29 - 2014-06-29 16:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SkypEmoticons 2014-06-29 16:29 - 2012-03-10 16:50 - 00000000 ____D () C:\ProgramData\InstallMate 2014-06-29 16:27 - 2014-06-29 16:27 - 00000000 ____D () C:\Program Files\Level Quality Watcher 2014-06-29 15:10 - 2011-01-15 17:44 - 00000000 ____D () C:\Users\Sebastian\AppData\Roaming\vlc 2014-06-29 14:35 - 2014-06-29 14:35 - 00000000 _____ () C:\autoexec.bat 2014-06-29 14:34 - 2014-06-29 14:34 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-06-29 14:14 - 2014-06-29 14:14 - 00000000 ____D () C:\Users\Sebastian\AppData\Roaming\TestApp 2014-06-29 14:14 - 2014-06-29 14:14 - 00000000 ____D () C:\ProgramData\PC Tools 2014-06-29 11:21 - 2013-11-22 10:41 - 00000000 ____D () C:\AdwCleaner 2014-06-29 07:24 - 2014-06-28 16:58 - 00000452 _____ () C:\Users\Sebastian\Desktop\Zed.txt 2014-06-28 13:56 - 2013-09-14 15:19 - 00000000 ____D () C:\Users\Sebastian\Documents\FIFA 13 2014-06-28 11:14 - 2014-06-14 22:52 - 00000728 _____ () C:\Users\Sebastian\Desktop\Avira.txt 2014-06-27 23:29 - 2014-06-27 23:28 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-27 23:28 - 2014-06-27 23:28 - 00000000 ____D () C:\Users\Sebastian\ Malwarebytes Anti-Malware 2014-06-27 23:28 - 2013-11-22 11:04 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-27 23:28 - 2011-01-15 15:18 - 00000000 ____D () C:\Users\Sebastian 2014-06-27 23:26 - 2014-06-27 23:25 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sebastian\Downloads\mbam-setup-2.0.2.1012.exe 2014-06-27 22:01 - 2011-02-04 22:40 - 00000000 ____D () C:\Users\Sebastian\Bridge Building Game 2014-06-27 15:55 - 2014-06-27 15:54 - 636661760 _____ () C:\Users\Sebastian\Desktop\Avira_Notfall_CD.iso 2014-06-27 15:46 - 2014-06-27 15:29 - 638438160 _____ (Avira GmbH) C:\Users\Sebastian\Downloads\rescue-system.exe 2014-06-27 15:34 - 2014-06-25 16:33 - 00000694 _____ () C:\Users\Sebastian\Desktop\Avira_Rescue_System.txt 2014-06-24 17:15 - 2009-07-14 07:08 - 00032632 _____ () C:\windows\Tasks\SCHEDLGU.TXT 2014-06-24 15:32 - 2014-06-15 11:24 - 00001654 _____ () C:\Users\Sebastian\Desktop\Avira_Answers_Frage.txt 2014-06-22 18:02 - 2011-02-13 19:28 - 00000000 ____D () C:\Users\Sebastian\AppData\Roaming\SoftGrid Client 2014-06-22 11:33 - 2014-06-22 11:33 - 00000000 _____ () C:\windows\setuperr.log 2014-06-22 11:32 - 2011-01-15 15:38 - 00001003 _____ () C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-06-22 09:24 - 2011-01-15 17:33 - 00000000 ____D () C:\Users\Sebastian\AppData\Roaming\DAEMON Tools Lite 2014-06-21 10:33 - 2011-03-24 21:58 - 00000000 ____D () C:\Users\Sebastian\D-Fend Reloaded 2014-06-21 10:18 - 2011-01-23 14:42 - 00000000 ____D () C:\Users\Sebastian\Spiele 2014-06-21 07:09 - 2011-01-16 01:28 - 00000000 ____D () C:\Users\Sebastian\Desktop\DivX 2014-06-20 16:11 - 2011-01-15 17:49 - 00000000 ____D () C:\Users\Sebastian\AppData\Roaming\ICQ 2014-06-20 15:36 - 2014-06-20 15:36 - 00001062 _____ () C:\Users\Public\Desktop\DivX Player.lnk 2014-06-20 15:36 - 2013-09-09 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX 2014-06-20 15:36 - 2011-01-16 01:23 - 00000000 ____D () C:\Program Files\DivX 2014-06-20 15:36 - 2011-01-16 01:20 - 00000000 ____D () C:\ProgramData\DivX 2014-06-20 15:36 - 2011-01-16 01:20 - 00000000 ____D () C:\Program Files (x86)\DivX 2014-06-19 16:36 - 2010-08-17 21:34 - 00700134 _____ () C:\windows\system32\perfh007.dat 2014-06-19 16:36 - 2010-08-17 21:34 - 00149984 _____ () C:\windows\system32\perfc007.dat 2014-06-19 16:36 - 2009-07-14 07:13 - 01622236 _____ () C:\windows\system32\PerfStringBackup.INI 2014-06-18 22:37 - 2014-04-27 19:54 - 00000000 ____D () C:\Users\Sebastian\Desktop\Neuer Ordner 2014-06-15 11:25 - 2014-06-15 11:08 - 00000151 _____ () C:\Users\Sebastian\Desktop\Avira_Answers.txt 2014-06-14 07:50 - 2014-06-14 07:46 - 00000000 ____D () C:\Users\Sebastian\AppData\Local\DownBooster 2014-06-14 07:50 - 2014-06-14 07:46 - 00000000 ____D () C:\Program Files (x86)\WinUpd 2014-06-13 21:03 - 2014-06-13 21:03 - 00000000 ____D () C:\Users\Sebastian\Documents\StreamTransport 2014-06-13 15:41 - 2014-06-13 15:41 - 00002428 _____ () C:\windows\SysWOW64\qtplugin.log 2014-06-13 15:41 - 2014-06-13 15:41 - 00001049 _____ () C:\Users\Sebastian\Desktop\QuickTime Player.lnk 2014-06-13 15:41 - 2014-06-13 15:41 - 00000000 ____D () C:\windows\SysWOW64\QuickTime 2014-06-13 15:41 - 2014-06-13 15:41 - 00000000 ____D () C:\ProgramData\QuickTime 2014-06-13 15:41 - 2014-06-13 15:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-06-13 15:41 - 2014-06-13 15:41 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-06-13 15:41 - 2014-06-13 15:41 - 00000000 _____ () C:\windows\SysWOW64\QuickTime.qtp 2014-06-13 15:31 - 2013-08-15 15:33 - 00000000 ____D () C:\windows\system32\MRT 2014-06-13 15:22 - 2011-01-16 13:01 - 95414520 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-06-11 16:39 - 2010-08-17 04:46 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-06-11 16:39 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-06-11 15:32 - 2011-01-15 18:08 - 00000000 ____D () C:\Users\Sebastian\Desktop\Internet 2014-06-10 20:42 - 2010-08-17 05:00 - 00000000 ____D () C:\ProgramData\Temp 2014-06-10 20:36 - 2014-06-10 20:36 - 00000000 __SHD () C:\Users\Sebastian\AppData\Local\EmieUserList 2014-06-10 20:36 - 2014-06-10 20:36 - 00000000 __SHD () C:\Users\Sebastian\AppData\Local\EmieSiteList 2014-06-08 16:43 - 2014-06-08 16:43 - 00000000 ____D () C:\Users\Sebastian\AppData\Local\PDF24 2014-06-08 16:41 - 2014-06-08 16:41 - 16311224 _____ (Geek Software GmbH ) C:\Users\Sebastian\Downloads\pdf24-creator-6.5.0.exe 2014-06-08 15:22 - 2014-06-08 14:58 - 00001578 _____ () C:\Users\Sebastian\Desktop\Karl_May.txt 2014-06-07 10:02 - 2014-06-07 10:02 - 00003190 _____ () C:\windows\System32\Tasks\{54A693F1-314E-4B96-8A6C-220FDD8C8C29} 2014-06-06 15:50 - 2014-06-06 15:50 - 00780704 _____ () C:\Users\Sebastian\Downloads\Player.exe 2014-06-04 22:18 - 2014-06-04 22:18 - 00668568 _____ () C:\Users\Sebastian\Downloads\Java.exe 2014-06-04 22:03 - 2012-12-22 17:57 - 00003360 _____ () C:\windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-76830181-1066914796-2057996457-1000 2014-06-04 22:03 - 2012-12-22 17:57 - 00003234 _____ () C:\windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-76830181-1066914796-2057996457-1000 2014-06-03 17:42 - 2014-06-03 17:42 - 00003860 _____ () C:\windows\System32\Tasks\Opera scheduled Autoupdate 1377950922 2014-06-03 17:42 - 2013-04-19 15:58 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-06-02 15:35 - 2014-05-28 15:14 - 00000130 _____ () C:\Users\Sebastian\Desktop\Atze_Schröder-Chemnitz.txt 2014-06-01 09:11 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\rescache 2014-06-01 08:29 - 2011-01-22 14:19 - 00000000 ____D () C:\Users\Sebastian\Desktop\Spiele 2014-05-31 22:41 - 2013-06-07 19:16 - 00000125 ___SH () C:\ProgramData\.zreglib 2014-05-31 10:25 - 2014-01-21 17:21 - 00000000 ____D () C:\Users\Sebastian\Documents\gothic3 ZeroAccess: C:\Windows\Installer\{3137ec37-8634-c619-3470-34d1b8cd37bc} C:\Windows\Installer\{3137ec37-8634-c619-3470-34d1b8cd37bc}\@ ZeroAccess: C:\Users\Sebastian\AppData\Local\{3137ec37-8634-c619-3470-34d1b8cd37bc} C:\Users\Sebastian\AppData\Local\{3137ec37-8634-c619-3470-34d1b8cd37bc}\@ Files to move or delete: ==================== C:\Users\Sebastian\Opera_1215_int_Setup.exe C:\Users\Sebastian\Setup_CM10_Rel_10_3.exe C:\Users\Sebastian\streamwriter_setup.exe C:\Users\Sebastian\Wolfenstein 3D (Full Version).exe Some content of TEMP: ==================== C:\Users\Sebastian\AppData\Local\Temp\avgnt.exe C:\Users\Sebastian\AppData\Local\Temp\Quarantine.exe C:\Users\Sebastian\AppData\Local\Temp\SHSetup.exe C:\Users\Sebastian\AppData\Local\Temp\sSetup-se.