|
Plagegeister aller Art und deren Bekämpfung: Programme haben keinen InternetzugriffWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
07.10.2014, 13:54 | #16 | |
/// the machine /// TB-Ausbilder | Programme haben keinen InternetzugriffZitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.10.2014, 09:26 | #17 |
| Programme haben keinen Internetzugriff also über den browers komme ich (wie vorher auch) ganz normal ins internet. probleme gibt es bei den updates, da diese programme keine verbindung mit dem internet aufbauen können bzw. das evtl. verhindert wird.
__________________ |
08.10.2014, 16:50 | #18 |
/// the machine /// TB-Ausbilder | Programme haben keinen Internetzugriff hi,
__________________Downloade dir bitte Farbar Service Scanner
Poste bitte den Inhalt hier.
__________________ |
09.10.2014, 20:29 | #19 |
| Programme haben keinen InternetzugriffCode:
ATTFilter Farbar Service Scanner Version: 21-07-2014 Ran by Dario (administrator) on 09-10-2014 at 21:27:22 Running from "C:\Users\Dario\Desktop" Microsoft Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Attempt to access Yahoo.com returned error: Yahoo.com is unreachable Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is set to Demand. The default start type is Auto. The ImagePath of WinDefend service is OK. The ServiceDll of WinDefend service is OK. Windows Defender Disabled Policy: ========================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] "DisableAntiSpyware"=DWORD:1 Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => File is digitally signed C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed C:\Windows\System32\dhcpcore.dll => File is digitally signed C:\Windows\System32\drivers\afd.sys => File is digitally signed C:\Windows\System32\drivers\tdx.sys => File is digitally signed C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed C:\Windows\System32\dnsrslvr.dll => File is digitally signed C:\Windows\System32\mpssvc.dll => File is digitally signed C:\Windows\System32\bfe.dll => File is digitally signed C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed C:\Windows\System32\SDRSVC.dll => File is digitally signed C:\Windows\System32\vssvc.exe => File is digitally signed C:\Windows\System32\wscsvc.dll => File is digitally signed C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed C:\Windows\System32\wuaueng.dll => File is digitally signed C:\Windows\System32\qmgr.dll => File is digitally signed C:\Windows\System32\es.dll => File is digitally signed C:\Windows\System32\cryptsvc.dll => File is digitally signed C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed C:\Windows\System32\ipnathlp.dll => File is digitally signed C:\Windows\System32\iphlpsvc.dll => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed **** End of log **** |
10.10.2014, 18:15 | #20 |
/// the machine /// TB-Ausbilder | Programme haben keinen Internetzugriff Poste mal die Fehlermeldung die kommt wenn du ein Programm updaten willst.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.10.2014, 18:33 | #21 |
| Programme haben keinen Internetzugriff Hier mal ein paar Beispiele Windows Update: 80072EFE iTunes verbindung zum iTunes Store: Fehler 310, Netzwerk überprüfen Internet Explorer (benutze eigentlich FireFox und da klappt auch alles): Der Proxyserver reagiert nicht. •Überprüfen Sie Ihre Proxyeinstellungen 134.100.32.207:3128. Navigieren Sie zu „Extras“ > „Internetoptionen“ > „Verbindungen“ . Klicken Sie auf „LAN-Einstellungen“, falls Sie sich in einem LAN befinden. •Vergewissern Sie sich, dass der Webzugriff nicht durch Ihre Firewalleinstellungen blockiert wird. •Bitten Sie Ihren Systemadministrator um Hilfe. Grüße Dario |
11.10.2014, 11:55 | #22 |
/// the machine /// TB-Ausbilder | Programme haben keinen Internetzugriff Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter FF Homepage: google.de FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1))%20%7B%20return%20'PROXY%20us10.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000%3B%20PROXY%20us03.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us02.sq.proxmate.me%3A8000%3B%20PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us11.sq.proxmate.me%3A8000%3B%20PROXY%20us06.sq.proxmate.me%3A8000%3B%20PROXY%20us07.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF NetworkProxy: "type", 2 Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.10.2014, 08:08 | #23 |
| Programme haben keinen Internetzugriff Falls ich alles richtig gemacht habe, dann ist das dabei rausgekommen: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-09-2014 02 Ran by Dario at 2014-10-13 09:04:59 Run:1 Running from C:\Users\Dario\Desktop\Neuer Ordner Loaded Profile: Dario (Available profiles: Dario) Boot Mode: Normal ============================================== Content of fixlist: ***************** FF Homepage: google.de FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1))%20%7B%20return%20'PROXY%20us10.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000%3B%20PROXY%20us03.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us02.sq.proxmate.me%3A8000%3B%20PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us11.sq.proxmate.me%3A8000%3B%20PROXY%20us06.sq.proxmate.me%3A8000%3B%20PROXY%20us07.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF NetworkProxy: "type", 2 ***************** Firefox homepage deleted successfully. Firefox Proxy settings were reset. Firefox Proxy settings were reset. ==== End of Fixlog ==== |
13.10.2014, 16:40 | #24 |
/// the machine /// TB-Ausbilder | Programme haben keinen Internetzugriff Das frische FRST log fehlt. Noch PRobleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.10.2014, 17:33 | #25 |
