Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 20.10.2014, 21:00   #16
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Meldung  RunDLL Program Files (x86)\HomeTab\TBUpdater.dll - Standard

Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll



Zitat:
Malware Datenbank: v2014.09.19.05
Ging das Sig-Update nicht?
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 21.10.2014, 00:57   #17
Martin56
 
Meldung  RunDLL Program Files (x86)\HomeTab\TBUpdater.dll - Standard

Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll



Nö, soll ich´s nochmal versuchen?

Ich muss ihn wohl immer zweimal bitten
Hat jetzt 2014.10.20.06 - Suchlauf ist wieder aktiv

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 20.10.2014
Suchlauf-Zeit: 22:07:09
Logdatei: mbam.2.txt
Administrator: Ja

Version: 2.00.3.1025
Malware Datenbank: v2014.10.20.06
Rootkit Datenbank: v2014.10.17.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Martin Rinke

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 390689
Verstrichene Zeit: 20 Min, 21 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(Keine schädliche Elemente erkannt)

Module: 0
(Keine schädliche Elemente erkannt)

Registrierungsschlüssel: 0
(Keine schädliche Elemente erkannt)

Registrierungswerte: 0
(Keine schädliche Elemente erkannt)

Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)

Ordner: 0
(Keine schädliche Elemente erkannt)

Dateien: 0
(Keine schädliche Elemente erkannt)

Physische Sektoren: 0
(Keine schädliche Elemente erkannt)


(end)
         
Sorry, der ist erst bei 85%, aber 15 Meldungen. Durchforstet die externe HDD, hängt leider noch an einen USB 2.0

Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=4b9f1dba6915a34d8348ba96c28e066a
# engine=20691
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-10-20 11:50:16
# local_time=2014-10-21 01:50:16 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 22249 165478866 0 0
# scanned=288171
# found=31
# cleaned=0
# scan_time=17630
sh=E9C216ADF17020C604FE37B57EE9EAEE43C846FB ft=0 fh=0000000000000000 vn="VBS/Runner.NBW Trojaner" ac=I fn="C:\Users\Martin Rinke\9zol3d5lnss4\23092.vbs"
sh=EAE2784C9115FE9CFA44A116B74E72C1BCCFA7F6 ft=1 fh=2e79e77116fe19c4 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Martin Rinke\Downloads\MyPhoneExplorer_Setup_1.8.5.exe"
sh=77801D0E0DC02E8C50CDC73562F4D7F13FC1C18B ft=0 fh=0000000000000000 vn="Win32/Conduit.SearchProtect.A evtl. unerwünschte Anwendung" ac=I fn="H:\Katja\Anwendungsdaten\SearchProtect\ffprotect\application.js"
sh=170ACC25B35BA845064591DF61F2D52142823738 ft=0 fh=0000000000000000 vn="Win32/Conduit.SearchProtect.A evtl. unerwünschte Anwendung" ac=I fn="H:\Katja\Anwendungsdaten\SearchProtect\ffprotect\nsprotector.js"
sh=8BE4C277A62F2400C3B0A20F39297D310774E2AC ft=1 fh=d69c639933d87dfe vn="Win32/Toolbar.SearchSuite evtl. unerwünschte Anwendung" ac=I fn="H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter (1).exe"
sh=8BE4C277A62F2400C3B0A20F39297D310774E2AC ft=1 fh=d69c639933d87dfe vn="Win32/Toolbar.SearchSuite evtl. unerwünschte Anwendung" ac=I fn="H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter.exe"
sh=CFCF0ADB9C1CF62D655041B7082EF3B017E1C3EF ft=1 fh=c3cf7631b8bb7034 vn="Win32/LoadTubes.D evtl. unerwünschte Anwendung" ac=I fn="H:\Katja\Eigene Dateien\Downloads\setup_codec_3dx.exe"
sh=373374C26F18E43E9B7452405CC2A5DD4AC9F70E ft=1 fh=e95b08ab27f34774 vn="Win32/SoftonicDownloader.D evtl. unerwünschte Anwendung" ac=I fn="H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_free-youtube-download.exe"
sh=7A9A81DF947762FEEF571DD4EA78151F45A93FDC ft=1 fh=b435d59e704945b6 vn="Win32/SoftonicDownloader.D evtl. unerwünschte Anwendung" ac=I fn="H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_vso-downloader.exe"
sh=890F1EDBA898E362BD225666AE3BDF862B343492 ft=1 fh=51f91afe2f642905 vn="Mehrere Bedrohungen" ac=I fn="H:\Katja\Eigene Dateien\Downloads\video_downloader.exe"
sh=F6B71E6DF0EF3ED6289EE4B8A00F6A07A6A9D3D0 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Iminent.I evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2013-10-09 205300\Backup Files 2013-10-09 205300\Backup files 1.zip"
sh=D93DFB48F135DD4DE95CB82544C3EDA3BAD2C753 ft=1 fh=d1199f70f2992f69 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2013-10-09 205300\Backup Files 2013-10-09 205300\C\Users\Martin Rinke\AppData\Local\DownloadGuide\Offers\plus-hd-3-8.exe"
sh=38A38A0A5F21B87E2110E696B011AD4208388466 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Iminent.I evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2013-10-09 205300\Backup Files 2013-10-09 205300\C\Users\Martin Rinke\AppData\Roaming\Mozilla\Firefox\Profiles\5x1hhb18.default\extensions\webbooster@iminent.com.xpi"
sh=1E46D343C6FEEF369583003B0047CDC0970A7987 ft=1 fh=6d53e81a0b77d269 vn="Win32/Toolbar.Montiera.B evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2013-10-09 205300\Backup Files 2013-10-09 205300\C\Users\Martin Rinke\AppData\Roaming\Mozilla\Firefox\Profiles\5x1hhb18.default\extensions\ffxtlbr@iminent.com\uninstall.exe"
sh=A4C162AB072BACD82BEF5C23DFA743B8C57FC063 ft=0 fh=0000000000000000 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2013-10-16 121235\Backup Files 2013-10-16 121235\Backup files 2.zip"
sh=B1D9F6E9C42C0589D956AD40E9CF8C5B71237214 ft=0 fh=0000000000000000 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2013-11-18 213935\Backup Files 2013-11-18 213935\Backup files 2.zip"
sh=4336A730C03E3AAE359DB4F1C9EA7A4CB26BC674 ft=0 fh=0000000000000000 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-01-08 154935\Backup Files 2014-01-08 154935\Backup files 3.zip"
sh=8E32DBA7C7DE7B414B07D610076C895CD1BA5A3B ft=0 fh=0000000000000000 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-01-20 082853\Backup Files 2014-01-20 082853\Backup files 3.zip"
sh=40F27881F380661CC4FAB9E798C9E696080AC600 ft=0 fh=0000000000000000 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-01-20 082853\Backup Files 2014-01-20 082853\Backup files 6.zip"
sh=BE2E6F82869EBC3E604CD4B2467E8E56CD949EB7 ft=0 fh=0000000000000000 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-01-29 125128\Backup Files 2014-01-29 125128\Backup files 3.zip"
sh=0624A1478E8233B45843AF1BD39CD963A89E087A ft=0 fh=0000000000000000 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-01-29 125128\Backup Files 2014-01-29 125128\Backup files 6.zip"
sh=4A263C35EAC2E8D3444FD6F68974B0E31F48512E ft=0 fh=0000000000000000 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-04-03 125403\Backup Files 2014-04-03 125403\Backup files 3.zip"
sh=41C9F1EABF82ABF0C5D1162F3B1E17F955512368 ft=0 fh=0000000000000000 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-04-03 125403\Backup Files 2014-04-03 125403\Backup files 7.zip"
sh=48C692928C243EB297DF1F3A86D3B076F07527D0 ft=0 fh=0000000000000000 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-07-09 081309\Backup Files 2014-07-09 081309\Backup files 3.zip"
sh=1127255B84A61DA6E2FE42ED1EEA5ED5D4CDB914 ft=0 fh=0000000000000000 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-07-09 081309\Backup Files 2014-07-09 081309\Backup files 6.zip"
sh=E69DA8A766FBC786393D5BF3E5B0584B855E2260 ft=0 fh=0000000000000000 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-10-20 083256\Backup Files 2014-10-20 083256\Backup files 8.zip"
sh=7D4A3CA3A3789D1EA7530FE4727D6BA8E8B47B83 ft=1 fh=4d32dd9dfb87fc86 vn="Win32/Conduit.SearchProtect.E evtl. unerwünschte Anwendung" ac=I fn="H:\Sicherung 2013-09-29\Kerstin\Anwendungsdaten\SearchProtect\bin\CltMngSvc.exe"
sh=FC96B1F32B9320881BA847B4B84AF0EF096CB99D ft=1 fh=e2b5ce1f1ae776f7 vn="Win32/Conduit.SearchProtect.D evtl. unerwünschte Anwendung" ac=I fn="H:\Sicherung 2013-09-29\Kerstin\Anwendungsdaten\SearchProtect\bin\SPRunner.exe"
sh=8202466E1DE3A815AB172AFF4383E4BD94278DCF ft=1 fh=89f70014390bbe76 vn="Win32/Conduit.SearchProtect.S evtl. unerwünschte Anwendung" ac=I fn="H:\Sicherung 2013-09-29\Kerstin\Anwendungsdaten\SearchProtect\bin\uninstall.exe"
sh=77801D0E0DC02E8C50CDC73562F4D7F13FC1C18B ft=0 fh=0000000000000000 vn="Win32/Conduit.SearchProtect.A evtl. unerwünschte Anwendung" ac=I fn="H:\Sicherung 2013-09-29\Kerstin\Anwendungsdaten\SearchProtect\ffprotect\application.js"
sh=170ACC25B35BA845064591DF61F2D52142823738 ft=0 fh=0000000000000000 vn="Win32/Conduit.SearchProtect.A evtl. unerwünschte Anwendung" ac=I fn="H:\Sicherung 2013-09-29\Kerstin\Anwendungsdaten\SearchProtect\ffprotect\nsprotector.js"
         