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-01 09:00 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-06-2014 02 Ran by Sebastian at 2014-06-30 21:14:03 Running from C:\Users\Sebastian\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== "Nero SoundTrax Help (x32 Version: 4.4.32.0 - Nero AG) Hidden Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.1.0.4880 - Adobe Systems Incorporated) Hidden Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Reader X (10.1.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated) Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.3.633 - Adobe Systems, Inc.) Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden Anno 1701 (HKLM-x32\...\{A2433A63-5F5D-40E5-B529-9123C2B3E734}) (Version: 1.02 - Sunflowers) Art Plus Download Assistant (HKLM-x32\...\Art Plus Download Assistant) (Version: 2.2.0.125 - Art Plus Marketing & Publishing) Atheros Client Installation Program (HKLM-x32\...\{D1434266-0486-4469-B338-A60082CC04E1}) (Version: 1.0.5.0621 - Atheros) ATI Catalyst Install Manager (HKLM\...\{5635224E-675C-B94C-43EE-70BCD39BF30B}) (Version: 3.0.782.0 - ATI Technologies, Inc.) Avidemux 2.5 (HKLM-x32\...\Avidemux 2.5) (Version: 2.5.4.6714 - ) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.672 - Avira) Avira SearchFree Toolbar (HKLM-x32\...\{41564952-412D-5637-00A7-A758B70C0A03}) (Version: 12.10.3.4489 - APN, LLC) AVS Update Manager 1.0 (HKLM-x32\...\AVS Update Manager_is1) (Version: - Online Media Technologies Ltd.) AVS4YOU Software Navigator 1.4 (HKLM-x32\...\AVS4YOU Software Navigator_is1) (Version: - Online Media Technologies Ltd.) BatteryLifeExtender (HKLM-x32\...\{E308B555-8434-4AF8-B66F-729897C75F93}) (Version: 1.0.6 - Samsung) Bonjour (HKLM-x32\...\{07287123-B8AC-41CE-8346-3D777245C35B}) (Version: 1.0.106 - Apple Inc.) Bridge Building Game (HKLM-x32\...\Bridge Building Game) (Version: - ) Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 5.60.48.44 - Broadcom Corporation) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0706.2128.36662 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0706.2128.36662 - ATI) Hidden Catalyst Control Center InstallProxy (x32 Version: 2010.0706.2128.36662 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2010.0706.2128.36662 - ATI) Hidden CCC Help Chinese Standard (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Chinese Traditional (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Czech (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Danish (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Dutch (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help English (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Finnish (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help French (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help German (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Greek (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Hungarian (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Italian (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Japanese (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Korean (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Norwegian (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Polish (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Portuguese (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Russian (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Spanish (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Swedish (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Thai (x32 Version: 2010.0706.2127.36662 - ATI) Hidden CCC Help Turkish (x32 Version: 2010.0706.2127.36662 - ATI) Hidden ccc-core-static (x32 Version: 2010.0706.2128.36662 - ATI) Hidden ccc-utility64 (Version: 2010.0706.2128.36662 - ATI) Hidden CCleaner (HKLM\...\CCleaner) (Version: 3.24 - Piriform) CloneDVD2 (HKLM-x32\...\CloneDVD2) (Version: 2.9.3.0 - Elaborate Bytes) CyberLink DVD Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 6.0.2806 - CyberLink Corp.) CyberLink DVD Suite (x32 Version: 6.0.2806 - CyberLink Corp.) Hidden CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1916 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.1916 - CyberLink Corp.) Hidden CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.3108a - CyberLink Corp.) CyberLink Power2Go (x32 Version: 6.0.3108a - CyberLink Corp.) Hidden CyberLink PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.3213 - CyberLink Corp.) CyberLink PowerDirector (x32 Version: 7.0.3213 - CyberLink Corp.) Hidden CyberLink PowerDVD 8 (HKLM-x32\...\InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}) (Version: 8.0.2815b - CyberLink Corp.) CyberLink PowerDVD 8 (x32 Version: 8.0.2815b - CyberLink Corp.) Hidden CyberLink PowerProducer (HKLM-x32\...\InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 5.0.1.1812 - CyberLink Corp.) CyberLink PowerProducer (x32 Version: 5.0.1.1812 - CyberLink Corp.) Hidden CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.0.3911 - CyberLink Corp.) CyberLink YouCam (x32 Version: 2.0.3911 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.45.1.0236 - DT Soft Ltd) Dart 'm Up (HKLM-x32\...\Dart 'm Up) (Version: - ) D-Fend Reloaded 1.1.0 (deinstallieren) (HKLM-x32\...\D-Fend Reloaded) (Version: 1.1.0 - Alexander Herzog) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.3.52 - DivX, LLC) DolbyFiles (x32 Version: 2.0 - Nero AG) Hidden DVD Shrink 3.2 deutsch (HKLM-x32\...\DVD Shrink DE_is1) (Version: - DVD Shrink) Easy Content Share (HKLM-x32\...\{2DDC70C1-C77A-4D08-89D2-9AB648504533}) (Version: 1.0 - Samsung Electronics Co., LTD) Easy Display Manager (HKLM-x32\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 3.2 - Samsung Electronics Co., Ltd.) Easy Network Manager (HKLM-x32\...\{559D1FDB-6D5C-4EF3-8F63-5E1E93A0A244}) (Version: 4.4.1 - Samsung) Easy SpeedUp Manager (HKLM-x32\...\{EF367AA4-070B-493C-9575-85BE59D789C9}) (Version: 2.1.0.15 - Samsung Electronics Co.,Ltd.) EasyBatteryManager (HKLM-x32\...\{4A331D24-A9E8-484F-835E-1BA7B139689C}) (Version: 4.0.0.4 - Samsung) EasyFileShare (HKLM-x32\...\{C4582EED-A3FB-4358-8F3F-8C994460DF28}) (Version: 1.0.3 - Samsung) EasyLife Gadget (HKLM\...\{ACE9FB2A-31A5-4285-9510-43F1636EAB21}) (Version: 1.0 - EasyLife Gadget) Empire Earth Ultimate Edition (HKLM-x32\...\{912CE296-3D73-4A9D-B3FB-70A5CF7A8568}) (Version: 1.0 - The Games Company) Feature Update Service (YFD) (HKCU\...\YourFileDownloaderUpdater) (Version: 2.14.21 - ) <==== ATTENTION FIFA 13 (HKLM-x32\...\{A29E18C2-7AB1-4b6b-848C-5D5E2C85F0C0}) (Version: 1.0.0.0 - Electronic Arts) Flatcast Viewer Plugin 5.3.0.784 (HKLM-x32\...\Flatcast Viewer 5.3_is1) (Version: - 1 mal 1 Software GmbH) FormatFactory 3.0.1 (HKLM-x32\...\FormatFactory) (Version: 3.0.1 - Free Time) Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Free YouTube Download version 3.2.20.1230 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.20.1230 - DVDVideoSoft Ltd.) Frieven_s_Prox_1.8 (HKLM-x32\...\Frieven_s_Prox_1.8) (Version: 1.34.5.29 - shift) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.25.0 - Google Inc.) Hidden Gothic 3 (HKLM-x32\...\{13F59927-CFBE-44D1-8417-7203AD4F1795}) (Version: 1.0.0 - JoWooD) ICQ7.7 (HKLM-x32\...