| Programme haben keinen Internetzugriff ach ja sorry, hier: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-09-2014 02 (ATTENTION: ====> FRST version is 15 days old and could be outdated) Ran by Dario (administrator) on DARIO-VAIO on 13-10-2014 18:30:49 Running from C:\Users\Dario\Desktop\Neuer Ordner Loaded Profile: Dario (Available profiles: Dario) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (AMD) C:\Windows\System32\atieclxx.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\fshoster32.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\CCF_Reputation\fsorsp.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\fsgk32.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSMA32.EXE (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSHDLL64.EXE (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\fssm32.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Spotify Ltd) C:\Users\Dario\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\fshoster32.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSM32.EXE (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10775584 2010-05-31] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2040352 2010-05-31] (Realtek Semiconductor) HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [212480 2010-05-31] (Alps Electric Co., Ltd.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-03-12] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [600928 2010-06-01] (Sony Corporation) HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [673136 2010-05-31] (Sony Corporation) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.) HKLM-x32\...\Run: [F-Secure Hoster (666)] => C:\Program Files (x86)\F-Secure\fshoster32.exe [187432 2014-07-08] (F-Secure Corporation) HKLM-x32\...\Run: [F-Secure Manager] => C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSM32.EXE [310312 2014-06-24] (F-Secure Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3810040113-3366235107-2524779152-1000\...\Run: [Spotify Web Helper] => C:\Users\Dario\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1245752 2014-09-21] (Spotify Ltd) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => No File ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {791387CC-FD3D-4649-A362-23DEFED0F29D} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices SearchScopes: HKCU - {C909D0DC-BB0B-4692-8A78-5DFC11EE1066} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-9/4?satitle={searchTerms} SearchScopes: HKCU - {CCFDB796-99E0-4AE7-B5CC-B72FBA91483C} URL = hxxp://de.shopping.com/?linkin_id=8056363 BHO: F-Secure Browsing Protection -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https64.dll (F-Secure Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: F-Secure Browsing Protection -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll (F-Secure Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll (Microsoft Corporation) Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default FF DefaultSearchEngine: user_pref("browser.search.defaultenginename", ""); FF Homepage: google.de FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*'))%20%7B%20return%20'PROXY%20us03.sq.proxmate.me%3A8000%3B%20PROXY%20us02.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us06.sq.proxmate.me%3A8000%3B%20PROXY%20us07.sq.proxmate.me%3A8000%3B%20PROXY%20us11.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000%3B%20PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us10.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF NetworkProxy: "type", 2 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: GMX MailCheck - C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\Extensions\toolbar@gmx.net [2014-10-02] FF Extension: Adblock Plus Pop-up Addon - C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\Extensions\adblockpopups@jessehakanen.net.xpi [2014-04-21] FF Extension: ProxMate - Proxy on steroids! - C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-01-29] FF Extension: Adblock Plus - C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-21] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-09-21] FF HKLM-x32\...\Firefox\Extensions: [{99e13caf-b79e-4df2-90f8-62f471dc9ec8}] - C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\bin\browser\deploy\fs_firefox_https FF Extension: Browsing Protection - C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\bin\browser\deploy\fs_firefox_https [2014-10-05] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] - C:/Program Files (x86)/F-Secure/apps/CCF_Scanning/bin/browser/install/fs_chrome_https/fs_chrome_https.crx [2014-06-25] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 fshoster; C:\Program Files (x86)\F-Secure\fshoster32.exe [187432 2014-07-08] (F-Secure Corporation) R3 FSMA; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSMA32.EXE [216104 2014-06-24] (F-Secure Corporation) R2 FSORSPClient; C:\Program Files (x86)\F-Secure\apps\CCF_Reputation\fsorsp.exe [60456 2014-06-24] (F-Secure Corporation) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [851824 2010-06-17] (Sony Corporation) R2 VSNService; C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [836608 2010-06-08] (Sony Corporation) [File not signed] R3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1642544 2014-02-27] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R3 F-Secure Gatekeeper; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [203304 2014-10-05] (F-Secure Corporation) R1 F-Secure HIPS; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\HIPS\drivers\fshs.sys [69960 2014-10-05] (F-Secure Corporation) R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [56016 2014-10-05] () R3 fsni; C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\bin\fsni64.sys [89640 2014-10-05] (F-Secure Corporation) R1 fsvista; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys [13352 2014-06-24] () S3 igfx; C:\Windows\System32\DRIVERS\igdkmd64.sys [10326784 2010-06-24] (Intel Corporation) [File not signed] S3 IntcDAud; C:\Windows\System32\DRIVERS\IntcDAud.sys [271872 2010-06-24] (Intel(R) Corporation) [File not