|
Plagegeister aller Art und deren Bekämpfung: Programme haben keinen InternetzugriffWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
18.10.2014, 11:15 | #31 |
| Programme haben keinen Internetzugriff also das installationsprogramm von ff läd ja daten zur installation im internet runter, aber das besteht das eigentliche problem, programme können nicht auf das internet zugreifen. habe mir jetzt ein offline installer von ff besorgt und konnte den browser installieren. konnte nun die schritte so ausführen, wie du es mir geschrieben hast: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-09-2014 02 Ran by Dario at 2014-10-18 11:46:39 Run:2 Running from C:\Users\Dario\Desktop Loaded Profile: Dario (Available profiles: Dario) Boot Mode: Normal ============================================== Content of fixlist: ***************** FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*'))%20%7B%20return%20'PROXY%20us10.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000%3B%20PROXY%20us02.sq.proxmate.me%3A8000%3B%20PROXY%20us11.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us03.sq.proxmate.me%3A8000%3B%20PROXY%20us06.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000%3B%20PROXY%20us07.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF NetworkProxy: "type", 2 ***************** Firefox Proxy settings were reset. Firefox Proxy settings were reset. ==== End of Fixlog ==== FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-09-2014 02 (ATTENTION: ====> FRST version is 20 days old and could be outdated) Ran by Dario (administrator) on DARIO-VAIO on 18-10-2014 11:47:00 Running from C:\Users\Dario\Desktop Loaded Profile: Dario (Available profiles: Dario) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\fshoster32.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\CCF_Reputation\fsorsp.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\fsgk32.exe (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\fssm32.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSMA32.EXE (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSHDLL64.EXE (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Spotify Ltd) C:\Users\Dario\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\fshoster32.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSM32.EXE (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10775584 2010-05-31] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2040352 2010-05-31] (Realtek Semiconductor) HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [212480 2010-05-31] (Alps Electric Co., Ltd.) HKLM\...\Run: [Onboard] => C:\Program Files\Western Digital\WD SmartWare\WDSmartWare.exe [3165040 2013-08-14] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-03-12] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [600928 2010-06-01] (Sony Corporation) HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [673136 2010-05-31] (Sony Corporation) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.) HKLM-x32\...\Run: [F-Secure Hoster (666)] => C:\Program Files (x86)\F-Secure\fshoster32.exe [187432 2014-07-08] (F-Secure Corporation) HKLM-x32\...\Run: [F-Secure Manager] => C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSM32.EXE [310312 2014-06-24] (F-Secure Corporation) HKLM-x32\...\Run: [WD Drive Unlocker] => C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe [1694080 2013-07-10] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5537136 2013-08-14] (Western Digital Technologies, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3810040113-3366235107-2524779152-1000\...\Run: [Spotify Web Helper] => C:\Users\Dario\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1245752 2014-09-21] (Spotify Ltd) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => No File ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {791387CC-FD3D-4649-A362-23DEFED0F29D} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices SearchScopes: HKCU - {C909D0DC-BB0B-4692-8A78-5DFC11EE1066} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-9/4?satitle={searchTerms} SearchScopes: HKCU - {CCFDB796-99E0-4AE7-B5CC-B72FBA91483C} URL = hxxp://de.shopping.com/?linkin_id=8056363 BHO: F-Secure Browsing Protection -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https64.dll (F-Secure Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: F-Secure Browsing Protection -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll (F-Secure Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll (Microsoft Corporation) Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\y0ru0gfl.default-1413625245269 FF Homepage: google.de FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [{99e13caf-b79e-4df2-90f8-62f471dc9ec8}] - C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\bin\browser\deploy\fs_firefox_https