\{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE}) (Version: 7.7 - ICQ) ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.3.1001 - Intel Corporation) Intel(R) Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.02.00.1002 - Intel Corporation) Java Auto Updater (x32 Version: 2.0.6.1 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 15 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216015F0}) (Version: 6.0.150 - Sun Microsystems, Inc.) Java(TM) 6 Update 20 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216020F0}) (Version: 6.0.200 - Sun Microsystems, Inc.) Java(TM) 6 Update 22 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216022F0}) (Version: 6.0.220 - Oracle) Java(TM) 6 Update 27 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216027F0}) (Version: 6.0.270 - Oracle) Java(TM) 6 Update 29 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416029FF}) (Version: 6.0.290 - Oracle) Java(TM) 6 Update 29 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216022FF}) (Version: 6.0.290 - Oracle) Junk Mail filter update (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Killer Sudoku 1.1.0 (HKLM-x32\...\Killer Sudoku_is1) (Version: 1.1.0 - Novel Games Limited) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Marvell Miniport Driver (HKLM-x32\...\Marvell Miniport Driver) (Version: 11.22.3.3 - Marvell) Media Buzz (HKLM-x32\...\MediaBuzzV1mode2726) (Version: 1.1 - Media Buzz) <==== ATTENTION Media_Play_AIR+_1.1 (HKLM-x32\...\Media_Play_AIR+_1.1) (Version: 1.34.5.29 - enter) <==== ATTENTION Meiern (HKLM-x32\...\ST6UNST #1) (Version: - ) Menu Templates - Starter Kit (x32 Version: 9.4.6.0 - Nero AG) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1 - Nokia) Hidden Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1 - Nokia) Hidden Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Movie Templates - Starter Kit (x32 Version: 9.4.6.0 - Nero AG) Hidden MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nero 9 (HKLM-x32\...\{02993877-0006-40d9-b5c8-de73bfd4b37d}) (Version: - Nero AG) Nero Burning ROM Help (x32 Version: 9.4.17.100 - Nero AG) Hidden Nero BurnRights (x32 Version: 3.4.11.100 - Nero AG) Hidden Nero BurnRights Help (x32 Version: 3.4.4.100 - Nero AG) Hidden Nero ControlCenter (x32 Version: 9.0.0.1 - Nero AG) Hidden Nero CoverDesigner (x32 Version: 4.4.9.100 - Nero AG) Hidden Nero CoverDesigner Help (x32 Version: 4.4.9.100 - Nero AG) Hidden Nero Disc Copy Gadget (x32 Version: 2.4.22.0 - Nero AG) Hidden Nero Disc Copy Gadget Help (x32 Version: 2.4.22.0 - Nero AG) Hidden Nero DiscSpeed (x32 Version: 5.4.12.100 - Nero AG) Hidden Nero DiscSpeed Help (x32 Version: 5.4.4.100 - Nero AG) Hidden Nero DriveSpeed (x32 Version: 4.4.11.100 - Nero AG) Hidden Nero DriveSpeed Help (x32 Version: 4.4.4.100 - Nero AG) Hidden Nero Express Help (x32 Version: 9.4.17.100 - Nero AG) Hidden Nero InfoTool (x32 Version: 6.4.11.100 - Nero AG) Hidden Nero InfoTool Help (x32 Version: 6.4.4.100 - Nero AG) Hidden Nero Installer (x32 Version: 4.4.9.0 - Nero AG) Hidden Nero Live (x32 Version: 1.4.48.0 - Nero AG) Hidden Nero Live Help (x32 Version: 1.4.48.0 - Nero AG) Hidden Nero PhotoSnap (x32 Version: 1.53.2.0 - Nero AG) Hidden Nero PhotoSnap Help (x32 Version: 1.53.2.0 - Nero AG) Hidden Nero Recode (x32 Version: 4.4.31.0 - Nero AG) Hidden Nero Recode Help (x32 Version: 4.4.31.0 - Nero AG) Hidden Nero Rescue Agent (x32 Version: 2.4.12.100 - Nero AG) Hidden Nero RescueAgent Help (x32 Version: 2.4.4.100 - Nero AG) Hidden Nero ShowTime (x32 Version: 5.4.0.100 - Nero AG) Hidden Nero ShowTime (x32 Version: 5.4.14.100 - Nero AG) Hidden Nero StartSmart (x32 Version: 9.4.12.100 - Nero AG) Hidden Nero StartSmart Help (x32 Version: 9.4.12.100 - Nero AG) Hidden Nero Vision (x32 Version: 6.4.10.205 - Nero AG) Hidden Nero Vision Help (x32 Version: 6.4.8.100 - Nero AG) Hidden Nero WaveEditor (x32 Version: 5.4.32.0 - Nero AG) Hidden NeroBurningROM (x32 Version: 9.4.17.100 - Nero AG) Hidden NeroExpress (x32 Version: 9.4.17.100 - Nero AG) Hidden NeroLiveGadget (x32 Version: 1.2.16.100 - Nero AG) Hidden NeroLiveGadget Help (x32 Version: 1.2.16.100 - Nero AG) Hidden neroxml (x32 Version: 1.0.0 - Nero AG) Hidden Nokia Connectivity Cable Driver (HKLM-x32\...\{29373274-977E-413C-A4DE-DC0F8E80C429}) (Version: 7.1.172.0 - Nokia) Nokia Suite (HKLM-x32\...\Nokia Suite) (Version: 3.8.48.0 - Nokia) Nokia Suite (x32 Version: 3.8.48.0 - Nokia) Hidden NVIDIA PhysX (HKLM-x32\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) Opera Stable 22.0.1471.50 (HKLM-x32\...\Opera 22.0.1471.50) (Version: 22.0.1471.50 - Opera Software ASA) Origin (HKLM-x32\...\Origin) (Version: 9.0.10.69 - Electronic Arts, Inc.) OSA Kit Pro Player v4.0 1.0 (HKLM-x32\...\OSA Kit Pro Player) (Version: 1.0 - Maher F. Farag) PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia) pdfforge Toolbar v7.3 (HKLM-x32\...\{D0F1CFB6-090B-45B6-86B9-20C72CD9B261}) (Version: 7.3 - Spigot, Inc.) <==== ATTENTION pgcchelper (HKCU\...\pgcchelper) (Version: - ) Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden PlusSHD9.5v4 (HKLM-x32\...\PlusSHD9.5v4) (Version: 1.34.4.10 - HDSplus) Protect Disc License Helper 1.0.118 (HKLM-x32\...\Protect Disc License Helper) (Version: 1.0.118 - Protect Disc) ProtectDisc Driver, Version 11 (HKLM-x32\...\ProtectDisc Driver 11) (Version: 11.0.0.11 - ProtectDisc Software GmbH) QuickTime (HKLM-x32\...\QuickTime) (Version: - ) RealDownloader (x32 Version: 1.3.2 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.2 - RealNetworks) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6156 - Realtek Semiconductor Corp.) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden RTPatch Update (HKLM-x32\...\RTPatch_is1) (Version: - PocketSoft) Samsung Recovery Solution 4 (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 4.0.0.6 - Samsung) Samsung Support Center (HKLM-x32\...\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.18 - Samsung) Samsung Update Plus (HKLM-x32\...\{D3F2FAA5-FEC4-42AA-9ABA-1F763919A2B5}) (Version: 2.0 - Samsung Electronics Co., Ltd.) Shockwave (HKLM-x32\...\Shockwave) (Version: - ) Show-Password (HKLM-x32\...\5D1501F7-2DC8-BEE0-61A4-310079B9BA15) (Version: - Show-Password-software) <==== ATTENTION Sierra Utilities (HKLM-x32\...\Sierra Utilities) (Version: - ) Sierra-Dienstprogramme (HKLM-x32\...\Sierra-Dienstprogramme) (Version: - ) Skype Toolbars (HKLM-x32\...\{981029E0-7FC9-4CF3-AB39-6F133621921A}) (Version: 1.0.4051 - Skype Technologies S.A.) SkypEmoticons (HKLM-x32\...\SkypEmoticons_is1) (Version: - ) <==== ATTENTION Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) SopCast 3.4.7 (HKLM-x32\...\SopCast) (Version: 3.4.7 - www.sopcast.com) SoundTrax (x32 Version: 4.4.32.0 - Nero AG) Hidden Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.) SRS Premium Sound Control Panel (HKLM\...\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}) (Version: 1.8.7300 - SRS Labs, Inc.) streamWriter (HKLM-x32\...\streamWriter_is1) (Version: - ) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.22.0 - Synaptics Incorporated) Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Updater (HKLM-x32\...\{D54E3D9F-FEB8-4D2D-A138-B69A5C80080B}) (Version: 2.6.53 - Creative Island Media, LLC) <==== ATTENTION User Guide (HKLM-x32\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.0 - ) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player 2.0.5 (HKLM-x32\...\VLC media player) (Version: 2.0.5 - VideoLAN) VLC media player 2.0.7 (HKLM\...\VLC media player) (Version: 2.0.7 - VideoLAN) WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.5100 - Broadcom Corporation) WinAce Archiver (HKLM-x32\...\WinAce Archiver) (Version: 2.69 - e-merge GmbH) Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Family Safety (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Sync (HKLM-x32\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation) Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia) WinRAR (HKLM\...\WinRAR archiver) (Version: - ) Zip Motion Block Video codec (Remove Only) (HKLM-x32\...