signed] S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl64.sys [22528 2011-08-02] (Apple Inc.) [File not signed] S3 VBTUSB; C:\Windows\System32\Drivers\VBTUSB.sys [14848 2010-06-17] (Sony Corporation) [File not signed] S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-05 22:13 - 2014-10-05 22:18 - 00056016 _____ () C:\Windows\system32\Drivers\fsbts.sys 2014-10-05 22:10 - 2014-10-05 22:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\F-Secure 2014-10-05 22:02 - 2014-10-05 22:03 - 00048426 _____ () C:\Users\Dario\Desktop\Result.txt 2014-10-05 20:16 - 2014-10-05 20:17 - 00047302 _____ () C:\Users\Dario\Desktop\Result 1.txt 2014-10-05 20:12 - 2014-10-05 20:12 - 00401920 _____ (Farbar) C:\Users\Dario\Desktop\MiniToolBox.exe 2014-10-03 15:38 - 2014-10-03 15:38 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-10-03 15:32 - 2014-10-03 15:32 - 02347384 _____ (ESET) C:\Users\Dario\Desktop\esetsmartinstaller_deu.exe 2014-10-03 15:32 - 2014-10-03 15:32 - 00854417 _____ () C:\Users\Dario\Desktop\SecurityCheck.exe 2014-10-02 10:28 - 2014-10-02 10:28 - 00000000 ____D () C:\Windows\ERUNT 2014-10-02 10:21 - 2014-10-02 10:22 - 00000000 ____D () C:\AdwCleaner 2014-10-02 09:59 - 2014-10-02 09:59 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-02 09:58 - 2014-10-02 09:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-10-02 09:58 - 2014-10-02 09:58 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-10-02 09:58 - 2014-10-02 09:58 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-10-02 09:58 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-10-02 09:58 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-10-02 09:58 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-10-02 09:45 - 2014-10-13 18:30 - 00000000 ____D () C:\Users\Dario\Desktop\Neuer Ordner 2014-09-30 17:03 - 2014-09-30 17:16 - 00000000 ____D () C:\Qoobox 2014-09-30 17:03 - 2014-09-30 17:15 - 00000000 ____D () C:\Windows\erdnt 2014-09-30 17:03 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-09-30 17:03 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-09-30 17:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-09-30 17:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-09-30 17:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-09-30 17:03 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-09-30 17:03 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-09-30 17:03 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-09-29 19:04 - 2014-10-13 18:30 - 00000000 ____D () C:\FRST 2014-09-28 23:19 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-09-28 23:19 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-09-28 23:19 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-09-28 23:15 - 2014-09-28 23:15 - 00182912 _____ () C:\Windows\msxml4-KB2758694-deu.LOG 2014-09-28 22:50 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2014-09-28 22:47 - 2014-09-28 22:47 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-09-28 22:47 - 2014-09-28 22:47 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-09-28 22:47 - 2014-09-28 22:47 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-09-28 22:47 - 2014-09-28 22:47 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-09-28 22:47 - 2014-09-28 22:47 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-09-28 22:47 - 2014-09-28 22:47 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-09-28 22:47 - 2014-09-28 22:47 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-09-28 22:47 - 2014-09-28 22:47 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-09-28 22:47 - 2014-09-28 22:47 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-09-28 22:47 - 2014-09-28 22:47 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-09-28 22:47 - 2014-09-28 22:47 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-09-28 21:29 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2014-09-28 21:29 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2014-09-28 21:24 - 2012-11-23 05:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe 2014-09-28 21:10 - 2013-01-13 23:17 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:17 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:35 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:35 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:35 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:22 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-09-28 21:10 - 2013-01-13 22:20 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2014-09-28 21:10 - 2013-01-13 22:09 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2014-09-28 21:10 - 2013-01-13 22:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2014-09-28 21:10 - 2013-01-13 21:59 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2014-09-28 21:10 - 2013-01-13 21:58 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2014-09-28 21:10 - 2013-01-13 21:54 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2014-09-28 21:10 - 2013-01-13 21:53 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2014-09-28 21:10 - 2013-01-13 21:53 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2014-09-28 21:10 - 2013-01-13 21:51 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-09-28 21:10 - 2013-01-13 21:49 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2014-09-28 21:10 - 2013-01-13 21:48 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2014-09-28 21:10 - 2013-01-13 21:46 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2014-09-28 21:10 - 2013-01-13 21:43 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-09-28 21:10 - 2013-01-13 21:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2014-09-28 21:10 - 2013-01-13 21:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2014-09-28 21:10 - 2013-01-13 21:37 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-09-28 21:10 - 2013-01-13 21:25 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2014-09-28 