Here we are!
__________________


Alt 21.10.2014, 14:52   #18
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Meldung  RunDLL Program Files (x86)\HomeTab\TBUpdater.dll - Standard

Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll



Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
C:\Users\Martin Rinke\9zol3d5lnss4
C:\Users\Martin Rinke\Downloads\MyPhoneExplorer_Setup_1.8.5.exe
H:\Katja\Anwendungsdaten\SearchProtect\ffprotect
H:\Katja\Anwendungsdaten\SearchProtect\ffprotect
H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter (1).exe
H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter.exe
H:\Katja\Eigene Dateien\Downloads\setup_codec_3dx.exe
H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_free-youtube-download.exe
H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_vso-downloader.exe
H:\Katja\Eigene Dateien\Downloads\video_downloader.exe
EmptyTemp:
Hosts:
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

__________________
__________________

Alt 21.10.2014, 21:09   #19
Martin56
 
Meldung  RunDLL Program Files (x86)\HomeTab\TBUpdater.dll - Standard

Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll



Moin cosinus,
schreibe hier von meinem Laptop. Zunächst vielen Dank für die Antwort. Heute morgen gegen 2:00 Uhr war der eset Virenscanner durch. Ich komme erst am Freitag wieder dazu, Deinem Rat zu folgen und die fixlist zu posten. Sorry, aber die Arbeit ruft, und ich bin bis Freitagabend nicht daheim. Mein Rechner bleibt bis dahin aus. Vielen vielen Dank bis dahin. CU on friday

Alt 25.10.2014, 22:02   #20
Martin56
 
Meldung  RunDLL Program Files (x86)\HomeTab\TBUpdater.dll - Standard

Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll



Moin cosinus, da bin ich wieder. Hier folgt der log
Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-10-2014
Ran by Martin Rinke at 2014-10-25 22:57:19 Run:3
Running from C:\Users\Martin Rinke\Downloads
Loaded Profiles: Martin Rinke & Acronis Agent User (Available profiles: Martin Rinke & Kerstin & Acronis Agent User)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\Users\Martin Rinke\9zol3d5lnss4
C:\Users\Martin Rinke\Downloads\MyPhoneExplorer_Setup_1.8.5.exe
H:\Katja\Anwendungsdaten\SearchProtect\ffprotect
H:\Katja\Anwendungsdaten\SearchProtect\ffprotect
H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter (1).exe
H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter.exe
H:\Katja\Eigene Dateien\Downloads\setup_codec_3dx.exe
H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_free-youtube-download.exe
H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_vso-downloader.exe
H:\Katja\Eigene Dateien\Downloads\video_downloader.exe
EmptyTemp:
Hosts:
     
*****************

"C:\Users\Martin Rinke\9zol3d5lnss4" => File/Directory not found.
"C:\Users\Martin Rinke\Downloads\MyPhoneExplorer_Setup_1.8.5.exe" => File/Directory not found.
"H:\Katja\Anwendungsdaten\SearchProtect\ffprotect" => File/Directory not found.
"H:\Katja\Anwendungsdaten\SearchProtect\ffprotect" => File/Directory not found.
"H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter (1).exe" => File/Directory not found.
"H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter.exe" => File/Directory not found.
"H:\Katja\Eigene Dateien\Downloads\setup_codec_3dx.exe" => File/Directory not found.
"H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_free-youtube-download.exe" => File/Directory not found.
"H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_vso-downloader.exe" => File/Directory not found.
"H:\Katja\Eigene Dateien\Downloads\video_downloader.exe" => File/Directory not found.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 6.4 MB temporary data.


The system needed a reboot. 

==== End of Fixlog ====
         


Alt 25.10.2014, 22:05   #21
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Meldung  RunDLL Program Files (x86)\HomeTab\TBUpdater.dll - Standard

Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll



Sieht soweit ok aus

Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat. Ist aber nur optional. Um Usertracking zu verhindern kann man gut die Firefox-Erweiterung Ghostery verwenden.

Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________
--> Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll

Alt 25.10.2014, 22:16   #22
Martin56
 
Meldung  RunDLL Program Files (x86)\HomeTab\TBUpdater.dll - Standard

Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll



Moin und danke für Deine Hilfe. Beim Starten poppt immer noch diese Meldung hoch:
Problem beim Starten von C:\Program Files (x86)\HomeTab\TBUpdate.dll
Das angegeben Modul wurde nicht gefunden.

Es beruhigt mich aber, dass das nicht weiter gefährlich ist.
Zwar ein büschen lästig, aber die Meldung lässt sich einfach wegklicken.