\ZMBV) (Version: - DOSBox Team) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {000FBB24-423C-4258-9812-997BA41B4A6C} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-76830181-1066914796-2057996457-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {008BFDDD-F653-449F-A295-DF9C5CEB2737} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-76830181-1066914796-2057996457-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {083989C6-BB97-44BF-B38F-D768AD8264CE} - System32\Tasks\{0C3494A2-2168-4C01-BE40-2E45C34F2F68} => E:\SETUP.EXE [1996-07-20] (Transpeed) Task: {097AD253-753B-4F3F-8360-D7E58A032638} - \FTdownloader V4.0-updater No Task File <==== ATTENTION Task: {0A265031-5DBB-4FBC-98D2-72F397E5C507} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2010-07-12] (Samsung Electronics. Co. Ltd.) Task: {0CD42F13-E7D4-4583-B9D7-D19718A20BED} - System32\Tasks\{F05EA7C7-4B48-4B3E-A244-AB41A253EA50} => E:\SETUP.EXE [1996-07-20] (Transpeed) Task: {16BC4C94-0DD9-4BA3-B791-60A42F6F8BB8} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {22A490C3-90E9-4CF5-81AE-BE0D9AD41F4A} - System32\Tasks\Go for FilesUpdate => C:\Program Files (x86)\GoforFiles\GFFUpdater.exe <==== ATTENTION Task: {23F71B8D-9561-4E78-AA13-9A79D61C9865} - \AmiUpdXp No Task File <==== ATTENTION Task: {2B3F59A9-ED63-4165-ADBF-DED21D14A7EE} - System32\Tasks\Games\UpdateCheck_S-1-5-21-76830181-1066914796-2057996457-1000 Task: {361731F4-7081-4028-8825-4A7D0F923602} - System32\Tasks\AdobeFlashPlayerUpdate 2 => C:\windows\SysWOW64\FlashPlayerUpdateService.exe Task: {3B031D6F-3239-4953-9F11-3B2FA2ED10CE} - System32\Tasks\{657705BB-20E5-481B-BBD6-BE409E9019A9} => E:\SETUP.EXE [1996-07-20] (Transpeed) Task: {3B76D6E2-5641-41C8-927B-AF5E0BB78EFC} - \DealPlyLiveUpdateTaskMachineUA No Task File <==== ATTENTION Task: {3B8A85F1-0385-4D91-A2A6-E58D7F8B892D} - \Mext Guard FBE8818C-5B13-48C2-A93E-AD731167DBF2 No Task File <==== ATTENTION Task: {3F4618EA-0462-4FF0-B3E4-A93693E8CFE7} - \144899d5-d17f-48f2-9759-c73aad165301-4 No Task File <==== ATTENTION Task: {4186E796-589D-4723-9490-CEDF7C71AC00} - System32\Tasks\{868B76A8-1604-431B-ACB3-09B751F36517} => E:\SETUP.EXE [1996-07-20] (Transpeed) Task: {41FE0453-421E-42FF-A01A-FB89E5FE28F4} - System32\Tasks\{985DE0F0-D498-4CB8-A1B2-E509911529C0} => E:\SETUP.EXE [1996-07-20] (Transpeed) Task: {4AE47D1F-0AA4-41FC-A401-4C32DF25DE1F} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager2.exe [2010-08-05] (Samsung Electronics) Task: {4DE1323B-B08D-4C41-AEAF-822C371C866E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {4F8B6533-566A-4424-BF7C-F06FDFD3A4E9} - System32\Tasks\Opera scheduled Autoupdate 1377950922 => C:\Program Files (x86)\Opera\launcher.exe [2014-05-27] (Opera Software) Task: {55DB4EFA-F2AE-4829-8F5D-6386040DC015} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [2010-08-05] (Samsung Electronics Co., Ltd.) Task: {5A4D13D3-705D-4042-81C8-6E0CBA21C730} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2010-07-20] (SAMSUNG Electronics co., LTD.) Task: {5A6C79DD-8ACA-4274-BAA0-D62FA542975A} - System32\Tasks\Show-Password_wd => C:\Program Files (x86)\Show-Password-soft\Show-Passwordd.exe [2014-04-27] () <==== ATTENTION Task: {5CC210B7-3A50-442C-809D-21A1290179A2} - \GoforFilesUpdate No Task File <==== ATTENTION Task: {67F9468E-29DA-43F0-93B7-07C1886F8BFE} - System32\Tasks\{A7F52898-E540-4631-9BE8-E0A9F5B7DA8A} => E:\SETUP.EXE [1996-07-20] (Transpeed) Task: {6A4D02F2-C63D-4F19-880C-289FE78BD508} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {6F55A953-3F22-44F1-AB5F-74CFEC963B9C} - System32\Tasks\{8432FC74-5CA1-4DF0-85D7-AA7921E57D19} => E:\SETUP.EXE [1996-07-20] (Transpeed) Task: {70AD28FB-6A14-4312-A373-895F49C3E7F6} - \EPUpdater No Task File <==== ATTENTION Task: {74109A32-0B08-4A0E-8C0B-6EA2F8E8B1C8} - System32\Tasks\{DA06645A-E904-45EE-B721-C75D59EA5DCC} => E:\SETUP.EXE [1996-07-20] (Transpeed) Task: {7D7DF77F-76C9-4037-9E58-7EF28EFDF944} - System32\Tasks\{3F559BE1-83A6-43AF-BF69-3C1341D8BD3F} => E:\SETUP.NOW.EXE Task: {7E6C67FB-2512-4CE7-BC4F-214908C9AA63} - System32\Tasks\{49A51809-1B26-4BB5-8B91-24F7C752DCF0} => E:\SETUP.EXE [1996-07-20] (Transpeed) Task: {7EED7FB4-B7B6-4641-9A4C-BFB82D74301F} - System32\Tasks\{ACBC5723-4421-4502-A890-0383123C24C5} => E:\SETUP.EXE [1996-07-20] (Transpeed) Task: {7FFD7BCF-9565-433F-91F8-4DE4B6FC20E1} - \BrowserDefendert No Task File <==== ATTENTION Task: {81667E4A-99D5-4C70-9A11-9328E7463B0A} - \dab3e7f2-3183-49ea-9c57-b856ed7be1c1-4 No Task File <==== ATTENTION Task: {81706C4A-3EEC-4BF9-8F0B-E4BB23FDA788} - \FTdownloader V4.0-codedownloader No Task File <==== ATTENTION Task: {8F06D40B-14B6-4544-996E-C1E5F1D525BE} - System32\Tasks\{46363280-0C93-4162-BA84-C1800DE6E106} => C:\Users\Sebastian\D-Fend Reloaded\VirtualHD\KEEPER\DOS4GW.EXE [2011-03-25] () Task: {90D12D95-1F07-4A0C-B6A0-E1D6ABF18029} - \FF Watcher {CEEEE79E-5163-41C5-BB70-2ED25D849F40} No Task File <==== ATTENTION Task: {94C9AE4E-6109-4A72-AE30-10D2DA46EC45} - \Advanced System Protector_startup No Task File <==== ATTENTION Task: {97010ECF-03B6-4179-B8D1-1723C4C66427} - \144899d5-d17f-48f2-9759-c73aad165301-5 No Task File <==== ATTENTION Task: {9843C4FD-136A-4F01-8CA6-725655D6D434} - \dab3e7f2-3183-49ea-9c57-b856ed7be1c1-3 No Task File <==== ATTENTION Task: {A466853E-3E7C-4072-9096-5AC7E6EF5AD3} - \144899d5-d17f-48f2-9759-c73aad165301-1 No Task File <==== ATTENTION Task: {A5FD8137-7899-402C-AE57-F509D0C80F24} - System32\Tasks\{C41693B4-6238-4DF6-A5BF-477D5481953E} => E:\INSTALL.EXE [1996-07-24] () Task: {A9C51BDB-93F6-4DEA-9F42-54AEB32A3F1D} - \56069f09-0072-4e8d-acae-894052cbe8fd-5 No Task File <==== ATTENTION Task: {A9D6893C-E422-4726-9AF9-213B028554D8} - System32\Tasks\{EB4AD1E4-C24F-459D-BE00-B37693AF8815} => C:\Users\Sebastian\D-Fend Reloaded\VirtualHD\KEEPER\DOS4GW.EXE [2011-03-25] () Task: {ACE0ED67-F396-42E5-9F0E-15CA294C307A} - \DealPlyLiveUpdateTaskMachineCore No Task File <==== ATTENTION Task: {AD32453B-3F4E-41DF-A34D-BD1C0A70C56D} - System32\Tasks\{456230FE-9F87-4040-82B4-5E0405800C5A} => E:\SETUP.EXE [1996-07-20] (Transpeed) Task: {B0B56F85-3012-47E7-AB0A-39A39337A70E} - \144899d5-d17f-48f2-9759-c73aad165301-3 No Task File <==== ATTENTION Task: {B0D847BC-6886-4676-9D95-BC594A9E4736} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION Task: {B3059A2E-615E-4E21-B270-D01978483984} - System32\Tasks\advSRS4 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2010-01-19] (SEC) Task: {B625C507-EDB9-4104-8CE9-F242D6DABD8A} - \FTdownloader V4.0-enabler No Task File <==== ATTENTION Task: {B8C8E55D-3B26-47A8-A4D1-CBBF6FD47CC0} - System32\Tasks\{3504ED92-9C34-4043-A3C4-C595D87C4EAE} => E:\SETUP.EXE [1996-07-20] (Transpeed) Task: {BDEB32E8-6C4A-475C-BAAE-F91B1476FB98} - \Show-Password Update No Task File <==== ATTENTION Task: {BFF99860-4956-436A-83CB-C99FD9A1BDE4} - System32\Tasks\GoogleUpdateTaskMachineCore1cecb646eabf06 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {C496FFDE-63EE-418F-B346-0C1414B93704} - \144899d5-d17f-48f2-9759-c73aad165301-2 No Task File <==== ATTENTION Task: {C89D5894-AA4B-4C8B-9369-9D5A48F570A7} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-76830181-1066914796-2057996457-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {C94BA303-5A76-45FE-A089-C762FF3BCA5E} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe Task: {D3FA1EB9-41FE-4666-9630-D22301870DDF} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe [2010-07-30] (SAMSUNG Electronics) Task: {D45A97AD-D2B1-4489-B0A1-279321653444} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION Task: {E3F03C90-5DAB-4F45-99CC-CDB97F8B8576} - \6c0e75e6-f53f-4d19-b513-977d38468083-4 No Task File <==== ATTENTION Task: {E629E160-85A9-42B3-8B03-FD7520B247D8} - System32\Tasks\AdobeFlashPlayerUpdate => C:\windows\SysWOW64\FlashPlayerUpdateService.exe Task: {E89E6DF4-976D-42F4-A52C-561D7131468B} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {E95DE261-32A7-4966-BADB-0EABFF128AFF} - \4c67f1a3-05c6-4d3a-b075-815a13101fc2-5 No Task File <==== ATTENTION Task: {EB2D0D37-3214-4721-B21C-DCF04D14968A} - System32\Tasks\{3AEA7388-306B-4BBC-8D4F-23DEA40980D5} => C:\Users\Sebastian\D-Fend Reloaded\VirtualHD\KEEPER\DOS4GW.EXE [2011-03-25] () Task: {ECD9C209-F434-421B-8449-B9984E498D22} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-22] (Adobe Systems Incorporated) Task: {F6F84538-9AA1-4B79-B380-8E7C245A2D3C} - \Desk 365 RunAsStdUser No Task File <==== ATTENTION Task: {FD1B3EBA-EFC8-4124-9EAD-5EEA92AA4577} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-76830181-1066914796-2057996457-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {FE2CEFC2-35E0-48D8-BAB4-EFA59A7DDEFA} - \YourFile DownloaderUpdate No Task File <==== ATTENTION Task: {FE9EA747-FF82-4B0B-85EB-A086087EF43A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1cecb646eabf06.