21:10 - 2013-01-13 21:24 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2014-09-28 21:10 - 2013-01-13 21:24 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2014-09-28 21:10 - 2013-01-13 21:20 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2014-09-28 21:10 - 2013-01-13 21:20 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2014-09-28 21:10 - 2013-01-13 21:15 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-09-28 21:10 - 2013-01-13 21:10 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-09-28 21:10 - 2013-01-13 21:02 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-09-28 21:10 - 2013-01-13 20:34 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2014-09-28 21:10 - 2013-01-13 20:32 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-09-28 21:10 - 2013-01-13 20:09 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2014-09-28 21:10 - 2013-01-13 19:26 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2014-09-28 21:10 - 2013-01-13 19:05 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2014-09-28 21:10 - 2013-01-04 08:11 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2014-09-28 21:10 - 2013-01-04 08:11 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2014-09-28 21:01 - 2014-09-28 22:50 - 00035949 _____ () C:\Windows\IE11_main.log 2014-09-28 20:27 - 2014-09-28 20:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-09-28 20:27 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys 2014-09-28 20:26 - 2014-09-28 20:27 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-09-28 20:26 - 2014-09-28 20:27 - 00000000 ____D () C:\Program Files\iTunes 2014-09-28 20:26 - 2014-09-28 20:27 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-09-28 20:26 - 2014-09-28 20:26 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2014-09-28 20:26 - 2014-09-28 20:26 - 00000000 ____D () C:\Windows\System32\Tasks\Apple 2014-09-28 20:26 - 2014-09-28 20:26 - 00000000 ____D () C:\Program Files\iPod 2014-09-28 20:26 - 2014-09-28 20:26 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-09-28 20:25 - 2014-09-28 20:25 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-09-28 20:25 - 2014-09-28 20:25 - 00000000 ____D () C:\Program Files\Bonjour 2014-09-28 20:25 - 2014-09-28 20:25 - 00000000 ____D () C:\Program Files (x86)\Bonjour 2014-09-25 08:51 - 2014-10-05 22:13 - 00001314 _____ () C:\Windows\fsav_db_setup.log 2014-09-25 08:50 - 2014-10-05 22:13 - 01790220 _____ () C:\Windows\FSSFM.log 2014-09-25 08:50 - 2014-10-05 22:13 - 01609838 _____ () C:\Windows\FSSETUP.log 2014-09-25 08:50 - 2014-10-05 22:13 - 00272154 _____ () C:\Windows\FSPROD.log 2014-09-25 08:50 - 2014-10-05 22:13 - 00176978 _____ () C:\Windows\RunSetup.log 2014-09-25 08:50 - 2014-10-05 22:13 - 00141419 _____ () C:\Windows\FSAVINST.LOG 2014-09-25 08:50 - 2014-10-05 22:13 - 00009874 _____ () C:\Windows\FSAVCSIN.LOG 2014-09-25 08:50 - 2014-10-05 22:13 - 00004230 _____ () C:\Windows\fstnbins.LOG 2014-09-25 08:50 - 2014-10-05 22:12 - 00038656 _____ () C:\Windows\fspplugin.log 2014-09-25 08:48 - 2014-10-05 22:11 - 00000000 ____D () C:\Program Files (x86)\F-Secure 2014-09-24 23:30 - 2014-10-05 21:37 - 00754232 _____ () C:\Windows\PFRO.log 2014-09-24 21:21 - 2014-09-25 08:41 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-09-24 21:19 - 2014-10-05 22:13 - 04127298 _____ () C:\Windows\FSISU.log 2014-09-24 21:19 - 2014-10-05 22:13 - 00737784 _____ () C:\Windows\FSDEPH.log 2014-09-24 21:19 - 2014-10-05 22:13 - 00016658 _____ () C:\Windows\FSGKIAIN.log 2014-09-24 21:19 - 2014-10-05 22:13 - 00007222 _____ () C:\Windows\FSLDIN.LOG 2014-09-24 21:19 - 2014-10-05 22:13 - 00003257 _____ () C:\Windows\fsavunin.log 2014-09-24 21:19 - 2014-10-05 21:29 - 00502671 _____ () C:\Windows\FSUNINST.log 2014-09-24 21:19 - 2014-10-05 21:29 - 00026266 _____ () C:\Windows\uninstaller.log 2014-09-24 21:19 - 2014-10-05 21:29 - 00000985 _____ () C:\Windows\fsavunin_2.log 2014-09-24 21:19 - 2014-09-24 21:19 - 00000812 _____ () C:\Windows\daasunin.LOG 2014-09-21 09:28 - 2014-09-25 09:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-21 09:14 - 2014-10-02 19:12 - 00000063 _____ () C:\Users\Dario\Desktop\ib.txt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-13 18:31 - 2014-08-16 15:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-13 18:16 - 2010-11-25 19:27 - 01471284 _____ () C:\Windows\WindowsUpdate.log 2014-10-13 18:16 - 2009-07-14 06:45 - 00013664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-13 18:16 - 2009-07-14 06:45 - 00013664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-13 18:08 - 2014-08-09 09:27 - 00009714 _____ () C:\Windows\setupact.log 2014-10-13 18:08 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-13 09:19 - 2013-01-27 18:46 - 00000000 ____D () C:\Users\Dario\AppData\Local\Spotify 2014-10-13 09:19 - 2013-01-27 18:12 - 00000000 ____D () C:\Users\Dario\AppData\Roaming\Spotify 2014-10-13 09:01 - 2010-11-25 19:40 - 00003938 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{737607F8-836A-4C0C-B675-CAA71288B56F} 2014-10-10 11:12 - 2014-09-06 14:41 - 00000000 ____D () C:\Users\Dario\Desktop\Bewerbung NEU ab 2014 2014-10-10 09:17 - 2013-04-12 20:25 - 00370846 _____ () C:\test.xml 2014-10-05 22:13 - 2014-04-10 21:40 - 00000000 ____D () C:\Users\Dario\AppData\Local\F-Secure 2014-10-05 22:13 - 2012-12-10 14:49 - 00000000 ____D () C:\ProgramData\F-Secure 2014-10-05 22:12 - 2012-12-10 15:01 - 00020560 _____ () C:\Windows\prodsett_copy.ini 2014-10-04 13:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-09-30 17:16 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-09-30 17:14 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-09-28 23:40 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-09-28 23:24 - 2009-07-14 06:45 - 00443352 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-09-28 23:05 - 2010-07-12 22:26 - 00000000 ____D () C:\Windows\Panther 2014-09-28 23:02 