FF Extension: Browsing Protection - C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\bin\browser\deploy\fs_firefox_https [2014-10-05] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] - C:/Program Files (x86)/F-Secure/apps/CCF_Scanning/bin/browser/install/fs_chrome_https/fs_chrome_https.crx [2014-06-25] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 fshoster; C:\Program Files (x86)\F-Secure\fshoster32.exe [187432 2014-07-08] (F-Secure Corporation) R3 FSMA; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Common\FSMA32.EXE [216104 2014-06-24] (F-Secure Corporation) R2 FSORSPClient; C:\Program Files (x86)\F-Secure\apps\CCF_Reputation\fsorsp.exe [60456 2014-06-24] (F-Secure Corporation) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [851824 2010-06-17] (Sony Corporation) R2 VSNService; C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [836608 2010-06-08] (Sony Corporation) [File not signed] R3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1642544 2014-02-27] (Sony Corporation) R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2013-08-14] (Western Digital Technologies, Inc.) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [270704 2013-07-10] (Western Digital Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R3 F-Secure Gatekeeper; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [203304 2014-10-05] (F-Secure Corporation) R1 F-Secure HIPS; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\HIPS\drivers\fshs.sys [69960 2014-10-05] (F-Secure Corporation) R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [56016 2014-10-05] () R3 fsni; C:\Program Files (x86)\F-Secure\apps\CCF_Scanning\bin\fsni64.sys [89640 2014-10-05] (F-Secure Corporation) R1 fsvista; C:\Program Files (x86)\F-Secure\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys [13352 2014-06-24] () S3 igfx; C:\Windows\System32\DRIVERS\igdkmd64.sys [10326784 2010-06-24] (Intel Corporation) [File not signed] S3 IntcDAud; C:\Windows\System32\DRIVERS\IntcDAud.sys [271872 2010-06-24] (Intel(R) Corporation) [File not signed] S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl64.sys [22528 2011-08-02] (Apple Inc.) [File not signed] S3 VBTUSB; C:\Windows\System32\Drivers\VBTUSB.sys [14848 2010-06-17] (Sony Corporation) [File not signed] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 vpnva; system32\DRIVERS\vpnva64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-18 11:47 - 2014-10-18 11:47 - 00016318 _____ () C:\Users\Dario\Desktop\FRST.txt 2014-10-18 11:40 - 2014-10-18 11:40 - 00000000 ____D () C:\Users\Dario\Desktop\Alte Firefox-Daten 2014-10-18 11:39 - 2014-10-18 11:39 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-10-18 11:39 - 2014-10-18 11:39 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-10-18 11:39 - 2014-10-18 11:39 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-10-18 11:31 - 2014-10-18 11:31 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Dario\Desktop\revosetup95.exe 2014-10-17 16:08 - 2014-10-17 16:08 - 36254312 _____ () C:\Users\Dario\Desktop\Firefox Setup 33.0.exe 2014-10-17 14:49 - 2014-10-17 14:49 - 00000000 ____D () C:\Users\Dario\Desktop\externe Festplatte 2014-10-17 14:45 - 2014-10-17 14:45 - 00000000 ____D () C:\Windows\System32\Tasks\Western Digital 2014-10-17 14:44 - 2014-10-18 11:21 - 00008192 _____ () C:\Windows\SysWOW64\WDPABKP.dat 2014-10-17 14:44 - 2014-10-17 14:44 - 00000000 ____D () C:\Users\Dario\AppData\Local\Western_Digital_Technolog 2014-10-17 14:44 - 2014-10-17 14:44 - 00000000 ____D () C:\Users\Dario\AppData\Local\Western Digital 2014-10-17 14:43 - 2014-10-17 14:44 - 00014218 _____ () C:\Windows\DPINST.LOG 2014-10-17 14:43 - 2014-10-17 14:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital 2014-10-17 14:43 - 2014-10-17 14:43 - 00000000 ____D () C:\Program Files\Western Digital 2014-10-17 14:43 - 2014-10-17 14:43 - 00000000 ____D () C:\Program Files\Common Files\Western Digital 2014-10-17 14:43 - 2014-10-17 14:43 - 00000000 ____D () C:\Program Files (x86)\Western Digital 2014-10-17 14:42 - 2014-10-17 14:44 - 00000000 ____D () C:\ProgramData\Western Digital 2014-10-17 10:48 - 2014-10-17 10:49 - 00001385 _____ () C:\Users\Dario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-10-17 09:26 - 2014-10-18 11:35 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-10-05 22:13 - 2014-10-05 22:18 - 00056016 _____ () C:\Windows\system32\Drivers\fsbts.sys 2014-10-05 22:10 - 2014-10-05 22:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\F-Secure 2014-10-05 22:02 - 2014-10-05 22:03 - 00048426 _____ () C:\Users\Dario\Desktop\Result.txt 2014-10-05 20:16 - 2014-10-05 20:17 - 00047302 _____ () C:\Users\Dario\Desktop\Result 1.txt 2014-10-05 20:12 - 2014-10-05 20:12 - 00401920 _____ (Farbar) C:\Users\Dario\Desktop\MiniToolBox.exe 2014-10-03 15:38 - 2014-10-03 15:38 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-10-03 15:32 - 2014-10-03 15:32 - 02347384 _____ (ESET) C:\Users\Dario\Desktop\esetsmartinstaller_deu.exe 2014-10-03 15:32 - 2014-10-03 15:32 - 00854417 _____ () C:\Users\Dario\Desktop\SecurityCheck.exe 2014-10-02 10:28 - 2014-10-02 10:28 - 00000000 ____D () C:\Windows\ERUNT 2014-10-02 10:21 - 2014-10-02 10:22 - 00000000 ____D () C:\AdwCleaner 2014-10-02 09:59 - 2014-10-02 09:59 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-02 09:58 - 2014-10-02 09:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-10-02 09:58 - 2014-10-02 09:58 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-10-02 09:58 - 2014-10-02 09:58 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-10-02 09:58 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-10-02 09:58 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-10-02 09:58 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-10-02 09:45 - 2014-10-18 11:45 - 00000000 ____D () C:\Users\Dario\Desktop\Neuer Ordner 2014-09-30 17:03 - 2014-09-30 17:16 - 00000000 ____D () C:\Qoobox 2014-09-30 17:03 - 2014-09-30 17:15 - 00000000 ____D () C:\Windows\erdnt 2014-09-30 17:03 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-09-30 17:03 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-09-30 17:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-09-30 17:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-09-30 17:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-09-30 17:03 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-09-30 17:03 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-09-30 17:03 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-09-29 19:04 - 2014-10-18 11:47 - 00000000 ____D () C:\FRST 2014-09-29 19:02 - 2014-09-29 19:02 - 02108928 _____ (Farbar) C:\Users\Dario\Desktop\FRST64.exe 2014-09-28 23:19 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-09-28 23:19 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-09-28 23:19 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-09-28 23:15 - 2014-09-28 23:15 - 00182912 _____ () C:\Windows\msxml4-KB2758694-deu.LOG 2014-09-28 22:50 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2014-09-28 22:47 - 2014-09-28 22:47 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-09-28 22:47 - 2014-09-28 22:47 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-09-28 22:47 - 2014-09-28 22:47 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-09-28 22:47 - 2014-09-28 22:47 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-09-28 22:47 - 2014-09-28 22:47 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-09-28 22:47 - 2014-09-28 22:47 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-09-28 22:47 - 2014-09-28 22:47 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-09-28 22:47 - 2014-09-28 22:47 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-09-28 22:47 - 2014-09-28 22:47 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-09-28 22:47 - 2014-09-28 22:47 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-09-28 22:47 - 2014-09-28 22:47 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-09-28 22:47 - 2014-09-28 22:47 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-09-28 22:47 - 2014-09-28 22:47 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-09-28 21:29 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2014-09-28 21:29 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2014-09-28 21:24 - 2012-11-23 05:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe 2014-09-28 21:10 - 2013-01-13 23:17 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:17 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:35 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:35 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:35 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-09-28 21:10 - 2013-01-13 22:22 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-09-28 21:10 - 2013-01-13 22:20 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2014-09-28 21:10 - 2013-01-13 22:09 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2014-09-28 21:10 - 2013-01-13 22:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2014-09-28 21:10 - 2013-01-13 21:59 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2014-09-28 21:10 - 2013-01-13 21:58 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2014-09-28 21:10 - 2013-01-13 21:54 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2014-09-28 21:10 - 2013-01-13 21:53 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2014-09-28 21:10 - 2013-01-13 21:53 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2014-09-28 21:10 - 2013-01-13 21:51 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-09-28 21:10 - 2013-01-13 21:49 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2014-09-28 21:10 - 2013-01-13 21:48 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2014-09-28 21:10 - 2013-01-13 21:46 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2014-09-28 21:10 - 2013-01-13 21:43 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-09-28 21:10 - 2013-01-13 21:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2014-09-28 21:10 - 2013-01-13 21:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2014-09-28 21:10 - 2013-01-13 21:37 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-09-28 21:10 - 2013-01-13 21:25 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2014-09-28 21:10 - 2013-01-13 21:24 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2014-09-28 21:10 - 2013-01-13 21:24 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2014-09-28 21:10 - 2013-01-13 21:20 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2014-09-28 21:10 - 2013-01-13 21:20 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2014-09-28 21:10 - 2013-01-13 21:15 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-09-28 21:10 - 2013-01-13 21:10 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-09-28 21:10 - 2013-01-13 21:02 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-09-28 21:10 - 2013-01-13 20:34 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2014-09-28 21:10 - 2013-01-13 20:32 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-09-28 21:10 - 2013-01-13 20:09 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2014-09-28 21:10 - 2013-01-13 19:26 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2014-09-28 21:10 - 2013-01-13 19:05 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2014-09-28 21:10 - 2013-01-04 08:11 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2014-09-28 21:10 - 2013-01-04 08:11 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2014-09-28 21:01 - 2014-09-28 22:50 - 00035949 _____ () C:\Windows\IE11_main.log 2014-09-28 20:27 - 2014-09-28 20:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-09-28 20:27 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys 2014-09-28 20:26 - 2014-09-28 20:27 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-09-28 20:26 - 2014-09-28 20:27 - 00000000 ____D () C:\Program Files\iTunes 2014-09-28 20:26 - 2014-09-28 20:27 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-09-28 20:26 - 2014-09-28 20:26 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2014-09-28 20:26 - 2014-09-28 20:26 - 00000000 ____D () C:\Windows\System32\Tasks\Apple 2014-09-28 20:26 - 2014-09-28 20:26 - 00000000 ____D () C:\Program Files\iPod 2014-09-28 20:26 - 2014-09-28 20:26 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-09-28 20:25 - 2014-09-28 20:25 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-09-28 20:25 - 2014-09-28 20:25 - 00000000 ____D () C:\Program Files\Bonjour 2014-09-28 20:25 - 2014-09-28 20:25 - 00000000 ____D () C:\Program Files (x86)\Bonjour 2014-09-25 08:51 - 2014-10-05 22:13 - 00001314 _____ () C:\Windows\fsav_db_setup.log 2014-09-25 08:50 - 2014-10-05 22:13 - 01790220 _____ () C:\Windows\FSSFM.log 2014-09-25 08:50 - 2014-10-05 22:13 - 01609838 _____ () C:\Windows\FSSETUP.log 2014-09-25 08:50 - 2014-10-05 22:13 - 00272154 _____ () C:\Windows\FSPROD.log 2014-09-25 08:50 - 2014-10-05 22:13 - 00176978 _____ () C:\Windows\RunSetup.log 2014-09-25 08:50 - 2014-10-05 22:13 - 00141419 _____ () C:\Windows\FSAVINST.LOG 2014-09-25 08:50 - 2014-10-05 22:13 - 00009874 _____ () C:\Windows\FSAVCSIN.LOG 2014-09-25 08:50 - 2014-10-05 22:13 - 00004230 _____ () C:\Windows\fstnbins.LOG 2014-09-25 08:50 - 2014-10-05 22:12 - 00038656 _____ () C:\Windows\fspplugin.log 2014-09-25 08:48 - 2014-10-17 10:39 - 00000000 ____D () C:\Program Files (x86)\F-Secure 2014-09-24 23:30 - 2014-10-05 21:37 - 00754232 _____ () C:\Windows\PFRO.log 2014-09-24 21:21 - 2014-09-25 08:41 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-09-24 21:19 - 2014-10-05 22:13 - 04127298 _____ () C:\Windows\FSISU.log 2014-09-24 21:19 - 2014-10-05 22:13 - 00737784 _____ () C:\Windows\FSDEPH.log 2014-09-24 21:19 - 2014-10-05 22:13 - 00016658 _____ () C:\Windows\FSGKIAIN.log 2014-09-24 21:19 - 2014-10-05 22:13 - 00007222 _____ () C:\Windows\FSLDIN.LOG 2014-09-24 21:19 - 2014-10-05 22:13 - 00003257 _____ () C:\Windows\fsavunin.log 2014-09-24 21:19 - 2014-10-05 21:29 - 00502671 _____ () C:\Windows\FSUNINST.log 2014-09-24 21:19 - 2014-10-05 21:29 - 00026266 _____ () C:\Windows\uninstaller.log 2014-09-24 21:19 - 2014-10-05 21:29 - 00000985 _____ () C:\Windows\fsavunin_2.log 2014-09-24 21:19 - 2014-09-24 21:19 - 00000812 _____ () C:\Windows\daasunin.LOG 2014-09-21 09:14 - 2014-10-18 11:33 - 00000159 _____ () C:\Users\Dario\Desktop\ib.txt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-18 11:31 - 2014-08-16 15:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-18 11:31 - 2010-11-25 19:27 - 01611761 _____ () C:\Windows\WindowsUpdate.log 2014-10-18 11:31 - 2009-07-14 06:45 - 00013664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-18 11:31 - 2009-07-14 06:45 - 00013664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-18 11:21 - 2014-08-09 09:27 - 00010330 _____ () C:\Windows\setupact.log 2014-10-18 11:21 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-17 16:22 - 2010-11-25 19:40 - 00003938 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{737607F8-836A-4C0C-B675-CAA71288B56F} 2014-10-17 16:20 - 2010-07-31 01:24 - 00703340 _____ () C:\Windows\system32\perfh007.dat 2014-10-17 16:20 - 2010-07-31 01:24 - 00151766 _____ () C:\Windows\system32\perfc007.dat 2014-10-17 16:20 - 2009-07-14 07:13 - 01631944 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-10-17 14:26 - 2013-05-15 19:51 - 00000000 ___RD () C:\Users\Dario\Dropbox 2014-10-17 11:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-10-17 10:34 - 2010-11-25 19:37 - 00000000 ____D () C:\Users\Dario 2014-10-17 10:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-10-17 10:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat 2014-10-16 09:26 - 2014-09-06 14:41 - 00000000 ____D () C:\Users\Dario\Desktop\Bewerbung NEU ab 2014 2014-10-13 09:19 - 2013-01-27 18:46 - 00000000 ____D () C:\Users\Dario\AppData\Local\Spotify 2014-10-13 09:19 - 2013-01-27 18:12 - 00000000 ____D () C:\Users\Dario\AppData\Roaming\Spotify 2014-10-10 09:17 - 2013-04-12 20:25 - 00370846 _____ () C:\test.xml 2014-10-05 22:13 - 2014-04-10 21:40 - 00000000 ____D () C:\Users\Dario\AppData\Local\F-Secure 2014-10-05 22:13 - 2012-12-10 14:49 - 00000000 ____D () C:\ProgramData\F-Secure 2014-10-05 22:12 - 2012-12-10 15:01 - 00020560 _____ () C:\Windows\prodsett_copy.ini 2014-10-04 13:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-09-30 17:16 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-09-30 17:14 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-09-28 23:24 - 2009-07-14 06:45 - 00443352 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-09-28 23:05 - 2010-07-12 22:26 - 00000000 ____D () C:\Windows\Panther 2014-09-28 23:02 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-09-28 22:06 - 2013-05-15 19:46 - 00000000 ____D () C:\Users\Dario\AppData\Roaming\Dropbox 2014-09-28 21:17 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-09-28 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK 2014-09-28 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR 2014-09-28 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\zh-HK 2014-09-28 21:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\tr-TR 2014-09-28 20:26 - 2010-12-28 19:08 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-09-28 20:25 - 2010-12-28 19:07 - 00000000 ____D () C:\ProgramData\Apple 2014-09-24 23:38 - 2014-03-26 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Some content of TEMP: ==================== C:\Users\Dario\AppData\Local\Temp\cleanup_tool.exe C:\Users\Dario\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplsij1r.dll C:\Users\Dario\AppData\Local\Temp\fsc6096.tmp.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-16 11:27 ==================== End Of Log ============================ --- --- --- --- --- --- bsp. windows update funktioniert wieder nicht und immer noch der gleiche fehler |
18.10.2014, 20:38 | #32 |
/// the machine /// TB-Ausbilder | Programme haben keinen Internetzugriff Ausser WIndows Updates, was machen jetzt Downloads im Browser?
__________________
__________________ |
20.10.2014, 08:14 | #33 |
| Programme haben keinen Internetzugriff ich meine das den installer, der läd ja bei der installation daten herunter um das programm zu intsllieren (während der intsallation). die installer sind ja in der regel keine offline installer.
__________________der normale installer hat dementsprechend nicht funktioniert da dieser keine intallationsdaten laden konnte, daher musste ich einen offline installer besorgen. |
20.10.2014, 18:16 | #34 |
/// the machine /// TB-Ausbilder | Programme haben keinen Internetzugriff Windows Scheibe da?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.10.2014, 18:49 | #35 |
| Programme haben keinen Internetzugriff Hey Schrauber, meinst du ob ich Windows auf CD-ROM habe? Leider nein, da es sich um einen Laptop handelt und damals keine dabei war. |
21.10.2014, 17:01 | #36 |
/// the machine /// TB-Ausbilder | Programme haben keinen Internetzugriff
__________________ --> Programme haben keinen Internetzugriff |