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-76830181-1066914796-2057996457-1000.job => C:\Program Files (x86)\Real\RealUpgrade\realupgrade.exe Task: C:\windows\Tasks\Show-Password_wd.job => C:\Program Files (x86)\Show-Password-soft\Show-Passwordd.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2011-07-12 18:15 - 2011-07-12 18:15 - 00018432 _____ () C:\Users\Sebastian\AppData\LocalLow\QuickTime\IE\QuickTimeUpdater.exe 2013-04-16 03:07 - 2013-04-16 03:07 - 00039056 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe 2010-08-17 05:05 - 2009-07-07 20:23 - 00247152 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe 2014-04-27 11:44 - 2014-04-27 11:44 - 00077312 _____ () C:\Program Files (x86)\Show-Password-soft\Show-Passwordd.exe 2011-01-21 17:58 - 2010-03-15 12:28 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll 2014-01-10 07:26 - 2014-01-10 07:26 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 2014-04-27 11:44 - 2014-04-27 11:44 - 00143872 _____ () C:\Program Files (x86)\Show-Password-soft\Show-Passwordnm161.exe 2013-08-31 07:47 - 2013-08-31 07:47 - 03233806 _____ () C:\Program Files (x86)\Tor\tor.exe 2014-06-14 07:46 - 2014-05-14 14:38 - 00059904 _____ () C:\Program Files (x86)\WinUpd\WinUpd.exe 2009-02-12 07:32 - 2009-02-12 07:32 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2010-07-06 14:26 - 2010-07-06 14:26 - 00270336 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2014-01-10 07:28 - 2014-01-10 07:28 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2014-03-11 22:41 - 2013-05-16 11:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2014-03-11 22:41 - 2013-05-16 11:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2010-08-17 05:10 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll 2014-04-27 11:44 - 2014-04-27 11:44 - 00133120 _____ () C:\Program Files (x86)\Show-Password-soft\Show-Passwordnm161.dll 2014-03-11 22:41 - 2013-05-16 11:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2009-06-03 13:59 - 2009-06-03 13:59 - 00619816 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2009-06-03 13:59 - 2009-06-03 13:59 - 00013096 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2014-01-30 16:38 - 2014-06-28 11:24 - 00962560 _____ () C:\Program Files (x86)\Origin\platforms\qwindows.dll 2014-01-30 16:38 - 2014-06-28 11:24 - 00024064 _____ () C:\Program Files (x86)\Origin\imageformats\qgif.dll 2014-01-30 16:38 - 2014-06-28 11:24 - 00025088 _____ () C:\Program Files (x86)\Origin\imageformats\qico.dll 2014-01-30 16:38 - 2014-06-28 11:24 - 00217088 _____ () C:\Program Files (x86)\Origin\imageformats\qjpeg.dll 2014-01-30 16:38 - 2014-06-28 11:24 - 00261632 _____ () C:\Program Files (x86)\Origin\imageformats\qmng.dll 2014-01-30 16:38 - 2014-06-28 11:24 - 00019968 _____ () C:\Program Files (x86)\Origin\imageformats\qtga.dll 2014-01-30 16:38 - 2014-06-28 11:24 - 00302592 _____ () C:\Program Files (x86)\Origin\imageformats\qtiff.dll 2014-01-30 16:38 - 2014-06-28 11:24 - 00018944 _____ () C:\Program Files (x86)\Origin\imageformats\qwbmp.dll 2014-06-03 17:41 - 2014-06-03 17:37 - 00877176 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\libglesv2.dll 2014-06-03 17:41 - 2014-06-03 17:37 - 00135800 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\libegl.dll 2014-06-03 17:41 - 2014-06-03 17:37 - 00957048 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\ffmpegsumo.dll 2014-05-14 15:49 - 2014-05-14 15:49 - 16361136 _____ () C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Sebastian:zylomtest AlternateDataStreams: C:\Users\Sebastian:zylomtr{000HQ7FF-AD7A-3FG3-VK8A-25GG67KOIVUV} AlternateDataStreams: C:\ProgramData\Temp:0F4A7B6A AlternateDataStreams: C:\ProgramData\Temp:2430E4FC AlternateDataStreams: C:\ProgramData\Temp:264B2CC4 AlternateDataStreams: C:\ProgramData\Temp:373E1720 AlternateDataStreams: C:\ProgramData\Temp:4CF61E54 AlternateDataStreams: C:\ProgramData\Temp:5C270C64 AlternateDataStreams: C:\ProgramData\Temp:6FB93194 AlternateDataStreams: C:\ProgramData\Temp:8530A643 AlternateDataStreams: C:\ProgramData\Temp:8AD1F2E0 AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1 AlternateDataStreams: C:\ProgramData\Temp:EB42AC3C AlternateDataStreams: C:\Users\Sebastian\Downloads:Shareaza.GUID ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= MSCONFIG\Services: wuauserv => 2 MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" ==================== Faulty Device Manager Devices ============= Name: Microsoft-ISATAP-Adapter Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-ISATAP-Adapter #5 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (06/30/2014 03:26:20 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: avshadow.exe, Version: 14.0.4.642, Zeitstempel: 0x536c9660 Name des fehlerhaften Moduls: avshadow.exe, Version: 14.0.4.642, Zeitstempel: 0x536c9660 Ausnahmecode: 0xc0000409 Fehleroffset: 0x000000000001370e ID des fehlerhaften Prozesses: 0x5c0 Startzeit der fehlerhaften Anwendung: 0xavshadow.exe0 Pfad der fehlerhaften Anwendung: avshadow.exe1 Pfad des fehlerhaften Moduls: avshadow.exe2 Berichtskennung: avshadow.exe3 Error: (06/29/2014 08:12:53 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm opera.exe, Version 22.0.1471.50 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1350 Startzeit: 01cf93c43e796fc8 Endzeit: 7 Anwendungspfad: C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe Berichts-ID: faaa5d5b-ffb8-11e3-b800-001bb16640c8 Error: (06/29/2014 07:25:06 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: opera.exe, Version: 22.0.1471.50, Zeitstempel: 0x53845c2c Name des fehlerhaften Moduls: opera.exe, Version: 22.0.1471.50, Zeitstempel: 0x53845c2c Ausnahmecode: 0xc000041d Fehleroffset: 0x00642534 ID des fehlerhaften Prozesses: 0x1294 Startzeit der fehlerhaften Anwendung: 0xopera.exe0 Pfad der fehlerhaften Anwendung: opera.exe1 Pfad des fehlerhaften Moduls: opera.exe2 Berichtskennung: opera.exe3 Error: (06/29/2014 07:24:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: opera.exe, Version: 22.0.1471.50, Zeitstempel: 0x53845c2c Name des fehlerhaften Moduls: opera.exe, Version: 22.0.1471.50, Zeitstempel: 0x53845c2c Ausnahmecode: 0xc0000005 Fehleroffset: 0x00642534 ID des fehlerhaften Prozesses: 0x1294 Startzeit der fehlerhaften Anwendung: 0xopera.exe0 Pfad der fehlerhaften Anwendung: opera.exe1 Pfad des fehlerhaften Moduls: opera.exe2 Berichtskennung: opera.exe3 Error: (06/27/2014 06:35:04 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: opera.exe, Version: 22.0.1471.50, Zeitstempel: 0x53845c2c Name des fehlerhaften Moduls: opera.exe, Version: 22.0.1471.50, Zeitstempel: 0x53845c2c Ausnahmecode: 0xc000041d Fehleroffset: 0x00642534 ID des fehlerhaften Prozesses: 0x10e0 Startzeit der fehlerhaften Anwendung: 0xopera.exe0 Pfad der fehlerhaften Anwendung: opera.exe1 Pfad des fehlerhaften Moduls: opera.exe2 Berichtskennung: opera.exe3 Error: (06/27/2014 06:34:54 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: opera.exe, Version: 