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-09-28 22:10 - 2010-07-31 01:24 - 00703340 _____ () C:\Windows\system32\perfh007.dat 2014-09-28 22:10 - 2010-07-31 01:24 - 00151766 _____ () C:\Windows\system32\perfc007.dat 2014-09-28 22:10 - 2009-07-14 07:13 - 01631944 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-28 22:07 - 2013-05-15 19:51 - 00000000 ___RD () C:\Users\Dario\Dropbox 2014-09-28 22:06 - 2013-05-15 19:46 - 00000000 ____D () C:\Users\Dario\AppData\Roaming\Dropbox 2014-09-28 21:17 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-09-28 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK 2014-09-28 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR 2014-09-28 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\zh-HK 2014-09-28 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\tr-TR 2014-09-28 20:26 - 2010-12-28 19:08 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-09-28 20:25 - 2010-12-28 19:07 - 00000000 ____D () C:\ProgramData\Apple 2014-09-25 18:23 - 2012-05-02 20:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-09-24 23:38 - 2014-03-26 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-09-15 16:00 - 2011-07-20 21:12 - 00000000 ____D () C:\Users\Dario\Documents\Bewerbung Dario_NICHT LÖSCHEN 2014-09-13 13:29 - 2011-11-04 17:46 - 00000000 ____D () C:\Users\Dario\Documents\Uni Some content of TEMP: ==================== C:\Users\Dario\AppData\Local\Temp\cleanup_tool.exe C:\Users\Dario\AppData\Local\Temp\fsc6096.tmp.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-08 09:08 ==================== End Of Log ============================ --- --- --- allerdings funktioniert es leider immer noch nicht also zb das windows update... immer noch die gleiche meldung. |
14.10.2014, 10:14 | #26 |
/// the machine /// TB-Ausbilder | Programme haben keinen Internetzugriff Versteh ich nicht. laut Fehlermeldung surfst du angeblich über nen Proxy, da ist aber keiner. Deaktiviere bitte mal den VPN zur Uni komplett.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.10.2014, 11:16 | #27 |
| Programme haben keinen Internetzugriff habe den vpn client von cisco jetzt deinstalliert. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-09-2014 02 (ATTENTION: ====> FRST version is 16 days old and could be outdated) Ran by Dario (administrator) on DARIO-VAIO on 14-10-2014 12:12:27 Running from C:\Users\Dario\Desktop\Neuer Ordner Loaded Profile: Dario (Available profiles: Dario) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\fshoster32.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\CCF_Reputation\fsorsp.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\fsgk32.exe (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSMA32.EXE (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\fssm32.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSHDLL64.EXE (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Spotify Ltd) C:\Users\Dario\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\fshoster32.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSM32.EXE (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10775584 2010-05-31] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2040352 2010-05-31] (Realtek Semiconductor) HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [212480 2010-05-31] (Alps Electric Co., Ltd.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-03-12] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [600928 2010-06-01] (Sony Corporation) HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [673136 2010-05-31] (Sony Corporation) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.) HKLM-x32\...\Run: [F-Secure Hoster (666)] => C:\Program Files (x86)\F-Secure\fshoster32.exe [187432 2014-07-08] (F-Secure Corporation) HKLM-x32\...\Run: [F-Secure Manager] => C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSM32.EXE [310312 2014-06-24] (F-Secure Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3810040113-3366235107-2524779152-1000\...\Run: [Spotify Web Helper] => C:\Users\Dario\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1245752 2014-09-21] (Spotify Ltd) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => No File ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {791387CC-FD3D-4649-A362-23DEFED0F29D} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices SearchScopes: HKCU - {C909D0DC-BB0B-4692-8A78-5DFC11EE1066} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-9/4?satitle={searchTerms} SearchScopes: HKCU - {CCFDB796-99E0-4AE7-B5CC-B72FBA91483C} URL = hxxp://de.shopping.com/?linkin_id=8056363 BHO: F-Secure Browsing Protection -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https64.dll (F-Secure Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: F-Secure Browsing Protection -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll (F-Secure Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll (Microsoft Corporation) Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default FF DefaultSearchEngine: user_pref("browser.search.defaultenginename", ""); FF Homepage: google.de FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*'))%20%7B%20return%20'PROXY%20us10.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000%3B%20PROXY%20us02.sq.proxmate.me%3A8000%3B%20PROXY%20us11.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us03.sq.proxmate.me%3A8000%3B%20PROXY%20us06.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000%3B%20PROXY%20us07.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF NetworkProxy: "type", 2 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: GMX MailCheck - C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\Extensions\toolbar@gmx.net [2014-10-02] FF Extension: Adblock Plus Pop-up Addon - C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\Extensions\adblockpopups@jessehakanen.net.xpi [2014-04-21] FF Extension: ProxMate - Proxy on steroids! - C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-01-29] FF Extension: Adblock Plus - C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\z374b044.