Alt 25.10.2014, 22:18   #23
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Meldung  RunDLL Program Files (x86)\HomeTab\TBUpdater.dll - Standard

Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll



Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Scan klicken

__________________
Logfiles bitte immer in CODE-Tags posten

Alt 25.10.2014, 22:26   #24
Martin56
 
Meldung  RunDLL Program Files (x86)\HomeTab\TBUpdater.dll - Standard

Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll



FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-10-2014
Ran by Martin Rinke (administrator) on MARTINRINKE-PC on 25-10-2014 23:23:10
Running from C:\Users\Martin Rinke\Downloads
Loaded Profiles: Martin Rinke & Acronis Agent User (Available profiles: Martin Rinke & Kerstin & Acronis Agent User)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Agent\agent.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Acronis) C:\Program Files (x86)\Acronis\ARSM\arsm.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Acronis) C:\Program Files (x86)\Acronis\BackupAndRecovery\mms.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Acronis) C:\Program Files (x86)\Acronis\TrayMonitor\TrayMonitor.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Vimicro Corporation) C:\Program Files (x86)\Vimicro Corporation\VMUVC\VMonitor.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Nitro PDF) C:\Program Files (x86)\Nitro PDF\Professional 7\NitroPDF.exe
(Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12936848 2012-07-13] (Realtek Semiconductor)
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [395736 2013-10-02] (Acronis)
HKLM\...\Run: [TrayMonitor.exe] => C:\Program Files (x86)\Acronis\TrayMonitor\TrayMonitor.exe [1498848 2013-10-02] (Acronis)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-16] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [VMonitorVMUVC] => C:\Program Files (x86)\Vimicro Corporation\VMUVC\VMonitor.exe [143360 2010-09-10] (Vimicro Corporation)
HKLM-x32\...\Run: [BackupAndRecoveryMonitor.exe] => C:\Program Files (x86)\Acronis\BackupAndRecovery\BackupAndRecoveryMonitor.exe [1561240 2013-10-02] (Acronis)
HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [1104608 2013-01-22] (Acronis)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1743648 2013-06-13] (Wondershare)
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [305088 2011-04-25] (Citrix Systems, Inc.)
HKU\S-1-5-21-4136266569-681284793-1319911660-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2010-08-12] (Acresso Corporation)
HKU\S-1-5-21-4136266569-681284793-1319911660-1000\...\Run: [w1Synt] => C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe [32768 2014-03-21] (Microsoft Corporation)
HKU\S-1-5-21-4136266569-681284793-1319911660-1000\...\Run: [GoogleChromeAutoLaunch_EAAF700B7549734D0B66A4B86C39037C] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [854344 2014-10-10] (Google Inc.)
HKU\S-1-5-21-4136266569-681284793-1319911660-1000\...\RunOnce: [Uninstall C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64"
HKU\S-1-5-21-4136266569-681284793-1319911660-1000\...\RunOnce: [Uninstall C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.4029.0217\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.4029.0217\amd64"
HKU\S-1-5-21-4136266569-681284793-1319911660-1000\...\MountPoints2: G - G:\LaunchU3.exe -a
HKU\S-1-5-21-4136266569-681284793-1319911660-1000\...\MountPoints2: {25358e3f-30b4-11e3-bfa4-b8975a476b92} - G:\LaunchU3.exe -a
Startup: C:\Users\Martin Rinke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ->  (No File)
Startup: C:\Users\Martin Rinke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\start.lnk
ShortcutTarget: start.lnk ->  (No File)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3218961A36BECE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://www.google.de/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab
SearchScopes: HKCU - URL hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms}
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=99&gid=1&dbCode=1&command={searchTerms}
SearchScopes: HKCU - TopResultURLFallback hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF ProfilePath: C:\Users\Martin Rinke\AppData\Roaming\Mozilla\Firefox\Profiles\5x1hhb18.default
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro PDF\Professional 7\npnitromozilla.dll ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CCMSDK.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\cgpcfg.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxlogging.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxmui.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icafile.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icalogon.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPCltInst11.dll (BroadSoft, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\sslsdk_b.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll (Citrix Systems, Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Personas Plus - C:\Users\Martin Rinke\AppData\Roaming\Mozilla\Firefox\Profiles\5x1hhb18.default\Extensions\personas@christopher.beard.xpi [2013-10-16]
FF Extension: Adblock Plus - C:\Users\Martin Rinke\AppData\Roaming\Mozilla\Firefox\Profiles\5x1hhb18.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-03]

Chrome: 
=======
CHR HomePage: Default -> https://www.xing.com/
CHR StartupUrls: Default -> "https://www.xing.com/de", "https://www.google.de/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default
CHR Extension: (TooManyTabs für Chrome) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\amigcgbheognjmfkaieeeadojiibgbdp [2014-07-29]
CHR Extension: (Google Docs) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-29]
CHR Extension: (Lucidchart diagrammer – Online) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\apboafhkiegglekeafbckfjldecefkhn [2014-07-29]
CHR Extension: (Google Drive) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-29]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-04]
CHR Extension: (Turn Off the Lights) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2014-07-29]
CHR Extension: (YouTube) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-29]
CHR Extension: (New york themes (sublimes city)) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\cchhdpienadooplffongnkgpdoojkfgb [2014-07-29]
CHR Extension: (Google-Suche) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-29]
CHR Extension: (Office Editor) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\gbkeegbaiigmenfmjfclcdgdpimamgkj [2014-09-29]
CHR Extension: (PDFescape Free PDF Editor) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\gdefoklganepljiopdnglodohlgfikkl [2014-07-29]
CHR Extension: (AdBlock) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-07-29]
CHR Extension: (Google Wallet) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-29]
CHR Extension: (Google Mail) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-29]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AcronisAgent; C:\Program Files (x86)\Common Files\Acronis\Agent\agent.exe [2059256 2012-12-29] (Acronis)
R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [806704 2014-10-16] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-10-16] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-16] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [994096 2014-10-16] (Avira Operations GmbH & Co. KG)
R2 ARSM; C:\Program Files (x86)\Acronis\ARSM\arsm.exe [5851192 2013-10-02] (Acronis)
R2 MMS; C:\Program Files (x86)\Acronis\BackupAndRecovery\mms.exe [11138464 2013-10-02] (Acronis)
R2 NitroDriverReadSpool2; C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe [216072 2012-09-04] (Nitro PDF Software)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-16] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-16] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-09-30] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [43064 2014-10-16] (Avira Operations GmbH & Co. KG)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-10-20] (Malwarebytes Corporation)
R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1119672 2013-12-03] (Acronis)
R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [183224 2013-12-03] (Acronis)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-12-16] (TuneUp Software)
R3 VMUVC; C:\Windows\System32\Drivers\VMUVC.sys [202112 2010-11-12] (Vimicro Corporation)
R3 vvftUVC; C:\Windows\System32\drivers\vvftUVC.sys [303616 2008-07-01] (Vimicro Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-25 22:50 - 2014-10-25 22:50 - 00000000 ____D () C:\Users\Martin Rinke\Downloads\FRST-OlderVersion
2014-10-25 20:14 - 2014-10-25 22:06 - 00000000 ____D () C:\ProgramData\tmp
2014-10-25 20:14 - 2014-10-25 20:14 - 00001031 _____ () C:\Users\Public\Desktop\Mein CEWE FOTOBUCH.lnk
2014-10-25 20:14 - 2014-10-25 20:14 - 00001011 _____ () C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk
2014-10-25 19:30 - 2014-10-25 19:30 - 00000000 ____D () C:\Program Files\CEWE
2014-10-25 19:26 - 2014-10-25 19:26 - 01633192 _____ () C:\Users\Kerstin\Downloads\setup_Mein_CEWE_FOTOBUCH(1).exe
2014-10-20 22:29 - 2014-10-20 22:29 - 00001212 _____ () C:\Users\Martin Rinke\Downloads\mbam.2.txt
2014-10-20 21:47 - 2014-10-20 21:47 - 00001210 _____ () C:\Users\Martin Rinke\Downloads\mbam.txt
2014-10-20 21:29 - 2014-10-20 21:29 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-10-20 20:37 - 2014-10-20 20:38 - 02347384 _____ (ESET) C:\Users\Martin Rinke\Downloads\esetsmartinstaller_deu.exe
2014-10-20 20:29 - 2014-10-20 22:07 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-20 20:29 - 2014-10-20 21:11 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-10-20 20:29 - 2014-10-20 21:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-10-20 20:29 - 2014-10-20 21:11 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-10-20 20:29 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-20 20:29 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-20 20:29 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-20 20:25 - 2014-10-20 20:28 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Martin Rinke\Downloads\mbam-setup-2.0.3.1025.exe
2014-10-20 19:15 - 2014-10-20 19:15 - 00001417 _____ () C:\Users\Martin Rinke\Desktop\JRT.txt
2014-10-20 19:12 - 2014-10-20 19:12 - 00000000 ____D () C:\Windows\ERUNT
2014-10-20 19:11 - 2014-10-20 19:11 - 01705698 _____ (Thisisu) C:\Users\Martin Rinke\Downloads\JRT.exe
2014-10-20 19:02 - 2014-10-20 19:02 - 01976320 _____ () C:\Users\Martin Rinke\Downloads\AdwCleaner_4.000.exe
2014-10-17 10:13 - 2014-10-10 04:05 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-17 10:13 - 2014-10-10 04:05 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-17 10:13 - 2014-10-10 04:00 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-17 10:13 - 2014-10-07 04:54 - 00378552 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-17 10:13 - 2014-10-07 04:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-10-17 10:13 - 2014-09-29 02:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-17 10:13 - 2014-09-26 00:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-17 10:13 - 2014-09-26 00:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-10-17 10:13 - 2014-09-26 00:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-10-17 10:13 - 2014-09-26 00:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-10-17 10:13 - 2014-09-26 00:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-10-17 10:13 - 2014-09-26 00:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-10-17 10:13 - 2014-09-26 00:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-17 10:13 - 2014-09-19 04:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-17 10:13 - 2014-09-19 03:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-17 10:13 - 2014-09-19 03:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-17 10:13 - 2014-09-19 03:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-10-17 10:13 - 2014-09-19 03:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-17 10:13 - 2014-09-19 03:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-17 10:13 - 2014-09-19 03:40 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-17 10:13 - 2014-09-19 03:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-17 10:13 - 2014-09-19 03:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-17 10:13 - 2014-09-19 03:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-17 10:13 - 2014-09-19 03:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-17 10:13 - 2014-09-19 03:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-17 10:13 - 2014-09-19 03:27 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-17 10:13 - 2014-09-19 03:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-17 10:13 - 2014-09-19 03:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-10-17 10:13 - 2014-09-19 03:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-17 10:13 - 2014-09-19 03:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-17 10:13 - 2014-09-19 03:18 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-17 10:13 - 2014-09-19 03:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-10-17 10:13 - 2014-09-19 03:14 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-17 10:13 - 2014-09-19 03:06 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-17 10:13 - 2014-09-19 03:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-10-17 10:13 - 2014-09-19 03:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-17 10:13 - 2014-09-19 03:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-10-17 10:13 - 2014-09-19 03:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-10-17 10:13 - 2014-09-19 03:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-17 10:13 - 2014-09-19 02:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-10-17 10:13 - 2014-09-19 02:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-17 10:13 - 2014-09-19 02:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-10-17 10:13 - 2014-09-19 02:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-10-17 10:13 - 2014-09-19 02:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-10-17 10:13 - 2014-09-19 02:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-10-17 10:13 - 2014-09-19 02:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-10-17 10:13 - 2014-09-19 02:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-10-17 10:13 - 2014-09-19 02:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-17 10:13 - 2014-09-19 02:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-17 10:13 - 2014-09-19 02:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-17 10:13 - 2014-09-19 02:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-17 10:13 - 2014-09-19 02:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-17 10:13 - 2014-09-19 02:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-10-17 10:13 - 2014-09-19 02:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-10-17 10:13 - 2014-09-19 02:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-10-17 10:13 - 2014-09-19 02:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-17 10:13 - 2014-09-19 01:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-10-17 10:13 - 2014-09-19 01:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-17 10:13 - 2014-09-19 01:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-10-17 10:13 - 2014-09-19 01:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-10-17 10:13 - 2014-06-19 00:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-17 10:13 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-10-17 10:13 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-10-17 10:13 - 2014-06-19 00:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-17 10:13 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-10-17 10:13 - 2014-06-19 00:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-17 10:12 - 2014-09-18 04:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-17 10:12 - 2014-09-18 03:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-10-17 10:12 - 2014-09-04 07:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-17 10:12 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-10-17 10:12 - 2014-08-29 04:07 - 05780480 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-17 10:12 - 2014-08-29 04:07 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-17 10:12 - 2014-08-29 04:07 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-10-17 10:12 - 2014-08-29 04:07 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-10-17 10:12 - 2014-08-29 04:06 - 01125888 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-10-17 10:12 - 2014-08-29 03:44 - 04922368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-10-17 10:12 - 2014-08-29 03:44 - 01050112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-10-17 10:12 - 2014-08-29 03:44 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-10-17 10:12 - 2014-08-29 03:44 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-10-17 10:12 - 2014-07-17 04:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-17 10:12 - 2014-07-17 04:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-17 10:12 - 2014-07-17 04:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-17 10:12 - 2014-07-17 04:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-17 10:12 - 2014-07-17 04:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-17 10:12 - 2014-07-17 04:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-17 10:12 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-10-17 10:12 - 2014-07-17 03:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-10-17 10:12 - 2014-07-17 03:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-10-17 10:12 - 2014-07-17 03:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-17 10:12 - 2014-07-17 03:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-17 10:11 - 2014-09-13 03:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-17 10:11 - 2014-09-13 03:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-10-04 22:56 - 2014-10-25 21:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-10-04 22:26 - 2014-10-04 22:27 - 00000000 ____D () C:\Users\Kerstin\Documents\Philips GoGear Betriebsanleitung
2014-10-01 11:14 - 2014-09-25 04:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-10-01 11:14 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-10-01 00:23 - 2014-10-01 00:23 - 00001517 _____ () C:\Users\Martin Rinke\Downloads\2014.10.01 Protokoll Malwarebytes.txt
2014-10-01 00:09 - 2014-10-01 00:10 - 00004680 _____ () C:\Users\Martin Rinke\Downloads\Ereignisse.txt
2014-09-30 17:19 - 2014-10-25 23:23 - 00023785 _____ () C:\Users\Martin Rinke\Downloads\FRST.txt
2014-09-30 17:19 - 2014-10-20 19:25 - 00018681 _____ () C:\Users\Martin Rinke\Downloads\Addition.txt
2014-09-30 17:18 - 2014-10-25 23:23 - 00000000 ____D () C:\FRST
2014-09-30 17:18 - 2014-10-25 22:50 - 02112512 _____ (Farbar) C:\Users\Martin Rinke\Downloads\FRST64.exe
2014-09-29 19:37 - 2014-09-29 19:37 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\ICAClient
2014-09-29 19:37 - 2014-09-29 19:37 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Citrix
2014-09-28 16:18 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-09-28 16:17 - 2014-10-20 19:05 - 00000000 ____D () C:\AdwCleaner
2014-09-26 16:48 - 2014-09-26 16:49 - 14153672 _____ (Citrix Systems, Inc.) C:\Users\Martin Rinke\Downloads\CitrixOnlinePluginWeb (1).exe
2014-09-26 16:46 - 2014-09-26 16:46 - 00000000 ____D () C:\ProgramData\Citrix
2014-09-26 16:45 - 2014-09-26 16:45 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Roaming\ICAClient
2014-09-26 16:45 - 2014-09-26 16:45 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Local\Citrix
2014-09-26 16:45 - 2014-09-26 16:45 - 00000000 ____D () C:\Program Files (x86)\Citrix
2014-09-26 16:40 - 2014-09-26 16:42 - 14153672 _____ (Citrix Systems, Inc.) C:\Users\Martin Rinke\Downloads\CitrixOnlinePluginWeb.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-25 23:22 - 2014-07-29 15:17 - 00001122 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-25 23:10 - 2013-10-04 12:59 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Roaming\Nitro PDF
2014-10-25 23:07 - 2009-07-14 06:45 - 00031680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-25 23:07 - 2009-07-14 06:45 - 00031680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-25 23:04 - 2013-10-02 01:22 - 01143584 _____ () C:\Windows\WindowsUpdate.log
2014-10-25 23:01 - 2013-10-09 13:23 - 00000000 ____D () C:\ProgramData\TEMP
2014-10-25 23:00 - 2013-10-09 10:43 - 00000000 ____D () C:\Users\Martin Rinke\Documents\Outlook-Dateien
2014-10-25 22:58 - 2014-07-29 15:17 - 00001118 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-25 22:58 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-25 22:58 - 2009-07-14 06:51 - 00066208 _____ () C:\Windows\setupact.log
2014-10-25 22:51 - 2010-11-21 05:47 - 02459596 _____ () C:\Windows\PFRO.log
2014-10-25 22:50 - 2013-10-01 01:28 - 00000000 ____D () C:\Users\Martin Rinke
2014-10-25 22:41 - 2013-10-03 13:47 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-25 19:35 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-10-25 18:56 - 2013-11-13 20:55 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\Nitro PDF
2014-10-20 23:57 - 2014-06-23 19:37 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Roaming\UseNeXT
2014-10-20 23:55 - 2013-10-04 13:33 - 00000000 ____D () C:\Users\Martin Rinke\Documents\UseNeXT
2014-10-20 22:01 - 2013-10-01 01:38 - 00003982 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{A31852FC-9FB0-4155-B359-F8F56639749F}
2014-10-20 19:38 - 2013-10-03 15:57 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch
2014-10-20 12:45 - 2013-10-16 12:04 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Roaming\Canon
2014-10-20 10:29 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-10-20 09:44 - 2011-04-12 09:43 - 00699190 _____ () C:\Windows\system32\perfh007.dat
2014-10-20 09:44 - 2011-04-12 09:43 - 00149330 _____ () C:\Windows\system32\perfc007.dat
2014-10-20 09:44 - 2009-07-14 07:13 - 01619700 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-20 08:20 - 2009-07-14 06:45 - 00408392 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-20 08:20 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-10-20 08:17 - 2014-04-30 15:53 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-18 00:47 - 2013-10-01 09:59 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-18 00:43 - 2013-10-01 02:42 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-18 00:36 - 2013-10-01 02:42 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-17 15:53 - 2013-10-01 01:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-16 15:14 - 2013-10-02 13:16 - 00131608 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-10-16 15:14 - 2013-10-02 13:16 - 00119272 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-10-16 15:14 - 2013-10-02 13:16 - 00043064 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-10-02 15:53 - 2010-11-21 05:27 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-01 13:15 - 2013-10-02 13:45 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Roaming\vlc
2014-09-30 14:37 - 2013-10-03 16:54 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2014-09-30 14:36 - 2013-10-01 09:59 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Local\Microsoft Help
2014-09-29 19:39 - 2014-05-10 19:22 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\Canon
2014-09-29 19:39 - 2013-11-06 19:05 - 00000000 ____D () C:\Users\Kerstin\Documents\Outlook-Dateien
2014-09-29 10:00 - 2013-10-01 01:41 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-25 12:28 - 2013-11-13 21:16 - 00000000 ____D () C:\Users\Kerstin\Documents\Fitness
2014-09-25 11:18 - 2013-11-13 21:16 - 00000000 ____D () C:\Users\Kerstin\Documents\Kontoauszüge
2014-09-25 01:07 - 2013-10-15 14:38 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Roaming\Skype

Some content of TEMP:
====================
C:\Users\Martin Rinke\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-10-17 15:12

==================== End Of Log ============================
         
--- --- ---

--- --- ---


Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-10-2014
Ran by Martin Rinke at 2014-10-25 23:23:58
Running from C:\Users\Martin Rinke\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acronis Backup & Recovery 11.5 Agent Core (HKLM-x32\...\{9CC39EA2-7D3A-4389-BD2C-FF0A4375F01F}) (Version: 11.5.37975 - Acronis)
Acronis Backup & Recovery 11.5 Bootable Media Builder (HKLM-x32\...\{49B581BF-C3E1-4E8C-8BD2-47009A26D42F}) (Version: 11.5.37975 - Acronis)
Acronis Backup & Recovery 11.5 Command-Line Tool (HKLM-x32\...\{4C2B4759-7625-4894-BF16-52828D2C9FDE}) (Version: 11.5.37975 - Acronis)
Acronis Backup & Recovery 11.5 Tray Monitor (HKLM-x32\...\{08C0CADB-4DC6-450A-A8CE-761173DCFC42}) (Version: 11.5.37975 - Acronis)
Acronis Backup & Recovery 11.5*Agent für Windows (HKLM-x32\...\{D9DC5B4F-1BAD-471E-A827-B3969AD24994}) (Version: 11.5.37975 - Acronis)
Acronis Backup & Recovery 11.5*Management*Console (HKLM-x32\...\{784BE313-D87B-4EBC-A1A6-48AA605C40BC}) (Version: 11.5.37975 - Acronis)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
Antivirus Pro (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.306 - Avira)
AudioCon (HKLM-x32\...\AudioCon) (Version: 1.0 - Basement Softworks)
AVM FRITZ!Box Dokumentation (HKLM-x32\...\AVMFBox) (Version:  - AVM Berlin)
AVM FRITZ!Box Druckeranschluss (HKLM-x32\...\AVMFBoxPrinter) (Version:  - AVM Berlin)
BURY Update Manager 1.4.1 (HKLM-x32\...\BURY Update Manager_is1) (Version:  - BURY Gmbh & Co. KG)
CanoScan Toolbox Ver4.6 (HKLM-x32\...\{088A077A-8028-408C-AE7B-4512AE2A65A0}) (Version:  - )
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4291 - CDBurnerXP)
Citrix Online Plug-in - Web (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 12.1.44.1 - Citrix Systems, Inc.)
Citrix Online Plug-in (DV) (x32 Version: 12.1.44.1 - Citrix Systems, Inc.) Hidden
Citrix Online Plug-in (HDX) (x32 Version: 12.1.44.1 - Citrix Systems, Inc.) Hidden
Citrix Online Plug-in (USB) (x32 Version: 12.1.44.1 - Citrix Systems, Inc.) Hidden
Citrix Online Plug-in (Web) (x32 Version: 12.1.44.1 - Citrix Systems, Inc.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DesignPro 5 (HKLM-x32\...\InstallShield_{F82C6574-AD88-4B40-A432-970BC77F1BD2}) (Version: 5.5.708 - Avery Dennison)
DesignPro 5 (x32 Version: 5.5.708 - Avery Dennison) Hidden
Dragon NaturallySpeaking 11 (HKLM-x32\...\{EFFA53BC-8C04-2E21-3D90-A13B1697B0CA}) (Version: 11.50.100 - Nuance Communications Inc.)
ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 15.0.20140212 - Landesfinanzdirektion Thüringen)
Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 38.0.2125.104 - Google Inc.)
Google Earth (HKLM-x32\...\{A2264E8F-1649-11E3-8BED-B8AC6F98CCE3}) (Version: 7.1.2.2019 - Google)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
iLinc 11 Client (HKLM-x32\...\iLincClient.11) (Version:  - )
Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
Mein CEWE FOTOBUCH (HKLM-x32\...\Mein CEWE FOTOBUCH) (Version: 5.1.6 - CEWE Stiftung u Co. KGaA)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKCU\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 32.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 32.0.2 (x86 de)) (Version: 32.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.5 - F.J. Wechselberger)
Nitro Pro 7 (HKLM\...\{EEF9C83C-5D22-4BB8-8453-0F4F5F2328D2}) (Version: 7.5.0.29 - Nitro PDF Software)
Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41418}) (Version: 3.61.0 - dotPDN LLC)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.1 - pdfforge)
Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.49.927.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6690 - Realtek Semiconductor Corp.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
SoftSkies (HKLM-x32\...\SoftSkies) (Version: 1.7 - SoundSpectrum)
TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden
TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities) (Version: 14.0.1000.340 - TuneUp Software)
TuneUp Utilities 2014 (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden
TuneUp Utilities Language Pack (de-DE) (x32 Version: 13.0.4000.245 - TuneUp Software) Hidden
UseNeXT by Tangysoft (HKLM-x32\...\UseNeXT by Tangysoft_is1) (Version:  - Tangysoft Ltd.)
Vimicro UVC USB2.0 PC Camera (HKLM-x32\...\{71A51A91-E7D3-11DB-A386-005056C00008}) (Version: 2009.03.18 - Vimicro Corporation)
Visual C++ 9.0 Runtime for Dragon NaturallySpeaking 64bit (x64) (HKLM\...\{4A5A427F-BA39-4BF0-7777-9A47FBE60C9F}) (Version: 11.0.0 - Nuance Communications Inc.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation)
WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
WinX Free DVD to MPEG Ripper 4.4.26 (HKLM-x32\...\WinX Free DVD to MPEG Ripper_is1) (Version:  - Digiarty Software,Inc.)
XING Outlook Connector (HKLM\...\{3B8AF990-AE63-481C-BC4B-8BB8D7A93B80}) (Version: 2.2.0 - XING)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-4136266569-681284793-1319911660-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4136266569-681284793-1319911660-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4136266569-681284793-1319911660-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4136266569-681284793-1319911660-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4136266569-681284793-1319911660-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation)

==================== Restore Points  =========================

20-10-2014 06:33:24 Windows-Sicherung
20-10-2014 19:25:03 Dragon NaturallySpeaking 11 wurde entfernt.
25-10-2014 16:48:50 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2014-10-25 22:57 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {175CC5A7-269A-4226-A679-11C883D6F376} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-24] (Adobe Systems Incorporated)
Task: {192D3862-44C1-43F8-8FB1-4AB2351D3C4E} - System32\Tasks\Browser Updater\Browser Updater => Rundll32.exe "C:\Program Files (x86)\HomeTab\TBUpdater.dll",TBCheckForUpdate
Task: {38F8E9B8-CFCA-4B33-BD53-5F3334EBD275} - \{5B2F6C6D-7973-4195-A550-81033A447A93} No Task File <==== ATTENTION
Task: {4805B0FA-735D-4B0D-AF50-5C691DADF634} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2014-07-16] (TuneUp Software)
Task: {688906B1-ED7E-4830-B7F8-2CE948F84935} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-29] (Google Inc.)
Task: {694CD1AC-1694-4F58-B3A7-D5039301BE8E} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {AFAFDF05-67D2-4355-8DFA-C978B422D027} - System32\Tasks\Xing Social Recommendations => C:\Program Files\XING\XING Outlook Connector\32-bit\XingSocial.exe [2014-01-08] (XING AG)
Task: {E5E051A9-3542-44E2-92CC-533CA218D4D5} - System32\Tasks\xingoscupdate => C:\Program Files\XING\XING Outlook Connector\xingoscupdate.exe [2014-01-08] (XING)
Task: {F49F24ED-AA1D-4568-8324-0A35266A88C7} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21] (Adobe Systems Incorporated)
Task: {FE3276A4-52C2-4550-ACD4-6BEC0780BDA0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-29] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-12-18 18:49 - 2013-08-23 14:36 - 00721263 _____ () C:\Windows\SysWOW64\WSCM64.dll
2013-10-02 12:50 - 2006-06-27 16:28 - 00322048 _____ () C:\Windows\system32\CNQL3203.DLL
2014-07-16 10:24 - 2014-07-16 10:24 - 00699704 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll
2013-10-02 02:57 - 2013-10-02 02:57 - 00284304 _____ () C:\Program Files (x86)\Common Files\Acronis\BackupAndRecovery\Common\fnls.dll
2013-10-02 02:57 - 2013-10-02 02:57 - 00327040 _____ () C:\Program Files (x86)\Common Files\Acronis\BackupAndRecovery\Common\events_trace.dll
2013-10-02 02:58 - 2013-10-02 02:58 - 00441512 _____ () C:\Program Files (x86)\Common Files\Acronis\BackupAndRecovery\Common\FileTrace.dll
2013-10-02 03:00 - 2013-10-02 03:00 - 00921024 _____ () C:\Program Files (x86)\Acronis\BackupAndRecovery\human_resolving_mms.dll
2013-01-22 14:30 - 2013-01-22 14:30 - 00013120 _____ () C:\Program Files (x86)\Common Files\Acronis\TibMounter\icudt38.dll
2014-10-16 15:27 - 2014-10-10 04:03 - 01042760 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\libglesv2.dll
2014-10-16 15:27 - 2014-10-10 04:03 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\libegl.dll
2014-10-16 15:27 - 2014-10-10 04:04 - 08910664 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\pdf.dll
2014-10-16 15:27 - 2014-10-10 04:03 - 01681224 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\ffmpegsumo.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2013-02-14 15:46 - 2013-02-14 15:46 - 01044048 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
2012-09-04 22:40 - 2012-09-04 22:40 - 07751688 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\npdf.dll
2012-09-04 22:39 - 2012-09-04 22:39 - 01649152 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPActions.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 02971136 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPAnnotations.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 01051136 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPAttachments.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 01587200 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPBookmarks.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 01776128 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPCreatePDF.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 02603520 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPDigitalSignature.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 01793024 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPExport.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 02861568 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPForms.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 01741312 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPLinks.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 02118656 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPObjectTool.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 00823816 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\idrskrn14.dll
2012-09-04 22:39 - 2012-09-04 22:39 - 01525760 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPOptimizer.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 01856000 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPPageEdit.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 01470464 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPPrint.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 01522176 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPScan2PDF.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 01785856 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPSetSecurity.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 02069504 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPStamper.npp
2012-09-04 22:39 - 2012-09-04 22:39 - 01861632 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPWatermarks.npp

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:7FFED16F

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


========================= Accounts: ==========================

Acronis Agent User (S-1-5-21-4136266569-681284793-1319911660-1003 - Administrator - Enabled) => C:\Users\Acronis Agent User
Administrator (S-1-5-21-4136266569-681284793-1319911660-500 - Administrator - Disabled)
Gast (S-1-5-21-4136266569-681284793-1319911660-501 - Limited - Disabled)
Kerstin (S-1-5-21-4136266569-681284793-1319911660-1001 - Limited - Enabled) => C:\Users\Kerstin
Martin Rinke (S-1-5-21-4136266569-681284793-1319911660-1000 - Administrator - Enabled) => C:\Users\Martin Rinke

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/25/2014 11:00:21 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/25/2014 10:53:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/25/2014 10:06:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe, Version: 0.0.0.0, Zeitstempel: 0x53db7f75
Name des fehlerhaften Moduls: Qt5Core.dll, Version: 5.1.1.0, Zeitstempel: 0x52a8888d
Ausnahmecode: 0xc000041d
Fehleroffset: 0x00000000001b1d9b
ID des fehlerhaften Prozesses: 0x1210
Startzeit der fehlerhaften Anwendung: 0xMein CEWE FOTOBUCH.exe0
Pfad der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe1
Pfad des fehlerhaften Moduls: Mein CEWE FOTOBUCH.exe2
Berichtskennung: Mein CEWE FOTOBUCH.exe3

Error: (10/25/2014 10:06:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe, Version: 0.0.0.0, Zeitstempel: 0x53db7f75
Name des fehlerhaften Moduls: Qt5Core.dll, Version: 5.1.1.0, Zeitstempel: 0x52a8888d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000001b1d9b
ID des fehlerhaften Prozesses: 0x1210
Startzeit der fehlerhaften Anwendung: 0xMein CEWE FOTOBUCH.exe0
Pfad der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe1
Pfad des fehlerhaften Moduls: Mein CEWE FOTOBUCH.exe2
Berichtskennung: Mein CEWE FOTOBUCH.exe3

Error: (10/25/2014 09:38:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe, Version: 0.0.0.0, Zeitstempel: 0x53db7f75
Name des fehlerhaften Moduls: Qt5Core.dll, Version: 5.1.1.0, Zeitstempel: 0x52a8888d
Ausnahmecode: 0xc000041d
Fehleroffset: 0x00000000001b1d9b
ID des fehlerhaften Prozesses: 0xb18
Startzeit der fehlerhaften Anwendung: 0xMein CEWE FOTOBUCH.exe0
Pfad der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe1
Pfad des fehlerhaften Moduls: Mein CEWE FOTOBUCH.exe2
Berichtskennung: Mein CEWE FOTOBUCH.exe3

Error: (10/25/2014 09:38:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe, Version: 0.0.0.0, Zeitstempel: 0x53db7f75
Name des fehlerhaften Moduls: Qt5Core.dll, Version: 5.1.1.0, Zeitstempel: 0x52a8888d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000001b1d9b
ID des fehlerhaften Prozesses: 0xb18
Startzeit der fehlerhaften Anwendung: 0xMein CEWE FOTOBUCH.exe0
Pfad der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe1
Pfad des fehlerhaften Moduls: Mein CEWE FOTOBUCH.exe2
Berichtskennung: Mein CEWE FOTOBUCH.exe3

Error: (10/25/2014 06:43:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/21/2014 01:52:33 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (10/20/2014 08:49:28 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (10/20/2014 08:38:42 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.


System errors:
=============
Error: (10/25/2014 10:58:33 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (10/25/2014 10:58:33 PM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter

Error: (10/25/2014 10:51:57 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (10/25/2014 10:51:57 PM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter

Error: (10/25/2014 10:44:51 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (10/25/2014 10:44:27 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (10/25/2014 10:06:34 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (10/25/2014 06:41:36 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (10/25/2014 06:41:36 PM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter

Error: (10/20/2014 08:36:45 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.


Microsoft Office Sessions:
=========================
Error: (10/25/2014 11:00:21 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/25/2014 10:53:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/25/2014 10:06:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Mein CEWE FOTOBUCH.exe0.0.0.053db7f75Qt5Core.dll5.1.1.052a8888dc000041d00000000001b1d9b121001cff08b5a52fcfcC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Mein CEWE FOTOBUCH.exeC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Qt5Core.dll6c5f8f1b-5c82-11e4-acf9-b8975a476b92

Error: (10/25/2014 10:06:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Mein CEWE FOTOBUCH.exe0.0.0.053db7f75Qt5Core.dll5.1.1.052a8888dc000000500000000001b1d9b121001cff08b5a52fcfcC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Mein CEWE FOTOBUCH.exeC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Qt5Core.dll634eb172-5c82-11e4-acf9-b8975a476b92

Error: (10/25/2014 09:38:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Mein CEWE FOTOBUCH.exe0.0.0.053db7f75Qt5Core.dll5.1.1.052a8888dc000041d00000000001b1d9bb1801cff07fcaecb64fC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Mein CEWE FOTOBUCH.exeC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Qt5Core.dll7ffe31fb-5c7e-11e4-acf9-b8975a476b92

Error: (10/25/2014 09:38:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Mein CEWE FOTOBUCH.exe0.0.0.053db7f75Qt5Core.dll5.1.1.052a8888dc000000500000000001b1d9bb1801cff07fcaecb64fC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Mein CEWE FOTOBUCH.exeC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Qt5Core.dll72f74a1e-5c7e-11e4-acf9-b8975a476b92

Error: (10/25/2014 06:43:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/21/2014 01:52:33 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe

Error: (10/20/2014 08:49:28 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Martin Rinke\Downloads\esetsmartinstaller_deu.exe

Error: (10/20/2014 08:38:42 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Martin Rinke\Downloads\esetsmartinstaller_deu.exe


==================== Memory info =========================== 

Processor: AMD FX(tm)-6300 Six-Core Processor 
Percentage of memory in use: 30%
Total physical RAM: 7935.3 MB
Available physical RAM: 5537.03 MB
Total Pagefile: 15868.79 MB
Available Pagefile: 13186.44 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:116.31 GB) (Free:49.93 GB) NTFS
Drive d: () (Fixed) (Total:116.48 GB) (Free:115.54 GB) NTFS
Drive h: (Volume) (Fixed) (Total:1397.26 GB) (Free:251.12 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: D294D294)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=116.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=116.5 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1397.3 GB) (Disk ID: 40D6E131)
Partition 1: (Not Active) - (Size=1397.3 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         

Alt 25.10.2014, 22:57   #25
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Meldung  RunDLL Program Files (x86)\HomeTab\TBUpdater.dll - Standard

Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll



Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab
SearchScopes: HKCU - URL http://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms}
SearchScopes: HKCU - SuggestionsURL_JSON http://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=99&gid=1&dbCode=1&command={searchTerms}
SearchScopes: HKCU - TopResultURLFallback http://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms}
Task: {38F8E9B8-CFCA-4B33-BD53-5F3334EBD275} - \{5B2F6C6D-7973-4195-A550-81033A447A93} No Task File <==== ATTENTION
Task: {192D3862-44C1-43F8-8FB1-4AB2351D3C4E} - System32\Tasks\Browser Updater\Browser Updater => Rundll32.exe "C:\Program Files (x86)\HomeTab\TBUpdater.dll",TBCheckForUpdate
C:\Program Files (x86)\HomeTab
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

__________________
Logfiles bitte immer in CODE-Tags posten

Alt 25.10.2014, 23:13   #26
Martin56
 
Meldung  RunDLL Program Files (x86)\HomeTab\TBUpdater.dll - Standard

Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll



Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-10-2014
Ran by Martin Rinke at 2014-10-26 00:12:52 Run:4
Running from C:\Users\Martin Rinke\Downloads
Loaded Profiles: Martin Rinke & Acronis Agent User (Available profiles: Martin Rinke & Kerstin & Acronis Agent User)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab
SearchScopes: HKCU - URL hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms}
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=99&gid=1&dbCode=1&command={searchTerms}
SearchScopes: HKCU - TopResultURLFallback hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms}
Task: {38F8E9B8-CFCA-4B33-BD53-5F3334EBD275} - \{5B2F6C6D-7973-4195-A550-81033A447A93} No Task File <==== ATTENTION
Task: {192D3862-44C1-43F8-8FB1-4AB2351D3C4E} - System32\Tasks\Browser Updater\Browser Updater => Rundll32.exe "C:\Program Files (x86)\HomeTab\TBUpdater.dll",TBCheckForUpdate
C:\Program Files (x86)\HomeTab
         
*****************

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL => value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SuggestionsURL_JSON => value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\TopResultURLFallback => value deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{38F8E9B8-CFCA-4B33-BD53-5F3334EBD275}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{38F8E9B8-CFCA-4B33-BD53-5F3334EBD275}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5B2F6C6D-7973-4195-A550-81033A447A93}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{192D3862-44C1-43F8-8FB1-4AB2351D3C4E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{192D3862-44C1-43F8-8FB1-4AB2351D3C4E}" => Key deleted successfully.
C:\Windows\System32\Tasks\Browser Updater\Browser Updater => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Browser Updater\Browser Updater" => Key deleted successfully.
"C:\Program Files (x86)\HomeTab" => File/Directory not found.

==== End of Fixlog ====
         

Alt 25.10.2014, 23:15   #27
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Meldung  RunDLL Program Files (x86)\HomeTab\TBUpdater.dll - Standard

Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll



Fehlermeledung beim Start weg?
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 25.10.2014, 23:32   #28
Martin56
 
Meldung  RunDLL Program Files (x86)\HomeTab\TBUpdater.dll - Standard

Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll



Ich starte mal neu

Meldung ist weg! Halleluja!!!!
Macht es Strass, mir noch drei Fragen zu beantworten?
1. War das irgendwas Gefährliches?
2. Was wurde auf meinem Rechner gemacht/geändert?
3. Das wichtigste: Kann ich mich irgenwie erkenntlich zeigen? War schließlich eine langwierige Sache, insbesondere für Dich!
Viele Grüße

Alt 26.10.2014, 00:10   #29
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Meldung  RunDLL Program Files (x86)\HomeTab\TBUpdater.dll - Standard

Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll



Du hattest wie fast jeder hier auch Werbung (Adware/Junkware/PUPs) auf deinem Rechner. Was PUPs sind erklärt Emsisoft hier recht gut => A Typical Day at Emsisoft?s Headquarters: The PUP Encounter | Emsisoft Blog

Danke, dass du uns unterstützen möchtest, nähere Infos findest du dazu hier => Spende - Trojaner-Board - Spendenkonto - Trojaner-Board



Dann wären wir durch!


Falls du noch Lob oder Kritik loswerden möchtest => Lob, Kritik und Wünsche - Trojaner-Board

Die Programme, die hier zum Einsatz kamen, können alle deinstalliert werden. Es empfiehlt sich Malwarebytes Anti-Malware zu behalten und damit wöchentlich nach Malware zu scannen.

Helfen kann dir dabei delfix:


Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.






Bitte abschließend noch die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate
Windows XP:Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.
Windows Vista/7: Start, Systemsteuerung, Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks findest du hier => Browsers and Plugins - FilePony.de

Alle Plugins im Firefox-Browser kannst du auch ganz einfach hier auf Aktualität prüfen => https://www.mozilla.org/de/plugincheck

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein großes Sicherheitsrisiko, daher solltest Du die alten Versionen deinstallieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software (bzw. Programme und Funktionen) und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.
__________________
Logfiles bitte immer in CODE-Tags posten

Antwort

Themen zu Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll
conduit.search, conduit.search entfernen, fehlercode 0xc0000005, fehlercode 0xc000041d, fehlercode 1, fehlercode windows, geschlossen, installiert, malwarebytes, onedrive, probleme beim hochfahren, refresh, tr/dropper.vb.17120, tr/trash.gen, unregelmäßige, vbs/runner.nbw, virenscanner, win32/conduit.searchprotect.a, win32/conduit.searchprotect.d, win32/conduit.searchprotect.e, win32/conduit.searchprotect.s, win32/downware.l, win32/loadtubes.d, win32/packed.scramblewrapper.d, win32/softonicdownloader.d, win32/toolbar.iminent.i, win32/toolbar.montiera.b, win32/toolbar.searchsuite




Ähnliche Themen: Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll


  1. Problem beim starten von C:\Program Files(x86)\HomeTab\TBUpdater.dll
    Log-Analyse und Auswertung - 22.08.2014 (15)
  2. C:\Program Files\HomeTab\TBUpdater.dll problem
    Plagegeister aller Art und deren Bekämpfung - 17.08.2014 (41)
  3. Fehlermeldung: Beim Starten von C:\Program Files (x86)\HomeTab\TBUpdater.dll
    Log-Analyse und Auswertung - 29.06.2014 (11)
  4. Problem beim Starten von C:\Program files (X86)\Hometab\TBUpdater.dll kommt nach hochfahren des PC
    Plagegeister aller Art und deren Bekämpfung - 31.05.2014 (13)
  5. Win7: Nach Neustart erscheint RunDLL-Window mit "Problem beim Starten von C:\Program Files (x86)\HomeTab\TBUpdater.dll"
    Plagegeister aller Art und deren Bekämpfung - 17.12.2013 (8)
  6. Run.dll - Problem beim Starten von C:\Program Files\HomeTab\TBUpdater.dll
    Plagegeister aller Art und deren Bekämpfung - 01.12.2013 (19)
  7. Win7: Nach Neustart erscheint RunDLL-Window mit "Problem beim Starten von C:\Program Files (x86)\HomeTab\TBUpdater.dll"
    Log-Analyse und Auswertung - 04.11.2013 (7)
  8. c:\program files(x86)\hometab\tbupdater.dll
    Log-Analyse und Auswertung - 05.10.2013 (14)
  9. Windows 7 C:\Program Files(x86)\HomeTab\TBUpdater.dll bekomme ständig diese meldung.
    Log-Analyse und Auswertung - 20.09.2013 (20)
  10. Problem mit dem Modul C:\Program Files\HomeTab\TBUpdater.dll wurde nicht gefunden ...
    Plagegeister aller Art und deren Bekämpfung - 24.08.2013 (9)
  11. C:\Program Files(x86)\HomeTab\TBUpdater.dll
    Plagegeister aller Art und deren Bekämpfung - 22.08.2013 (4)
  12. Problem beim Windows 7 Start program files\hometab\TBUpdater.dll
    Plagegeister aller Art und deren Bekämpfung - 20.08.2013 (13)
  13. Problem beim Starten von C:\Program Files(x86)\HomeTab\TBUpdater.dll
    Log-Analyse und Auswertung - 30.07.2013 (12)
  14. C:\Program Files(x86)\HomeTab\TBUpdater.dll bekomme ständig diese meldung ,ich poste mal die 2 logfile
    Log-Analyse und Auswertung - 28.07.2013 (21)
  15. Problem beim Starten von C:\Program Files(x86)\HomeTab\TBUpdater.dll
    Plagegeister aller Art und deren Bekämpfung - 27.07.2013 (11)
  16. C:\Program Files(x86)\HomeTab\TBUpdater.dll bekomme ständig diese meldun.
    Mülltonne - 25.07.2013 (1)
  17. C:\Program Files(x86)\HomeTab\TBUpdater.dll
    Plagegeister aller Art und deren Bekämpfung - 22.06.2013 (7)

Zum Thema Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll - Zitat: Malware Datenbank: v2014.09.19.05 Ging das Sig-Update nicht? - Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll...
Archiv
Du betrachtest: Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.