22.0.1471.50, Zeitstempel: 0x53845c2c Name des fehlerhaften Moduls: opera.exe, Version: 22.0.1471.50, Zeitstempel: 0x53845c2c Ausnahmecode: 0xc0000005 Fehleroffset: 0x00642534 ID des fehlerhaften Prozesses: 0x10e0 Startzeit der fehlerhaften Anwendung: 0xopera.exe0 Pfad der fehlerhaften Anwendung: opera.exe1 Pfad des fehlerhaften Moduls: opera.exe2 Berichtskennung: opera.exe3 Error: (06/24/2014 05:11:10 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: avshadow.exe, Version: 14.0.4.642, Zeitstempel: 0x536c9660 Name des fehlerhaften Moduls: avshadow.exe, Version: 14.0.4.642, Zeitstempel: 0x536c9660 Ausnahmecode: 0xc0000409 Fehleroffset: 0x000000000001370e ID des fehlerhaften Prozesses: 0x58c Startzeit der fehlerhaften Anwendung: 0xavshadow.exe0 Pfad der fehlerhaften Anwendung: avshadow.exe1 Pfad des fehlerhaften Moduls: avshadow.exe2 Berichtskennung: avshadow.exe3 Error: (06/24/2014 04:54:47 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: avshadow.exe, Version: 14.0.4.642, Zeitstempel: 0x536c9660 Name des fehlerhaften Moduls: avshadow.exe, Version: 14.0.4.642, Zeitstempel: 0x536c9660 Ausnahmecode: 0xc0000409 Fehleroffset: 0x000000000001370e ID des fehlerhaften Prozesses: 0x4d4 Startzeit der fehlerhaften Anwendung: 0xavshadow.exe0 Pfad der fehlerhaften Anwendung: avshadow.exe1 Pfad des fehlerhaften Moduls: avshadow.exe2 Berichtskennung: avshadow.exe3 Error: (06/24/2014 04:28:41 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: avshadow.exe, Version: 14.0.4.642, Zeitstempel: 0x536c9660 Name des fehlerhaften Moduls: avshadow.exe, Version: 14.0.4.642, Zeitstempel: 0x536c9660 Ausnahmecode: 0xc0000409 Fehleroffset: 0x000000000001370e ID des fehlerhaften Prozesses: 0x5b8 Startzeit der fehlerhaften Anwendung: 0xavshadow.exe0 Pfad der fehlerhaften Anwendung: avshadow.exe1 Pfad des fehlerhaften Moduls: avshadow.exe2 Berichtskennung: avshadow.exe3 Error: (06/22/2014 05:21:31 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm fifa13.exe, Version 1.1.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1204 Startzeit: 01cf8e2d5ae59534 Endzeit: 45 Anwendungspfad: C:\Program Files (x86)\Origin Games\FIFA 13\Game\fifa13.exe Berichts-ID: System errors: ============= Error: (06/30/2014 07:26:07 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2147024891 Error: (06/30/2014 07:26:07 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde mit folgendem Fehler beendet: %%-2147024891 Error: (06/30/2014 07:25:30 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "WinUpd" wurde nicht richtig gestartet. Error: (06/30/2014 07:23:11 PM) (Source: Service Control Manager) (EventID: 7003) (User: ) Description: Der Dienst "Spybot-S&D 2 Security Center Service" ist von folgendem Dienst abhängig: wscsvc. Dieser Dienst ist eventuell nicht installiert. Error: (06/30/2014 07:23:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (06/30/2014 07:23:11 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht. Error: (06/30/2014 07:22:41 PM) (Source: Service Control Manager) (EventID: 7003) (User: ) Description: Der Dienst "IPsec-Richtlinien-Agent" ist von folgendem Dienst abhängig: BFE. Dieser Dienst ist eventuell nicht installiert. Error: (06/30/2014 07:22:37 PM) (Source: Service Control Manager) (EventID: 7003) (User: ) Description: Der Dienst "IKE- und AuthIP IPsec-Schlüsselerstellungsmodule" ist von folgendem Dienst abhängig: BFE. Dieser Dienst ist eventuell nicht installiert. Error: (06/30/2014 07:22:36 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Computerbrowser" wurde mit folgendem Fehler beendet: %%1060 Error: (06/30/2014 03:50:04 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2147024891 Microsoft Office Sessions: ========================= Error: (06/30/2014 03:26:20 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: avshadow.exe14.0.4.642536c9660avshadow.exe14.0.4.642536c9660c0000409000000000001370e5c001cf9466d81d6e2dC:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exeC:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe1ecc8e76-005a-11e4-a314-827c6b745308 Error: (06/29/2014 08:12:53 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: opera.exe22.0.1471.50135001cf93c43e796fc87C:\Program Files (x86)\Opera\22.0.1471.50\opera.exefaaa5d5b-ffb8-11e3-b800-001bb16640c8 Error: (06/29/2014 07:25:06 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: opera.exe22.0.1471.5053845c2copera.exe22.0.1471.5053845c2cc000041d00642534129401cf93be87b9ec48C:\Program Files (x86)\Opera\22.0.1471.50\opera.exeC:\Program Files (x86)\Opera\22.0.1471.50\opera.exe4fd621f9-ffb2-11e3-b654-001bb16640c8 Error: (06/29/2014 07:24:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: opera.exe22.0.1471.5053845c2copera.exe22.0.1471.5053845c2cc000000500642534129401cf93be87b9ec48C:\Program Files (x86)\Opera\22.0.1471.50\opera.exeC:\Program Files (x86)\Opera\22.0.1471.50\opera.exe418ed554-ffb2-11e3-b654-001bb16640c8 Error: (06/27/2014 06:35:04 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: opera.exe22.0.1471.5053845c2copera.exe22.0.1471.5053845c2cc000041d0064253410e001cf92239d819702C:\Program Files (x86)\Opera\22.0.1471.50\opera.exeC:\Program Files (x86)\Opera\22.0.1471.50\opera.exefd597439-fe18-11e3-9412-001bb16640c8 Error: (06/27/2014 06:34:54 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: opera.exe22.0.1471.5053845c2copera.exe22.0.1471.5053845c2cc00000050064253410e001cf92239d819702C:\Program Files (x86)\Opera\22.0.1471.50\opera.exeC:\Program Files (x86)\Opera\22.0.1471.50\opera.exef79bf2d4-fe18-11e3-9412-001bb16640c8 Error: (06/24/2014 05:11:10 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: avshadow.exe14.0.4.642536c9660avshadow.exe14.0.4.642536c9660c0000409000000000001370e58c01cf8fbe7f0d0047C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exeC:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exec5c344b1-fbb1-11e3-a0a9-afdadf43bb17 Error: (06/24/2014 04:54:47 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: avshadow.exe14.0.4.642536c9660avshadow.exe14.0.4.642536c9660c0000409000000000001370e4d401cf8fbc35156d43C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exeC:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe7bc9504d-fbaf-11e3-9c0c-e86f8e581717 Error: (06/24/2014 04:28:41 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: avshadow.exe14.0.4.642536c9660avshadow.exe14.0.4.642536c9660c0000409000000000001370e5b801cf8fb88fc9a13cC:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exeC:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exed692f0a8-fbab-11e3-a000-86e9f0273b17 Error: (06/22/2014 05:21:31 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: fifa13.exe1.1.0.0120401cf8e2d5ae5953445C:\Program Files (x86)\Origin Games\FIFA 13\Game\fifa13.exe CodeIntegrity Errors: =================================== Date: 2013-04-28 00:49:58.738 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Users\SEBAST~1\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-04-28 00:49:58.582 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Users\SEBAST~1\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-04-28 00:49:58.395 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Users\Sebastian\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-04-28 00:49:58.255 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Users\Sebastian\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 52% Total physical RAM: 3946.16 MB Available physical RAM: 1855.88 MB Total Pagefile: 7890.51 MB Available Pagefile: 4715.4 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:231 GB) (Free:73.95 GB) NTFS Drive d: () (Fixed) (Total:345.07 GB) (Free:58.87 GB) NTFS Drive e: (SPI_046_01) (CDROM) (Total:0.37 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 596 GB) (Disk ID: 94F74182) Partition 1: (Not Active) - (Size=20 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=231 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=345 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
30.06.2014, 21:16 | #4 |
/// TB-Ausbilder /// Anleitungs-Guru | Benötige Hilfe zur Entfernung eines Trojaners Hi, Code:
ATTFilter ZeroAccess: C:\Windows\Installer\{3137ec37-8634-c619-3470-34d1b8cd37bc} C:\Windows\Installer\{3137ec37-8634-c619-3470-34d1b8cd37bc}\@ ZeroAccess: C:\Users\Sebastian\AppData\Local\{3137ec37-8634-c619-3470-34d1b8cd37bc} C:\Users\Sebastian\AppData\Local\{3137ec37-8634-c619-3470-34d1b8cd37bc}\@ Solltest Du Combofix oder die anderen Tools nicht runterladen können, dann bitte via USB-Stick von einem anderen PC auf den Desktop des infizierten PCs transferieren. Schritt 1 Bitte deinstalliere folgende Programme: Media Buzz Media_Play_AIR+_1.1 pdfforge Toolbar v7.3 Show-Password SkypEmoticons Updater Feature Update Service Java(TM) 6 Update 15 Java(TM) 6 Update 20 Java(TM) 6 Update 22 Java(TM) 6 Update 27 Java(TM) 6 Update 29 Versuche es bei Windows 7 zunächst über Systemsteuerung/Programme deinstallieren. Sollte das nicht gehen, lade Dir bitte Revo Uninstallerhier herunter. Entpacke die zip-Datei auf den Desktop.
Solltest Du ein Programm nicht finden oder nicht deinstallieren können, mache bitte mit dem nächsten Schritt weiter: Schritt 2 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 3 Scan mit Combofix
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
01.07.2014, 16:47 | #5 |
| Benötige Hilfe zur Entfernung eines Trojaners Log: Combofix Logfile: Code:
ATTFilter ComboFix 14-06-30.01 - Sebastian 01.07.2014 17:07:35.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3946.2661 [GMT 2:00] ausgeführt von:: c:\users\Sebastian\Desktop\ComboFix.exe AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\MediaBuzzV1 c:\users\Sebastian\Wolfenstein 3D (Full Version).exe c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut11_C03C290FA6F54A2B8A2DFE2786A1E275.exe c:\windows\IsUn0407.exe c:\windows\SysWow64\Oleaut32.1 c:\windows\SysWow64\Oleaut32.2 c:\windows\wininit.ini . . ((((((((((((((((((((((((((((((((((((((( Treiber/Dienste ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_ACEDRV11 -------\Service_acedrv11 -------\Service_WinUpd . . ((((((((((((((((((((((( Dateien erstellt von 2014-06-01 bis 2014-07-01 )))))))))))))))))))))))))))))) . . 2014-07-01 15:20 . 2014-07-01 15:20 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-06-30 19:10 . 2014-06-30 19:15 -------- d-----w- C:\FRST 2014-06-29 14:29 . 2014-06-29 14:29 -------- d-----w- c:\programdata\Wideblue installer 2014-06-29 14:27 . 2014-06-29 14:27 -------- d-----w- c:\program files\Level Quality Watcher 2014-06-29 12:34 . 2014-06-29 12:34 -------- d-----w- c:\program files\Enigma Software Group 2014-06-29 12:33 . 2014-06-29 14:35 -------- d-----w- c:\windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP 2014-06-29 12:14 . 2014-06-29 12:14 -------- d-----w- c:\users\Sebastian\AppData\Roaming\TestApp 2014-06-29 12:14 . 2014-06-29 12:14 -------- d-----w- c:\programdata\PC Tools 2014-06-27 21:28 . 2014-06-27 21:29 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-06-27 21:28 . 2014-05-12 05:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys 2014-06-27 21:28 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2014-06-27 21:28 . 2014-05-12 05:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys 2014-06-27 21:28 . 2014-06-27 21:28 -------- d-----w- c:\users\Sebastian\ Malwarebytes Anti-Malware 2014-06-14 05:46 . 2014-06-14 05:50 -------- d-----w- c:\users\Sebastian\AppData\Local\DownBooster 2014-06-14 05:46 . 2014-06-14 05:50 -------- d-----w- c:\program files (x86)\WinUpd 2014-06-13 13:41 . 1999-11-10 09:05 86016 ----a-w- c:\windows\unvise32qt.exe 2014-06-13 13:41 . 2014-06-13 13:41 90112 ----a-w- c:\program files\Internet Explorer\plugins\npqtplugin5.dll 2014-06-13 13:41 . 2014-06-13 13:41 90112 ----a-w- c:\program files\Internet Explorer\plugins\npqtplugin4.dll 2014-06-13 13:41 . 2014-06-13 13:41 90112 ----a-w- c:\program files\Internet Explorer\plugins\npqtplugin3.dll 2014-06-13 13:41 . 2014-06-13 13:41 90112 ----a-w- c:\program files\Internet Explorer\plugins\npqtplugin2.dll 2014-06-13 13:41 . 2014-06-13 13:41 90112 ----a-w- c:\program files\Internet Explorer\plugins\npqtplugin.dll 2014-06-13 13:41 . 2014-06-13 13:41 -------- d-----w- c:\programdata\QuickTime 2014-06-13 13:41 . 2014-06-13 13:41 -------- d-----w- c:\windows\SysWow64\QuickTime 2014-06-13 13:41 . 2014-06-13 13:41 -------- d-----w- c:\program files (x86)\QuickTime 2014-06-10 18:36 . 2014-06-10 18:36 -------- d-sh--w- c:\users\Sebastian\AppData\Local\EmieUserList 2014-06-10 18:36 . 2014-06-10 18:36 -------- d-sh--w- c:\users\Sebastian\AppData\Local\EmieSiteList 2014-06-08 14:43 . 2014-06-08 14:43 -------- d-----w- c:\users\Sebastian\AppData\Local\PDF24 . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-07-01 13:27 . 2013-04-03 13:35 117712 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2014-06-13 13:22 . 2011-01-16 11:01 95414520 ----a-w- c:\windows\system32\MRT.exe 2014-05-27 13:42 . 2013-04-03 13:35 130584 ----a-w- c:\windows\system32\drivers\avipbb.sys 2014-05-22 17:45 . 2012-04-02 16:48 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-05-22 17:45 . 2011-05-20 16:36 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-05-22 16:10 . 2014-05-26 18:38 61112 ----a-w- c:\windows\system32\drivers\{552199fb-9890-4055-9aaf-b2f6d51d46e9}Gw64.sys 2014-05-16 07:53 . 2014-05-16 07:53 341848 ----a-w- c:\windows\SysWow64\DivXControlPanelApplet.cpl 2014-05-09 06:14 . 2014-05-14 13:40 477184 ----a-w- c:\windows\system32\aepdu.dll 2014-05-09 06:11 . 2014-05-14 13:40 424448 ----a-w- c:\windows\system32\aeinv.dll 2014-04-24 10:19 . 2014-04-25 13:45 61112 ----a-w- c:\windows\system32\drivers\{552199fb-9890-4055-9aaf-b2f6d51d46e9}w64.sys 2014-04-12 02:22 . 2014-05-14 13:39 95680 ----a-w- c:\windows\system32\drivers\ksecdd.sys 2014-04-12 02:22 . 2014-05-14 13:39 155072 ----a-w- c:\windows\system32\drivers\ksecpkg.sys 2014-04-12 02:19 . 2014-05-14 13:39 29184 ----a-w- c:\windows\system32\sspisrv.dll 2014-04-12 02:19 . 2014-05-14 13:39 136192 ----a-w- c:\windows\system32\sspicli.dll 2014-04-12 02:19 . 2014-05-14 13:39 28160 ----a-w- c:\windows\system32\secur32.dll 2014-04-12 02:19 . 2014-05-14 13:39 1460736 ----a-w- c:\windows\system32\lsasrv.dll 2014-04-12 02:19 . 2014-05-14 13:39 31232 ----a-w- c:\windows\system32\lsass.exe 2014-04-12 02:12 . 2014-05-14 13:39 22016 ----a-w- c:\windows\SysWow64\secur32.dll 2014-04-12 02:10 . 2014-05-14 13:39 96768 ----a-w- c:\windows\SysWow64\sspicli.dll 2013-01-19 07:44 . 2013-01-19 07:44 2174976 ----a-w- c:\program files (x86)\Common Files\atimpenc.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}] 2014-02-13 05:22 12240 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{D4704207-C86B-4811-951E-6F322F9CEDE7}] 2011-07-12 16:16 270336 ----a-w- c:\users\Sebastian\AppData\LocalLow\QuickTime\IE\QuickTime.