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-21] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-09-21] FF HKLM-x32\...\Firefox\Extensions: [{99e13caf-b79e-4df2-90f8-62f471dc9ec8}] - C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\bin\browser\deploy\fs_firefox_https FF Extension: Browsing Protection - C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\bin\browser\deploy\fs_firefox_https [2014-10-05] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] - C:/Program Files (x86)/F-Secure/apps/CCF_Scanning/bin/browser/install/fs_chrome_https/fs_chrome_https.crx [2014-06-25] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 fshoster; C:\Program Files (x86)\F-Secure\fshoster32.exe [187432 2014-07-08] (F-Secure Corporation) R3 FSMA; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSMA32.EXE [216104 2014-06-24] (F-Secure Corporation) R2 FSORSPClient; C:\Program Files (x86)\F-Secure\apps\CCF_Reputation\fsorsp.exe [60456 2014-06-24] (F-Secure Corporation) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [851824 2010-06-17] (Sony Corporation) R2 VSNService; C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [836608 2010-06-08] (Sony Corporation) [File not signed] R3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1642544 2014-02-27] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R3 F-Secure Gatekeeper; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [203304 2014-10-05] (F-Secure Corporation) R1 F-Secure HIPS; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\HIPS\drivers\fshs.sys [69960 2014-10-05] (F-Secure Corporation) R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [56016 2014-10-05] () R3 fsni; C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\bin\fsni64.sys [89640 2014-10-05] (F-Secure Corporation) R1 fsvista; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys [13352 2014-06-24] () S3 igfx; C:\Windows\System32\DRIVERS\igdkmd64.sys [10326784 2010-06-24] (Intel Corporation) [File not signed] S3 IntcDAud; C:\Windows\System32\DRIVERS\IntcDAud.sys [271872 2010-06-24] (Intel(R) Corporation) [File not signed] S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl64.sys [22528 2011-08-02] (Apple Inc.) [File not signed] S3 VBTUSB; C:\Windows\System32\Drivers\VBTUSB.sys [14848 2010-06-17] (Sony Corporation) [File not signed] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 vpnva; system32\DRIVERS\vpnva64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-13 19:38 - 2014-10-13 19:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-10-13 19:38 - 2014-10-13 19:38 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-10-13 19:38 - 2014-10-13 19:38 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-10-13 19:09 - 2014-10-13 19:12 - 00000000 ____D () C:\df0a026feee0bf756ca2f2642e3146f4 2014-10-13 19:05 - 2014-10-13 19:09 - 00000000 ____D () C:\193e57ee3edfa01023dc 2014-10-05 22:13 - 2014-10-05 22:18 - 00056016 _____ () C:\Windows\system32\Drivers\fsbts.sys 2014-10-05 22:10 - 2014-10-05 22:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\F-Secure 2014-10-05 22:02 - 2014-10-05 22:03 - 00048426 _____ () C:\Users\Dario\Desktop\Result.txt 2014-10-05 20:16 - 2014-10-05 20:17 - 00047302 _____ () C:\Users\Dario\Desktop\Result 1.txt 2014-10-05 20:12 - 2014-10-05 20:12 - 00401920 _____ (Farbar) C:\Users\Dario\Desktop\MiniToolBox.exe 2014-10-03 15:38 - 2014-10-03 15:38 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-10-03 15:32 - 2014-10-03 15:32 - 02347384 _____ (ESET) C:\Users\Dario\Desktop\esetsmartinstaller_deu.exe 2014-10-03 15:32 - 2014-10-03 15:32 - 00854417 _____ () C:\Users\Dario\Desktop\SecurityCheck.exe 2014-10-02 10:28 - 2014-10-02 10:28 - 00000000 ____D () C:\Windows\ERUNT 2014-10-02 10:21 - 2014-10-02 10:22 - 00000000 ____D () C:\AdwCleaner 2014-10-02 09:59 - 2014-10-02 09:59 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-02 09:58 - 2014-10-02 09:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-10-02 09:58 - 2014-10-02 09:58 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-10-02 09:58 - 2014-10-02 09:58 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-10-02 09:58 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-10-02 09:58 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-10-02 09:58 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-10-02 09:45 - 2014-10-14 12:12 - 00000000 ____D () C:\Users\Dario\Desktop\Neuer Ordner 2014-09-30 17:03 - 2014-09-30 17:16 - 00000000 ____D () C:\Qoobox 2014-09-30 17:03 - 2014-09-30 17:15 - 00000000 ____D () C:\Windows\erdnt 2014-09-30 17:03 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-09-30 17:03 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-09-30 17:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-09-30 17:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-09-30 17:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-09-30 17:03 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-09-30 17:03 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-09-30 17:03 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-09-29 19:04 - 2014-10-14 12:12 - 00000000 ____D () C:\FRST 2014-09-28 23:19 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-09-28 23:19 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-09-28 23:19 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-09-28 23:15 - 2014-09-28 23:15 - 00182912 _____ () C:\Windows\msxml4-KB2758694-deu.LOG 2014-09-28 22:50 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2014-09-28 22:47 - 2014-09-28 22:47 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-09-28 22:47 - 2014-09-28 22:47 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-09-28 22:47 - 2014-09-28 22:47 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-09-28 22:47 - 2014-09-28 22:47 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-09-28 22:47 - 2014-09-28 22:47 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-09-28 22:47 - 2014-09-28 22:47 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-09-28 22:47 - 2014-09-28 22:47 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-09-28 22:47 - 2014-09-28 22:47 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-09-28 22:47 - 2014-09-28 22:47 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-09-28 22:47 - 2014-09-28 22:47 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-09-28 22:47 - 2014-09-28 22:47 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-09-28 21:29 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2014-09-28 21:29 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2014-09-28 21:24 - 2012-11-23 05:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe 2014-09-28 21:10 - 2013-01-13 23:17 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:17 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:35 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:35 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:35 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:22 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-09-28 21:10 - 2013-01-13 22:20 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2014-09-28 21:10 - 2013-01-13 22:09 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2014-09-28 21:10 - 2013-01-13 22:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2014-09-28 21:10 - 2013-01-13 21:59 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2014-09-28 21:10 - 2013-01-13 21:58 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2014-09-28 21:10 - 2013-01-13 21:54 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2014-09-28 21:10 - 2013-01-13 21:53 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2014-09-28 21:10 - 2013-01-13 21:53 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2014-09-28 21:10 - 2013-01-13 21:51 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-09-28 21:10 - 2013-01-13 21:49 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2014-09-28 21:10 - 2013-01-13 21:48 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2014-09-28 21:10 - 2013-01-13 21:46 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2014-09-28 21:10 - 2013-01-13 21:43 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-09-28 21:10 - 2013-01-13 21:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2014-09-28 21:10 - 2013-01-13 21:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2014-09-28 21:10 - 2013-01-13 21:37 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-09-28 21:10 - 2013-01-13 21:25 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2014-09-28 21:10 - 2013-01-13 21:24 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2014-09-28 21:10 - 2013-01-13 21:24 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2014-09-28 21:10 - 2013-01-13 21:20 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2014-09-28 21:10 - 2013-01-13 21:20 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2014-09-28 21:10 - 2013-01-13 21:15 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-09-28 21:10 - 2013-01-13 21:10 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-09-28 21:10 - 2013-01-13 21:02 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-09-28 21:10 - 2013-01-13 20:34 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2014-09-28 21:10 - 2013-01-13 20:32 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-09-28 21:10 - 2013-01-13 20:09 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2014-09-28 21:10 - 2013-01-13 19:26 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2014-09-28 21:10 - 2013-01-13 19:05 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2014-09-28 21:10 - 2013-01-04 08:11 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2014-09-28 21:10 - 2013-01-04 08:11 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2014-09-28 21:01 - 2014-09-28 22:50 - 00035949 _____ () C:\Windows\IE11_main.log 2014-09-28 20:27 - 2014-09-28 20:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-09-28 20:27 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys 2014-09-28 20:26 - 2014-09-28 20:27 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-09-28 20:26 - 2014-09-28 20:27 - 00000000 ____D () C:\Program Files\iTunes 2014-09-28 20:26 - 2014-09-28 20:27 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-09-28 20:26 - 2014-09-28 20:26 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2014-09-28 20:26 - 2014-09-28 20:26 - 00000000 ____D () C:\Windows\System32\Tasks\Apple 2014-09-28 20:26 - 2014-09-28 20:26 - 00000000 ____D () C:\Program Files\iPod 2014-09-28 20:26 - 2014-09-28 20:26 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-09-28 20:25 - 2014-09-28 20:25 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-09-28 20:25 - 2014-09-28 20:25 - 00000000 ____D () C:\Program Files\Bonjour 2014-09-28 20:25 - 2014-09-28 20:25 - 00000000 ____D () C:\Program Files (x86)\Bonjour 2014-09-25 08:51 - 2014-10-05 22:13 - 00001314 _____ () C:\Windows\fsav_db_setup.log 2014-09-25 08:50 - 2014-10-05 22:13 - 01790220 _____ () C:\Windows\FSSFM.log 2014-09-25 08:50 - 2014-10-05 22:13 - 01609838 _____ () C:\Windows\FSSETUP.log 2014-09-25 08:50 - 2014-10-05 22:13 - 00272154 _____ () C:\Windows\FSPROD.log 2014-09-25 08:50 - 2014-10-05 22:13 - 00176978 _____ () C:\Windows\RunSetup.log 2014-09-25 08:50 - 2014-10-05 22:13 - 00141419 _____ () C:\Windows\FSAVINST.LOG 2014-09-25 08:50 - 2014-10-05 22:13 - 00009874 _____ () C:\Windows\FSAVCSIN.LOG 2014-09-25 08:50 - 2014-10-05 22:13 - 00004230 _____ () C:\Windows\fstnbins.LOG 2014-09-25 08:50 - 2014-10-05 22:12 - 00038656 _____ () C:\Windows\fspplugin.log 2014-09-25 08:48 - 2014-10-05 22:11 - 00000000 ____D () C:\Program Files (x86)\F-Secure 2014-09-24 