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" [2014-02-13 12240] . [HKEY_CLASSES_ROOT\clsid\{41564952-412d-5637-00a7-7a786e7484d7}] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2013-11-15 14:21 220632 ----a-w- c:\users\Sebastian\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2013-11-15 14:21 220632 ----a-w- c:\users\Sebastian\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2013-11-15 14:21 220632 ----a-w- c:\users\Sebastian\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176] "ccleaner"="c:\program files\CCleaner\CCleaner64.exe" [2012-10-24 5435744] "Spybot-S&D Cleaning"="c:\program files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" [2013-09-20 3666224] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-07-01 750160] "DivXMediaServer"="c:\program files (x86)\DivX\DivX Media Server\DivXMediaServer.exe" [2014-05-28 455512] "TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2013-06-22 295512] "ApnTBMon"="c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2014-02-13 1758160] "Aimersoft Helper Compact.exe"="c:\program files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe" [2012-02-20 1666560] "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2014-01-10 1861968] "SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2013-07-25 5624784] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-4-29 1127712] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R2 tor;Tor Win32 Service;c:\program files (x86)\Tor\tor.exe;c:\program files (x86)\Tor\tor.exe [x] R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R4 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x] S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S1 {552199fb-9890-4055-9aaf-b2f6d51d46e9}Gw64;{552199fb-9890-4055-9aaf-b2f6d51d46e9}Gw64;c:\windows\system32\drivers\{552199fb-9890-4055-9aaf-b2f6d51d46e9}Gw64.sys;c:\windows\SYSNATIVE\drivers\{552199fb-9890-4055-9aaf-b2f6d51d46e9}Gw64.sys [x] S1 {552199fb-9890-4055-9aaf-b2f6d51d46e9}w64;{552199fb-9890-4055-9aaf-b2f6d51d46e9}w64;c:\windows\system32\drivers\{552199fb-9890-4055-9aaf-b2f6d51d46e9}w64.sys;c:\windows\SYSNATIVE\drivers\{552199fb-9890-4055-9aaf-b2f6d51d46e9}w64.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys;c:\windows\SYSNATIVE\Drivers\SABI.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 APNMCP;Ask Aktualisierungsdienst;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 QuickTimeUpdater;QuickTime Updater;c:\users\Sebastian\AppData\LocalLow\QuickTime\IE\QuickTimeUpdater.exe;c:\users\Sebastian\AppData\LocalLow\QuickTime\IE\QuickTimeUpdater.exe [x] S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe;c:\program files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [x] S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x] S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x] S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys;c:\windows\SYSNATIVE\drivers\btwampfl.sys [x] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . Inhalt des "geplante Tasks" Ordners . 2014-07-01 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-18 17:45] . 2012-05-27 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-76830181-1066914796-2057996457-1000.job - c:\program files (x86)\Real\RealUpgrade\realupgrade.exe [2013-04-16 10:45] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}] 2014-02-13 05:22 13776 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll" [2014-02-13 13776] . [HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2013-11-15 14:21 244696 ----a-w- c:\users\Sebastian\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2013-11-15 14:21 244696 ----a-w- c:\users\Sebastian\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2013-11-15 14:21 244696 ----a-w- c:\users\Sebastian\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-14 11046504] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://websearch.fastsearchings.info/?pid=1249&r=2014/06/29&hid=6740810968012150956&lg=EN&cc=DE&unqvl=56 uDefault_Search_URL = hxxp://www.google.com mDefault_Search_URL = hxxp://www.google.com mDefault_Page_URL = hxxp://www.google.com mStart Page = hxxp://websearch.fastsearchings.info/?pid=1249&r=2014/06/29&hid=6740810968012150956&lg=EN&cc=DE&unqvl=56 mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://www.google.com uSearchAssistant = hxxp://www.google.com mSearchAssistant = IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm IE: ????3?? - c:\users\Sebastian\AppData\Roaming\FlashGetBHO\GetUrl.htm IE: ????3?????? - c:\users\Sebastian\AppData\Roaming\FlashGetBHO\GetAllUrl.htm IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files (x86)\ICQ7.7\ICQ.exe IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - TCP: Interfaces\{9B334387-B32E-40AA-A8DA-FFAAFCCB3AE5}: NameServer = 192.168.198.10 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Wow6432Node-HKLM-Run-<NO NAME> - (no file) Wow6432Node-HKU-Default-Run-SearchProtect - \SearchProtect\bin\cltmng.exe c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut11_C03C290FA6F54A2B8A2DFE2786A1E275.exe /f=srs_premium_sound_noext_nogame.zip /h Notify-SDWinLogon - SDWinLogon.dll HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-Frieven_s_Prox_1.8 - c:\program files (x86)\Frieven_s_Prox_1.8\Uninstall.exe AddRemove-Shockwave - c:\windows\System32\Macromed\SHOCKW~1\UNWISE.EXE AddRemove-{AE54C622-BDD1-CEE6-A996-E000A3273001} - c:\progra~3\INSTAL~1\{460C5~1\Setup.exe AddRemove-{BD2E61BC-A249-28F3-FD0A-11E8E35E50B6} - c:\progra~3\INSTAL~1\{AC4AE~1\Setup.exe AddRemove-pgcchelper - c:\users\Sebastian\AppData\Local\pgcchelper\pgcchelper_uninstaller.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-76830181-1066914796-2057996457-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_f3*N}] @="c:\\Users\\Sebastian\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm" "contexts"=dword:00000022 . [HKEY_USERS\S-1-5-21-76830181-1066914796-2057996457-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_f3*N}hQèþ”¥c] @="c:\\Users\\Sebastian\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm" "contexts"=dword:000000f3 . [HKEY_USERS\S-1-5-21-76830181-1066914796-2057996457-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-76830181-1066914796-2057996457-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.13" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe c:\program files (x86)\CyberLink\Shared files\RichVideo.exe c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe c:\program files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe c:\program files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe c:\program files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe c:\windows\SysWOW64\DllHost.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-07-01 17:37:43 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-07-01 15:37 . Vor Suchlauf: 17 Verzeichnis(se), 79.671.812.096 Bytes frei Nach Suchlauf: 21 Verzeichnis(se), 79.450.775.552 Bytes frei . - - End Of File - - F93C9857AF774888A04E7220E9DB4E0A Nach dem Neustart startete Avira nicht automatisch, aber es ains alle Probleme behoben. DANKE |
01.07.2014, 16:53 | #6 |
/// TB-Ausbilder /// Anleitungs-Guru | Benötige Hilfe zur Entfernung eines Trojaners Wir sind noch nicht fertig... Schritt 1 Scan mit Malwarebytes Antimalware Unter Erkennung und Schutz setze bitte einen Haken bei "Suche nach Rootkits". Klicke im Anschluss auf "Suchlauf", wähle den Bedrohungssuchlauf aus, aktualisiere die Datenbanken und klicke auf "Suchlauf jetzt starten". Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. (geht so...) Poste mir den Inhalt der Logdatei. Klicke dazu auf Verlauf und dann auf Anwendungsprotokolle. Wähle das neueste Suchlauf-Protokoll aus und klicke auf Ansicht. Klicke auf "In Zwischenablage kopieren" poste mir den Inhalt in Code-Tags als Antwort in den Thread. Schritt 2 Downloade Dir HitmanProauf Deinen Desktop: HitmanPro - 32 Bit HitmanPro - 64 Bit
Schritt 3 Bitte starte FRST erneut, markiere auch die checkbox und drücke auf Scan. Bitte poste mir den Inhalt der beiden Logs die erstellt werden.
__________________ --> Benötige Hilfe zur Entfernung eines Trojaners |
Themen zu Benötige Hilfe zur Entfernung eines Trojaners |
benötige, c:\windows, c:\windows\temp, dankbar, datei, entferne, entfernen, entfernung, erklären, folge, folgendes, hilfe, laptop, problem, temp, tr/dropper.gen, troja, trojaner, trojaner blockiert zugriff auf datei, trojaner entferne, trojaner entfernen, trojaners, updater.exe, windows, windows\temp |