23:30 - 2014-10-05 21:37 - 00754232 _____ () C:\Windows\PFRO.log 2014-09-24 21:21 - 2014-09-25 08:41 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-09-24 21:19 - 2014-10-05 22:13 - 04127298 _____ () C:\Windows\FSISU.log 2014-09-24 21:19 - 2014-10-05 22:13 - 00737784 _____ () C:\Windows\FSDEPH.log 2014-09-24 21:19 - 2014-10-05 22:13 - 00016658 _____ () C:\Windows\FSGKIAIN.log 2014-09-24 21:19 - 2014-10-05 22:13 - 00007222 _____ () C:\Windows\FSLDIN.LOG 2014-09-24 21:19 - 2014-10-05 22:13 - 00003257 _____ () C:\Windows\fsavunin.log 2014-09-24 21:19 - 2014-10-05 21:29 - 00502671 _____ () C:\Windows\FSUNINST.log 2014-09-24 21:19 - 2014-10-05 21:29 - 00026266 _____ () C:\Windows\uninstaller.log 2014-09-24 21:19 - 2014-10-05 21:29 - 00000985 _____ () C:\Windows\fsavunin_2.log 2014-09-24 21:19 - 2014-09-24 21:19 - 00000812 _____ () C:\Windows\daasunin.LOG 2014-09-21 09:28 - 2014-09-25 09:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-21 09:14 - 2014-10-02 19:12 - 00000063 _____ () C:\Users\Dario\Desktop\ib.txt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-14 11:56 - 2010-11-25 19:27 - 01598411 _____ () C:\Windows\WindowsUpdate.log 2014-10-14 11:56 - 2009-07-14 06:45 - 00013664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-14 11:56 - 2009-07-14 06:45 - 00013664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-14 11:49 - 2014-08-09 09:27 - 00010106 _____ () C:\Windows\setupact.log 2014-10-14 11:49 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-14 11:38 - 2010-11-25 19:40 - 00003938 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{737607F8-836A-4C0C-B675-CAA71288B56F} 2014-10-14 11:31 - 2014-08-16 15:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-13 09:19 - 2013-01-27 18:46 - 00000000 ____D () C:\Users\Dario\AppData\Local\Spotify 2014-10-13 09:19 - 2013-01-27 18:12 - 00000000 ____D () C:\Users\Dario\AppData\Roaming\Spotify 2014-10-10 11:12 - 2014-09-06 14:41 - 00000000 ____D () C:\Users\Dario\Desktop\Bewerbung NEU ab 2014 2014-10-10 09:17 - 2013-04-12 20:25 - 00370846 _____ () C:\test.xml 2014-10-05 22:13 - 2014-04-10 21:40 - 00000000 ____D () C:\Users\Dario\AppData\Local\F-Secure 2014-10-05 22:13 - 2012-12-10 14:49 - 00000000 ____D () C:\ProgramData\F-Secure 2014-10-05 22:12 - 2012-12-10 15:01 - 00020560 _____ () C:\Windows\prodsett_copy.ini 2014-10-04 13:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-09-30 17:16 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-09-30 17:14 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-09-28 23:40 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-09-28 23:24 - 2009-07-14 06:45 - 00443352 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-09-28 23:05 - 2010-07-12 22:26 - 00000000 ____D () C:\Windows\Panther 2014-09-28 23:02 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-09-28 22:10 - 2010-07-31 01:24 - 00703340 _____ () C:\Windows\system32\perfh007.dat 2014-09-28 22:10 - 2010-07-31 01:24 - 00151766 _____ () C:\Windows\system32\perfc007.dat 2014-09-28 22:10 - 2009-07-14 07:13 - 01631944 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-28 22:07 - 2013-05-15 19:51 - 00000000 ___RD () C:\Users\Dario\Dropbox 2014-09-28 22:06 - 2013-05-15 19:46 - 00000000 ____D () C:\Users\Dario\AppData\Roaming\Dropbox 2014-09-28 21:17 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-09-28 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK 2014-09-28 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR 2014-09-28 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\zh-HK 2014-09-28 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\tr-TR 2014-09-28 20:26 - 2010-12-28 19:08 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-09-28 20:25 - 2010-12-28 19:07 - 00000000 ____D () C:\ProgramData\Apple 2014-09-25 18:23 - 2012-05-02 20:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-09-24 23:38 - 2014-03-26 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-09-15 16:00 - 2011-07-20 21:12 - 00000000 ____D () C:\Users\Dario\Documents\Bewerbung Dario_NICHT LÖSCHEN Some content of TEMP: ==================== C:\Users\Dario\AppData\Local\Temp\cleanup_tool.exe C:\Users\Dario\AppData\Local\Temp\fsc6096.tmp.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-08 09:08 ==================== End Of Log ============================ leider funktioniert das update aber immer noch nicht und immer noch die gleiche fehlermeldung |
15.10.2014, 09:42 | #28 |
/// the machine /// TB-Ausbilder | Programme haben keinen Internetzugriff Revo Uninstaller - Download - Filepony damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.mozilla.org/de/kb/fi...einfach-loesen Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*'))%20%7B%20return%20'PROXY%20us10.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000%3B%20PROXY%20us02.sq.proxmate.me%3A8000%3B%20PROXY%20us11.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us03.sq.proxmate.me%3A8000%3B%20PROXY%20us06.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000%3B%20PROXY%20us07.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF NetworkProxy: "type", 2 Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.10.2014, 08:50 | #29 |
| Programme haben keinen Internetzugriff Jetzt habe ich wie in der Anleitung, Firefox deinstallieren mit allen Komponenten. Habe vorher aber noch ff Installationsprogramm heruntergeladen damit ich es wieder installieren kann. Das funktioniert aber nicht da wieder keine Verbindung zum Internet aufgebaut wird (das grundprpblem) ich komme jetzt überhaupt nicht mehr ins Internet, da der Internet Explorer ja auch nicht geht -.- Was soll ich jetzt machen? |
17.10.2014, 20:40 | #30 |
/// the machine /// TB-Ausbilder | Programme haben keinen Internetzugriff Du hast FF jetzt installiert und der geht auch nicht online? Öffne mal cmd uns schick nen ping an Google, geht das?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |