Windows 7: Adware eingefangen - Standard

Windows 7: Adware eingefangen

ich habe mir wohl unbewusst eine nervige Adware runter geladen. Einzelne Wörter werden unterstrichen und sind mit Werbung hinterlegt. Dazu kommt, dass ich regelmäßigen Abständen sich ein Fenster öffnet, dass zu einer Umfrage auffordert.

Ich habe mir nun, gemäß euren Anweisungen, Defogger runter geladen und auf dem Desktop abgelegt.
Ich komme allerdings nur bis zu dem Punkt, wenn die Nachricht 'Finished!' erscheint,
Klicke ich dann auf ´OK´, dann passiert gar nichts mehr.

defogger_disable by jpshortstuff (
Log created at 09:04 on 12/10/2014 (Sven)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


/// the machine
/// TB-Ausbilder

Windows 7: Adware eingefangen - Standard

Windows 7: Adware eingefangen


Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)



Windows 7: Adware eingefangen - Standard

Windows 7: Adware eingefangen

FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-10-2014
Ran by Sven (administrator) on SVEN-PC on 12-10-2014 10:26:10
Running from C:\Users\Sven\Desktop
Loaded Profile: Sven (Available profiles: Sven & Administrator)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Small Island Development) C:\ProgramData\HhJanHrEZI\LSFDLPRh.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [NPSStartup] => [X]
HKU\S-1-5-21-2267789081-3611541687-2111919439-1000\...\Run: [AdobeBridge] => [X]

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2A8C04551BCDCC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
DPF: HKLM {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
Filter: AutorunsDisabled - No CLSID Value - No File
Filter-x32: AutorunsDisabled - No CLSID Value - No File
Hosts: activate.adobe.com
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default
FF SearchEngineOrder.2: www.ebay.de
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @phonostar.de/phonostar -> C:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll No File
FF SearchPlugin: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\searchplugins\youtube-videosuche.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: German Dictionary - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\de-DE@dictionaries.addons.mozilla.org [2014-07-30]
FF Extension: British English Dictionary (Updated) - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\en-gb@flyingtophat.co.uk [2013-10-23]
FF Extension: Russian spellchecking dictionary - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\ru@dictionaries.addons.mozilla.org [2014-09-21]
FF Extension: Garmin Communicator - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2014-07-07]
FF Extension: Flashblock - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2014-09-30]
FF Extension: EPUBReader - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F} [2014-09-21]
FF Extension: Quick Translator - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\{5C655500-E712-41e7-9349-CE462F844B19}.xpi [2014-01-19]
FF Extension: YouTube High Definition - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2014-09-29]
FF Extension: Easy Youtube Video Downloader Express - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2014-06-19]
FF Extension: Adblock Plus - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-01-07]
FF HKLM-x32\...\Firefox\Extensions:  - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: 卡巴斯基網址顧問 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-02-21]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: 虛擬鍵盤 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-02-21]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: 惡意網站攔截器 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-02-21]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Chặn quảng cáo - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-02-21]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-02-21]

CHR Profile: C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa []
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [koalekbhpbggkcfhkkbolikjoaobbppi] - C:\Program Files (x86)\PutLockerDownloader\PutLockerDownloader10.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
S4 cbVSCService11; C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe [67584 2012-05-25] (CobianSoft, Luis Cobian) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) [File not signed]
R2 LSFDLPRh; C:\ProgramData\HhJanHrEZI\LSFDLPRh.exe [2322296 2014-10-09] (Small Island Development)
S4 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [27648 2008-01-19] (Microsoft Corporation)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-02-22] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-04-01] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-04-01] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-02-22] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-02-22] (Kaspersky Lab ZAO)
U5 usbser; C:\Windows\System32\Drivers\usbser.sys [32768 2009-07-14] (Microsoft Corporation)
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-12 10:26 - 2014-10-12 10:26 - 00013965 _____ () C:\Users\Sven\Desktop\FRST.txt
2014-10-12 10:26 - 2014-10-12 10:26 - 00013965 _____ () C:\Users\Sven\Desktop\FRST.txt
2014-10-12 10:25 - 2014-10-12 10:26 - 00000000 ____D () C:\FRST
2014-10-12 10:25 - 2014-10-12 10:25 - 02109952 _____ (Farbar) C:\Users\Sven\Desktop\FRST64.exe
2014-10-12 10:25 - 2014-10-12 10:25 - 02109952 _____ (Farbar) C:\Users\Sven\Desktop\FRST64.exe
2014-10-12 10:18 - 2014-10-12 10:19 - 02109952 _____ (Farbar) C:\Users\Sven\Desktop\FRST64.exe.part
2014-10-12 10:18 - 2014-10-12 10:19 - 02109952 _____ (Farbar) C:\Users\Sven\Desktop\FRST64.exe.part
2014-10-12 08:59 - 2014-10-12 09:04 - 00000470 _____ () C:\Users\Sven\Desktop\defogger_disable.log
2014-10-12 08:59 - 2014-10-12 09:04 - 00000470 _____ () C:\Users\Sven\Desktop\defogger_disable.log
2014-10-12 08:59 - 2014-10-12 08:59 - 00000000 _____ () C:\Users\Sven\defogger_reenable
2014-10-12 08:58 - 2014-10-12 08:58 - 00050477 _____ () C:\Users\Sven\Desktop\Defogger.exe
2014-10-12 08:58 - 2014-10-12 08:58 - 00050477 _____ () C:\Users\Sven\Desktop\Defogger.exe
2014-10-12 08:53 - 2014-10-12 09:14 - 00000112 _____ () C:\Windows\setupact.log
2014-10-12 08:53 - 2014-10-12 08:53 - 00000000 _____ () C:\Windows\setuperr.log
2014-10-11 22:05 - 2014-10-11 22:05 - 00000000 ____D () C:\ProgramData\Browser
2014-10-09 18:25 - 2014-10-09 18:25 - 00000000 ____D () C:\Windows\ERUNT
2014-10-09 15:56 - 2014-10-09 15:56 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-09 15:29 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-10-09 15:28 - 2014-10-10 01:49 - 00000000 ____D () C:\AdwCleaner
2014-10-09 03:52 - 2014-10-09 03:52 - 00002585 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kalender1-Free.lnk
2014-10-09 03:52 - 2014-10-09 03:52 - 00000000 ____D () C:\Program Files (x86)\Kalender1-Free
2014-10-09 02:14 - 2014-10-12 09:32 - 00000000 ____D () C:\Users\Sven\AppData\Local\MovieWizard
2014-10-09 02:14 - 2014-10-09 02:14 - 00000000 ____D () C:\ProgramData\HhJanHrEZI
2014-10-09 02:09 - 2014-10-09 02:09 - 00000000 ____D () C:\Program Files\LopeSoft
2014-10-01 07:54 - 2014-10-01 07:54 - 00000135 _____ () C:\Windows\SysWOW64\debug.log
2014-10-01 07:49 - 2014-10-01 08:00 - 00000052 _____ () C:\Windows\BookPrintXP.ini
2014-10-01 02:16 - 2014-10-12 08:41 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\vlc
2014-10-01 02:00 - 2014-10-01 02:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-10-01 02:00 - 2014-10-01 02:00 - 00000000 ____D () C:\Program Files\VideoLAN
2014-10-01 00:35 - 2014-10-01 00:35 - 00001102 _____ () C:\Users\Sven\Desktop\Etiketten-Designer 2.1.lnk
2014-10-01 00:35 - 2014-10-01 00:35 - 00001102 _____ () C:\Users\Sven\Desktop\Etiketten-Designer 2.1.lnk
2014-10-01 00:35 - 2014-10-01 00:35 - 00001102 _____ () C:\Users\Administrator\Desktop\Etiketten-Designer 2.1.lnk
2014-10-01 00:35 - 2014-10-01 00:35 - 00001102 _____ () C:\Users\Administrator\Desktop\Etiketten-Designer 2.1.lnk
2014-10-01 00:35 - 2014-10-01 00:35 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Etiketten-Designer 2.1
2014-10-01 00:35 - 2014-10-01 00:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Etiketten-Designer 2.1
2014-10-01 00:35 - 2014-10-01 00:35 - 00000000 ____D () C:\Program Files (x86)\Etiketten-Designer 2
2014-10-01 00:34 - 2014-10-01 00:34 - 00000000 ____D () C:\Users\Sven\Downloads\Etiketten-Designer
2014-10-01 00:17 - 2014-10-10 01:48 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\AIMP3
2014-10-01 00:17 - 2014-10-01 00:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3
2014-10-01 00:17 - 2014-10-01 00:17 - 00000000 ____D () C:\Program Files (x86)\AIMP3
2014-09-29 09:48 - 2014-09-29 09:59 - 00047264 _____ () C:\Users\Sven\Desktop\Russisch Deutsch.xlsx
2014-09-29 09:48 - 2014-09-29 09:59 - 00047264 _____ () C:\Users\Sven\Desktop\Russisch Deutsch.xlsx
2014-09-26 16:25 - 2014-09-26 16:26 - 00000000 ____D () C:\Users\Sven\.ruslanka
2014-09-26 16:24 - 2014-09-26 16:24 - 00001901 _____ () C:\Users\Public\Desktop\Ruslanka.lnk
2014-09-26 16:24 - 2014-09-26 16:24 - 00001901 _____ () C:\Users\Public\Desktop\Ruslanka.lnk
2014-09-26 16:24 - 2014-09-26 16:24 - 00001901 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ruslanka.lnk
2014-09-26 16:24 - 2014-09-26 16:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ruslanka
2014-09-26 16:24 - 2014-09-26 16:24 - 00000000 ____D () C:\Program Files (x86)\Ruslanka
2014-09-26 15:23 - 2014-09-26 15:23 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Langenscheidt
2014-09-26 15:23 - 2014-09-26 15:23 - 00000000 ____D () C:\ProgramData\Langenscheidt
2014-09-26 15:22 - 2014-09-26 15:22 - 00000000 ____D () C:\Users\Sven\Desktop\vokabel_
2014-09-26 15:22 - 2014-09-26 15:22 - 00000000 ____D () C:\Users\Sven\Desktop\vokabel_
2014-09-26 15:10 - 2014-09-26 15:22 - 00000000 ____D () C:\Users\Sven\Desktop\VTrain
2014-09-26 15:10 - 2014-09-26 15:22 - 00000000 ____D () C:\Users\Sven\Desktop\VTrain
2014-09-26 15:10 - 2014-09-26 15:21 - 00000976 _____ () C:\Users\Sven\Desktop\VTrain Free.lnk
2014-09-26 15:10 - 2014-09-26 15:21 - 00000976 _____ () C:\Users\Sven\Desktop\VTrain Free.lnk
2014-09-26 15:10 - 2014-09-26 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTrain
2014-09-26 15:10 - 2014-09-26 15:21 - 00000000 ____D () C:\Program Files (x86)\VTrain
2014-09-26 15:10 - 2014-09-26 15:10 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\VTrain
2014-09-26 14:57 - 2014-09-26 14:57 - 00000909 _____ () C:\Users\Public\Desktop\Vocup.lnk
2014-09-26 14:57 - 2014-09-26 14:57 - 00000909 _____ () C:\Users\Public\Desktop\Vocup.lnk
2014-09-26 14:57 - 2014-09-26 14:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vocup
2014-09-26 14:33 - 2014-09-26 14:33 - 00004022 _____ () C:\Windows\System32\Tasks\LaunchSignup
2014-09-26 14:16 - 2014-09-26 14:16 - 00000000 ____D () C:\Users\Sven\Desktop\Vokabelhefte
2014-09-26 14:16 - 2014-09-26 14:16 - 00000000 ____D () C:\Users\Sven\Desktop\Vokabelhefte
2014-09-26 14:15 - 2014-09-26 14:15 - 00000000 ____D () C:\MemoStep6_14
2014-09-21 13:40 - 2014-09-26 14:57 - 00000000 ____D () C:\Program Files (x86)\Vocup
2014-09-21 13:40 - 2014-09-21 13:40 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Vocup
2014-09-21 13:40 - 2014-09-21 13:40 - 00000000 ____D () C:\Users\Sven\AppData\Local\_0_
2014-09-21 13:31 - 2014-09-21 13:31 - 00000000 ____D () C:\Program Files\JohnnyAnimation
2014-09-21 13:27 - 2014-09-26 15:04 - 00000000 ____D () C:\Program Files (x86)\MemoStep6
2014-09-21 13:20 - 2014-10-01 00:35 - 00087704 _____ () C:\Windows\cadkasdeinst01.exe
2014-09-21 13:20 - 2014-09-26 14:57 - 00000000 ____D () C:\Program Files (x86)\Vokabeltrainer 1
2014-09-21 13:20 - 2014-09-21 13:37 - 00001069 _____ () C:\Users\Administrator\Desktop\Vokabeltrainer 1.0.lnk
2014-09-21 13:20 - 2014-09-21 13:37 - 00001069 _____ () C:\Users\Administrator\Desktop\Vokabeltrainer 1.0.lnk
2014-09-21 13:20 - 2014-09-21 13:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vokabeltrainer 1.0
2014-09-21 13:07 - 2014-09-21 13:07 - 00000000 ____D () C:\Users\Sven\Downloads\ImTranslator
2014-09-21 12:05 - 2014-09-26 14:17 - 00009216 _____ () C:\Users\Sven\Vocabulator(English-Russian).vcb
2014-09-21 11:44 - 2014-09-21 11:48 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\jvlt
2014-09-21 11:14 - 2014-09-26 14:18 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\voc2brain
2014-09-21 11:13 - 2014-09-21 11:13 - 00001033 _____ () C:\Users\Public\Desktop\Voc2brain.lnk
2014-09-21 11:13 - 2014-09-21 11:13 - 00001033 _____ () C:\Users\Public\Desktop\Voc2brain.lnk
2014-09-21 11:13 - 2014-09-21 11:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Voc2Brain
2014-09-21 11:13 - 2014-09-21 11:13 - 00000000 ____D () C:\Program Files (x86)\Voc2brain
2014-09-21 11:01 - 2014-09-21 12:03 - 00009216 _____ () C:\Users\Sven\Vocabulator(German-English).vcb
2014-09-21 10:59 - 2014-09-26 14:58 - 00000000 ___HD () C:\Program Files (x86)\InstallJammer Registry
2014-09-21 02:52 - 2014-09-21 02:52 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\FireShot
2014-09-21 02:32 - 2014-09-21 02:32 - 00000355 _____ () C:\Users\Sven\Desktop\Computer.lnk
2014-09-21 02:32 - 2014-09-21 02:32 - 00000355 _____ () C:\Users\Sven\Desktop\Computer.lnk
2014-09-20 23:52 - 2014-09-26 15:55 - 00000000 ____D () C:\Program Files (x86)\HotAlarmClock
2014-09-20 21:36 - 2014-10-12 08:06 - 00000000 ____D () C:\Users\Sven\Desktop\Word Dateien
2014-09-20 21:36 - 2014-10-12 08:06 - 00000000 ____D () C:\Users\Sven\Desktop\Word Dateien
2014-09-20 21:35 - 2014-09-26 14:04 - 00000000 ____D () C:\Users\Sven\Desktop\PDF
2014-09-20 21:35 - 2014-09-26 14:04 - 00000000 ____D () C:\Users\Sven\Desktop\PDF
2014-09-20 17:22 - 2014-09-20 17:22 - 00002212 _____ () C:\Users\Public\Desktop\Google Earth.lnk
2014-09-20 17:22 - 2014-09-20 17:22 - 00002212 _____ () C:\Users\Public\Desktop\Google Earth.lnk
2014-09-20 17:22 - 2014-09-20 17:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2014-09-20 17:22 - 2014-09-20 17:22 - 00000000 ____D () C:\Program Files (x86)\Google
2014-09-18 21:42 - 2014-09-18 21:48 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\GeoSetter
2014-09-18 21:41 - 2014-09-18 21:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GeoSetter
2014-09-18 21:41 - 2014-09-18 21:41 - 00000000 ____D () C:\Program Files (x86)\GeoSetter

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-12 09:43 - 2014-01-18 14:17 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-12 09:21 - 2009-07-14 06:45 - 00020224 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-12 09:21 - 2009-07-14 06:45 - 00020224 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-12 09:20 - 2009-07-14 19:58 - 00705074 _____ () C:\Windows\system32\perfh007.dat
2014-10-12 09:20 - 2009-07-14 19:58 - 00151468 _____ () C:\Windows\system32\perfc007.dat
2014-10-12 09:20 - 2009-07-14 07:13 - 01635716 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-12 09:14 - 2010-04-12 01:40 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-10-12 09:14 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-12 08:59 - 2010-04-11 03:56 - 00000000 ____D () C:\Users\Sven
2014-10-12 08:07 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2014-10-10 01:17 - 2012-08-14 09:58 - 00000072 _____ () C:\Users\Public\LMDebug.log
2014-10-10 01:11 - 2013-10-23 16:57 - 00000000 ____D () C:\Users\Sven\Desktop\MP3s
2014-10-10 01:11 - 2013-10-23 16:57 - 00000000 ____D () C:\Users\Sven\Desktop\MP3s
2014-10-09 16:44 - 2013-11-29 22:51 - 00000000 ____D () C:\Users\Sven\AppData\Local\Kalender1-Free
2014-10-09 03:37 - 2012-01-08 06:27 - 00000000 ____D () C:\Users\Sven\AppData\Local\Downloaded Installations
2014-10-01 09:03 - 2013-12-11 23:28 - 00000000 ____D () C:\Users\Sven\Desktop\Lesestoff
2014-10-01 09:03 - 2013-12-11 23:28 - 00000000 ____D () C:\Users\Sven\Desktop\Lesestoff
2014-10-01 08:00 - 2009-07-14 04:34 - 00000478 _____ () C:\Windows\win.ini
2014-10-01 07:54 - 2010-04-12 00:01 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Adobe
2014-10-01 07:34 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-10-01 01:51 - 2011-02-24 00:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2014-10-01 00:40 - 2014-07-11 20:56 - 00000000 ____D () C:\Users\Sven\AppData\Local\Adobe
2014-09-30 02:18 - 2012-11-04 03:22 - 00000000 ____D () C:\Program Files (x86)\JDownloader
2014-09-29 23:59 - 2014-05-15 16:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-26 14:59 - 2012-02-09 18:09 - 00000000 ____D () C:\Windows\pss
2014-09-26 14:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-09-26 14:28 - 2014-09-09 15:19 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SanDisk
2014-09-26 11:48 - 2010-04-18 20:03 - 00000000 ____D () C:\Program Files (x86)\MP3Gain
2014-09-21 17:03 - 2014-07-10 08:47 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-09-21 17:03 - 2012-11-12 02:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-09-21 17:02 - 2014-07-10 08:45 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DVDVideoSoft
2014-09-21 06:05 - 2014-01-18 14:17 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-21 06:05 - 2013-12-28 03:18 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-21 06:05 - 2013-12-28 03:18 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-21 02:27 - 2009-07-14 06:45 - 05024768 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-21 02:13 - 2014-09-11 11:27 - 00000000 ____D () C:\Users\Sven\Desktop\Rennrad
2014-09-21 02:13 - 2014-09-11 11:27 - 00000000 ____D () C:\Users\Sven\Desktop\Rennrad
2014-09-20 23:58 - 2010-04-12 08:24 - 00130344 _____ () C:\Users\Sven\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-20 21:00 - 2012-01-15 01:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinHTTrack (Webseiten abspeichern)
2014-09-17 17:28 - 2013-12-17 20:37 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-14 19:23 - 2013-10-13 10:58 - 00000000 ___RD () C:\Users\Sven\Dropbox
2014-09-12 20:49 - 2011-12-18 20:31 - 00000000 __RHD () C:\Users\Public\Libraries
2014-09-12 07:18 - 2013-05-23 21:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2014-10-06 21:05

==================== End Of Log ============================
--- --- ---

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-10-2014
Ran by Sven at 2014-10-12 10:26:57
Running from C:\Users\Sven\Desktop
Boot Mode: Normal

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Kaspersky Internet Security (Enabled - Up to date) {AE1D740B-8F0F-D137-211D-873D44B3F4AE}
AS: Kaspersky Internet Security (Enabled - Up to date) {157C95EF-A935-DEB9-1BAD-BC4F3F34BE13}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {9626F52E-C560-D06F-0A42-2E08BA60B3D5}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: - Igor Pavlov)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: - Adobe Systems Incorporated)
Adobe AIR (x32 Version: - Adobe Systems Incorporated) Hidden
Adobe Dreamweaver CS6 (HKLM-x32\...\{A4ED5E53-7AA0-11E1-BF04-B2D4D4A5360E}) (Version: 12 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Help Manager (x32 Version: 4.0.244 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CS5 (HKLM-x32\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: - Adobe Systems, Inc.)
Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.)
Adobe Widget Browser (x32 Version: 2.0.348 - Adobe Systems Incorporated.) Hidden
AIMP3 (HKLM-x32\...\AIMP3) (Version: v3.55.1355, 14.07.2014 - AIMP DevTeam)
AudibleManager (HKLM-x32\...\AudibleManager) (Version: 2002795774.48.56.6032618 - Audible, Inc.)
Audiograbber 1.83 SE  (HKLM-x32\...\Audiograbber) (Version: 1.83 SE  - Audiograbber Deutschland)
Audiograbber Lame-MP3-Plugin (HKLM-x32\...\Audiograbber-Lame) (Version: 1.0 - AG)
CCleaner (HKLM\...\CCleaner) (Version: 4.09 - Piriform)
Cobian Backup 11 Gravity (HKLM-x32\...\CobBackup11) (Version:  - )
DriveImage XML (Private Edition) (HKLM-x32\...\{F7E1CA14-B39D-452A-960B-39423DDDD933}) (Version: 2.30 - Runtime Software)
Dropbox (HKCU\...\Dropbox) (Version: 2.4.2 - Dropbox, Inc.)
Etiketten-Designer 2 (HKLM-x32\...\Etiketten-Designer 2) (Version:  - )
Firebird SQL Server - MAGIX Edition (HKLM-x32\...\Firebird SQL Server D) (Version: - MAGIX AG)
Free Countdown Timer 2.7.2 (HKLM-x32\...\{404245D0-E836-4737-9C12-D4D0034540F5}_is1) (Version: 2.7 - Comfort Software Group)
Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com)
Free YouTube to MP3 Converter version (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: - DVDVideoSoft Ltd.)
FreeFileSync v4.6 (HKLM-x32\...\FreeFileSync) (Version: 4.6 - ZenJu)
Garmin BaseCamp (HKLM-x32\...\{EBAC8FD4-28EC-46F7-BF9E-89D6E6673001}) (Version: 4.2.5 - Garmin Ltd or its subsidiaries)
Garmin Communicator Plugin (HKLM-x32\...\{647BB978-2876-487B-9B0E-FDB73F0EA4A2}) (Version: 4.0.4 - Garmin Ltd or its subsidiaries)
Garmin Communicator Plugin x64 (HKLM\...\{237D687E-9E50-4A30-B810-262764CC491B}) (Version: 4.0.4 - Garmin Ltd or its subsidiaries)
Garmin MapSource (HKLM-x32\...\{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}) (Version: 6.16.3 - Garmin Ltd or its subsidiaries)
Garmin Training Center (HKLM-x32\...\{50C913B1-A091-48B8-A434-6C9670284888}) (Version: 3.6.5 - Garmin Ltd or its subsidiaries)
Garmin Training Center (HKLM-x32\...\{7D542452-84EB-47C0-97BA-735C523AB555}) (Version: 3.6.5 - Garmin Ltd or its subsidiaries)
Garmin USB Drivers (HKLM-x32\...\{510D2239-6C2E-457B-9590-485EC552D94D}) (Version: - Garmin Ltd or its subsidiaries)
GeoSetter 3.4.16 (HKLM-x32\...\GeoSetter_is1) (Version:  - Friedemann Schmidt)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: - Google)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version:  - )
Java 7 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417045FF}) (Version: 7.0.450 - Oracle)
Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle)
Java Auto Updater (x32 Version: - Sun Microsystems, Inc.) Hidden
JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
Kalender1-Free (HKLM-x32\...\{D30E9F27-37CE-4652-8C03-6B643A896E80}) (Version:  - )
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: - Kaspersky Lab) Hidden
MAGIX 3D Maker (embeded) (HKLM-x32\...\MAGIX 3D Maker D) (Version: - MAGIX AG)
MAGIX Foto Manager 8 (D) (HKLM-x32\...\MAGIX Foto Manager 8 D) (Version: - MAGIX AG)
MAGIX Fotobuch 3.6 (HKLM-x32\...\MAGIX Fotobuch) (Version: 3.6 - MAGIX AG)
MAGIX Online Druck Service (D) (HKLM-x32\...\MAGIX Online Druck Service D) (Version: - MAGIX AG)
MAGIX Screenshare (D) (HKLM-x32\...\MAGIX Screenshare D) (Version: - MAGIX AG)
MAGIX Video deluxe 15 Plus (D) (HKLM-x32\...\MAGIX Video deluxe 15 Plus D) (Version: - MAGIX AG)
MAGIX Xtreme Foto Designer 6 (D) (HKLM-x32\...\MAGIX Xtreme Foto Designer 6 D) (Version: - MAGIX AG)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden
Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Mozilla Firefox 32.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 32.0 (x86 de)) (Version: 32.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSVC80_x64_v2 (Version: - Nokia) Hidden
MSVC80_x86_v2 (x32 Version: - Nokia) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Nvu 1.0 (HKLM-x32\...\Nvu_is1) (Version: 1.0 - Thorsten Fritz)
OpenOffice.org 3.3 (HKLM-x32\...\{4286716B-1287-48E7-9078-3DC8248DBA96}) (Version: 3.3.9567 - OpenOffice.org)
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
Platform (x32 Version: 1.34 - VIA Technologies, Inc.) Hidden
Realtek Ethernet Controller  Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0008 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Ruslanka (HKLM-x32\...\4001-9763-4923-8008) (Version: 1.2 - nautavis GmbH)
SIW version 2010.03.10 (HKLM-x32\...\{AB67580-257C-45FF-B8F4-C8C30682091A}_is1) (Version: 2010.03.10 - Topala Software Solutions)
swMSM (x32 Version: - Adobe Systems, Inc) Hidden
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.0 - Ghisler Software GmbH)
VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.)
Visual C++ 9.0 CRT (x86) WinSXS MSM (x32 Version: 9.0 - Microsoft Corporation) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Voc2brain Version 4.00.00 (HKLM-x32\...\{AC2B7503-F26A-4C4D-90BE-3EFDCBB4D157}_is1) (Version: 4.00.00 - Jonathan Kossick)
Vocup 1.4.3 (HKLM-x32\...\Vocup_is1) (Version: 1.4.3 - Florian Amstutz)
VTrain (Vokabeltrainer) Free 5.5 (Build 119) (HKLM-x32\...\VTrain Free_is1) (Version:  - Paul Raedle)
WIDI Recognition System Pro 3.3 (remove only) (HKLM-x32\...\WIDI Recognition System Pro 3.3) (Version:  - )
Windows Driver Package - Dynastream Innovations (libusb0) LibUsbDevices  (07/07/2009 1.12.2) (HKLM\...\24DA573F901348FFDFF7717497830D45BE0C362E) (Version: 07/07/2009 1.12.2 - Dynastream Innovations)
Windows Driver Package - Garmin (grmnusb) GARMIN Devices  (06/03/2009 (HKLM\...\49CF605F02C7954F4E139D18828DE298CD59217C) (Version: 06/03/2009 - Garmin)
Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation)
Zeta Producer 11 11.4.2 (nur entfernen) (HKCU\...\ZetaProducer11) (Version: 11.4.2 - Zeta Software GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2267789081-3611541687-2111919439-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2267789081-3611541687-2111919439-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2267789081-3611541687-2111919439-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2267789081-3611541687-2111919439-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2267789081-3611541687-2111919439-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)

==================== Restore Points  =========================

28-09-2014 13:26:04 Geplanter Prüfpunkt
30-09-2014 23:50:30 Removed Adobe Media Player
01-10-2014 06:00:16 Revo Uninstaller's restore point - BookPrint2
09-10-2014 00:17:29 Kalender1-Free wurde installiert.
09-10-2014 00:34:11 Revo Uninstaller's restore point - Movie Wizard
09-10-2014 01:13:43 Revo Uninstaller's restore point - Kalender1-Free
09-10-2014 13:58:41 Revo Uninstaller's restore point - Malwarebytes Anti-Malware Version
12-10-2014 06:01:43 Revo Uninstaller's restore point - Malwarebytes Anti-Malware Version

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2013-10-26 15:19 - 00001985 ____A C:\Windows\system32\Drivers\etc\hosts activate.adobe.com practivate.adobe.com ereg.adobe.com activate.wip3.adobe.com wip3.adobe.com 3dns-3.adobe.com 3dns-2.adobe.com adobe-dns.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com ereg.wip3.adobe.com activate-sea.adobe.com wwis-dubc1-vip60.adobe.com activate-sjc0.adobe.com adobe.activate.com hl2rcv.adobe.com ood.opsource.net CRL.VERISIGN.NET adobeereg.com OCSP.SPO1.VERISIGN.COM lmlicenses.wip4.adobe.com lm.licenses.adobe.com

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {56B2CAA6-BD48-486A-BF13-7E10806E9B9D} - System32\Tasks\AdobeAAMUpdater-1.0-Sven-PC-Sven => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20] (Adobe Systems Incorporated)
Task: {6100DDB6-F2CA-478C-9AE1-13513A9A035E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-17] (Piriform Ltd)
Task: {7DC95D4D-32CB-49D7-83AB-A301A2B2B0EA} - System32\Tasks\Express FilesUpdate => C:\Program Files (x86)\ExpressFiles\EFUpdater.exe <==== ATTENTION
Task: {C3A1D24E-A48D-47EE-8BD0-428D9267253F} - System32\Tasks\Morzilla => Firefox.exe 
Task: {CEB950FB-8B41-4EA8-9164-EF674AACBCD9} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {DBB17811-ACE4-49EB-8CE5-6589FF80D734} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-21] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2011-06-22 09:09 - 2011-06-22 09:09 - 00034304 _____ () C:\Windows\System32\ssp5ml6.dll
2013-06-17 13:35 - 2013-06-17 13:35 - 00478400 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll
2013-05-08 15:52 - 2013-05-08 15:52 - 01270464 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll
2014-05-15 16:16 - 2014-09-11 20:24 - 03715184 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-10-12 09:14 - 2014-10-12 09:14 - 01187704 _____ () C:\ProgramData\HhJanHrEZI\dat\RpMIYRPUN.dll
2014-09-21 06:05 - 2014-09-21 06:05 - 16825520 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
2014-01-03 08:59 - 2014-02-10 19:04 - 00430080 _____ () C:\Windows\mod_frst.exe

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:5F64C164

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: Fax => 3
MSCONFIG\Services: FirebirdServerMAGIXInstance => 3
MSCONFIG\Services: ose => 3
MSCONFIG\Services: SENS => 2
MSCONFIG\Services: Wlansvc => 2
MSCONFIG\Services: WMPNetworkSvc => 3
MSCONFIG\Services: WSearch => 2
MSCONFIG\Services: wuauserv => 3
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^StartUp^firefox.exe => C:\Windows\pss\firefox.exe.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^StartUp^Kalender1-Free.lnk => C:\Windows\pss\Kalender1-Free.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^StartUp^to-find-out.lnk => C:\Windows\pss\to-find-out.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^StartUp^Voc2brain.lnk => C:\Windows\pss\Voc2brain.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Sven^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Sven^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MyPC Backup.lnk => C:\Windows\pss\MyPC Backup.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Sven^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk => C:\Windows\pss\OpenOffice.org 3.3.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: AdobeCS5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: AlternateTimer => C:\Program Files (x86)\Alternate\Timer\AlternateTimer.exe -auto
MSCONFIG\startupreg: ANT Agent => C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BookPrServ => C:\Program Files (x86)\BookPrint2\BookPrServ.EXE
MSCONFIG\startupreg: FreeCT => C:\Program Files (x86)\FreeCountdownTimer\FreeCountdownTimer.exe -autorun
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: gStart => C:\Program Files (x86)\Garmin\gStart.exe
MSCONFIG\startupreg: HDAudDeck => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
MSCONFIG\startupreg: Johnny Squeeze Refresh => C:\Program Files\JohnnyAnimation\Johnny Squeeze\squeeze_remember.exe
MSCONFIG\startupreg: Ocs_SM => C:\Users\Sven\AppData\Roaming\OCS\SM\SearchAnonymizer.exe
MSCONFIG\startupreg: OM2_Monitor => "C:\Program Files (x86)\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
MSCONFIG\startupreg: Optimizer Pro => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe
MSCONFIG\startupreg: PC Suite Tray => "C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SwitchBoard => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
MSCONFIG\startupreg: TrayServer => C:\PROGRA~2\MAGIX\VIDEO_~1\TrayServer.exe
MSCONFIG\startupreg: Windows Mobile Device Center => %windir%\WindowsMobile\wmdc.exe
MSCONFIG\startupreg: Yontoo Desktop => "C:\Users\Sven\AppData\Roaming\Yontoo\YontooDesktop.exe"

========================= Accounts: ==========================

Administrator (S-1-5-21-2267789081-3611541687-2111919439-500 - Administrator - Enabled) => C:\Users\Administrator
Gast (S-1-5-21-2267789081-3611541687-2111919439-501 - Limited - Disabled)
Sven (S-1-5-21-2267789081-3611541687-2111919439-1000 - Administrator - Enabled) => C:\Users\Sven

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:
Error: (10/12/2014 07:33:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbam.exe, Version:, Zeitstempel: 0x53518532
Name des fehlerhaften Moduls: MSVCR100.dll, Version: 10.0.40219.325, Zeitstempel: 0x4df2be1e
Ausnahmecode: 0x40000015
Fehleroffset: 0x0008d6fd
ID des fehlerhaften Prozesses: 0xde4
Startzeit der fehlerhaften Anwendung: 0xmbam.exe0
Pfad der fehlerhaften Anwendung: mbam.exe1
Pfad des fehlerhaften Moduls: mbam.exe2
Berichtskennung: mbam.exe3

Error: (10/11/2014 10:38:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbam.exe, Version:, Zeitstempel: 0x53518532
Name des fehlerhaften Moduls: MSVCR100.dll, Version: 10.0.40219.325, Zeitstempel: 0x4df2be1e
Ausnahmecode: 0x40000015
Fehleroffset: 0x0008d6fd
ID des fehlerhaften Prozesses: 0x7b8
Startzeit der fehlerhaften Anwendung: 0xmbam.exe0
Pfad der fehlerhaften Anwendung: mbam.exe1
Pfad des fehlerhaften Moduls: mbam.exe2
Berichtskennung: mbam.exe3

Error: (10/10/2014 03:35:24 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbam.exe, Version:, Zeitstempel: 0x53518532
Name des fehlerhaften Moduls: MSVCR100.dll, Version: 10.0.40219.325, Zeitstempel: 0x4df2be1e
Ausnahmecode: 0x40000015
Fehleroffset: 0x0008d6fd
ID des fehlerhaften Prozesses: 0xb58
Startzeit der fehlerhaften Anwendung: 0xmbam.exe0
Pfad der fehlerhaften Anwendung: mbam.exe1
Pfad des fehlerhaften Moduls: mbam.exe2
Berichtskennung: mbam.exe3

Error: (10/10/2014 02:32:18 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbam.exe, Version:, Zeitstempel: 0x53518532
Name des fehlerhaften Moduls: MSVCR100.dll, Version: 10.0.40219.325, Zeitstempel: 0x4df2be1e
Ausnahmecode: 0x40000015
Fehleroffset: 0x0008d6fd
ID des fehlerhaften Prozesses: 0xddc
Startzeit der fehlerhaften Anwendung: 0xmbam.exe0
Pfad der fehlerhaften Anwendung: mbam.exe1
Pfad des fehlerhaften Moduls: mbam.exe2
Berichtskennung: mbam.exe3

Error: (10/10/2014 02:15:02 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbam.exe, Version:, Zeitstempel: 0x53518532
Name des fehlerhaften Moduls: MSVCR100.dll, Version: 10.0.40219.325, Zeitstempel: 0x4df2be1e
Ausnahmecode: 0x40000015
Fehleroffset: 0x0008d6fd
ID des fehlerhaften Prozesses: 0xee4
Startzeit der fehlerhaften Anwendung: 0xmbam.exe0
Pfad der fehlerhaften Anwendung: mbam.exe1
Pfad des fehlerhaften Moduls: mbam.exe2
Berichtskennung: mbam.exe3

Error: (10/10/2014 01:36:29 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbam.exe, Version:, Zeitstempel: 0x53518532
Name des fehlerhaften Moduls: MSVCR100.dll, Version: 10.0.40219.325, Zeitstempel: 0x4df2be1e
Ausnahmecode: 0x40000015
Fehleroffset: 0x0008d6fd
ID des fehlerhaften Prozesses: 0xc30
Startzeit der fehlerhaften Anwendung: 0xmbam.exe0
Pfad der fehlerhaften Anwendung: mbam.exe1
Pfad des fehlerhaften Moduls: mbam.exe2
Berichtskennung: mbam.exe3

Error: (10/10/2014 01:33:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbam.exe, Version:, Zeitstempel: 0x53518532
Name des fehlerhaften Moduls: MSVCR100.dll, Version: 10.0.40219.325, Zeitstempel: 0x4df2be1e
Ausnahmecode: 0x40000015
Fehleroffset: 0x0008d6fd
ID des fehlerhaften Prozesses: 0xb9c
Startzeit der fehlerhaften Anwendung: 0xmbam.exe0
Pfad der fehlerhaften Anwendung: mbam.exe1
Pfad des fehlerhaften Moduls: mbam.exe2
Berichtskennung: mbam.exe3

Error: (10/10/2014 00:48:31 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbam.exe, Version:, Zeitstempel: 0x53518532
Name des fehlerhaften Moduls: MSVCR100.dll, Version: 10.0.40219.325, Zeitstempel: 0x4df2be1e
Ausnahmecode: 0x40000015
Fehleroffset: 0x0008d6fd
ID des fehlerhaften Prozesses: 0x874
Startzeit der fehlerhaften Anwendung: 0xmbam.exe0
Pfad der fehlerhaften Anwendung: mbam.exe1
Pfad des fehlerhaften Moduls: mbam.exe2
Berichtskennung: mbam.exe3

Error: (10/10/2014 00:37:31 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbam.exe, Version:, Zeitstempel: 0x53518532
Name des fehlerhaften Moduls: MSVCR100.dll, Version: 10.0.40219.325, Zeitstempel: 0x4df2be1e
Ausnahmecode: 0x40000015
Fehleroffset: 0x0008d6fd
ID des fehlerhaften Prozesses: 0x780
Startzeit der fehlerhaften Anwendung: 0xmbam.exe0
Pfad der fehlerhaften Anwendung: mbam.exe1
Pfad des fehlerhaften Moduls: mbam.exe2
Berichtskennung: mbam.exe3

Error: (10/10/2014 00:36:31 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbam.exe, Version:, Zeitstempel: 0x53518532
Name des fehlerhaften Moduls: MSVCR100.dll, Version: 10.0.40219.325, Zeitstempel: 0x4df2be1e
Ausnahmecode: 0x40000015
Fehleroffset: 0x0008d6fd
ID des fehlerhaften Prozesses: 0x744
Startzeit der fehlerhaften Anwendung: 0xmbam.exe0
Pfad der fehlerhaften Anwendung: mbam.exe1
Pfad des fehlerhaften Moduls: mbam.exe2
Berichtskennung: mbam.exe3

System errors:
Error: (10/12/2014 09:14:24 AM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (10/12/2014 09:14:24 AM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter

Error: (10/12/2014 09:14:18 AM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 6) (User: NT-AUTORITÄT)
Description: Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten.

Error: (10/12/2014 08:53:41 AM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (10/12/2014 08:53:41 AM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter

Error: (10/12/2014 08:53:35 AM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 6) (User: NT-AUTORITÄT)
Description: Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten.

Error: (10/12/2014 08:46:21 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "UPnP-Gerätehost" ist vom Dienst "SSDP-Suche" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 

Error: (10/12/2014 08:46:21 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1068upnphost{204810B9-73B2-11D4-BF42-00B0D0118B56}

Error: (10/12/2014 08:07:26 AM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (10/12/2014 08:07:26 AM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter

Microsoft Office Sessions:
Error: (04/26/2014 00:46:54 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (02/08/2014 05:18:54 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 4931 seconds with 4200 seconds of active time.  This session ended with a crash.

Error: (12/11/2012 01:32:10 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 173 seconds with 60 seconds of active time.  This session ended with a crash.

Error: (01/08/2012 01:04:47 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 8 seconds with 0 seconds of active time.  This session ended with a crash.

==================== Memory info =========================== 

Processor: AMD Phenom(tm) II X4 945 Processor
Percentage of memory in use: 38%
Total physical RAM: 4095.3 MB
Available physical RAM: 2532.41 MB
Total Pagefile: 8188.79 MB
Available Pagefile: 6314.51 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:112.05 GB) NTFS
Drive d: () (Fixed) (Total:0.1 GB) (Free:0.08 GB) NTFS
Drive e: () (Fixed) (Total:931.41 GB) (Free:0.4 GB) NTFS
Drive z: (Volume) (Fixed) (Total:465.76 GB) (Free:230.51 GB) NTFS

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 4636EA9E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: F27ED734)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)

Disk: 6 (Size: 465.8 GB) (Disk ID: 01E248E7)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

==================== End Of Log ============================

/// the machine
/// TB-Ausbilder

Windows 7: Adware eingefangen - Standard

Windows 7: Adware eingefangen


Scan mit Combofix
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


Windows 7: Adware eingefangen - Standard

Windows 7: Adware eingefangen

ComboFix 14-10-13.01 - Sven 13.10.2014  14:55:55.2.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.4095.2757 [GMT 2:00]
ausgeführt von:: c:\users\Sven\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886}
FW: Kaspersky Internet Security *Disabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
SP: Kaspersky Internet Security *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
---- Vorheriger Suchlauf -------
(((((((((((((((((((((((   Dateien erstellt von 2014-09-13 bis 2014-10-13  ))))))))))))))))))))))))))))))
2014-10-13 13:04 . 2014-10-13 13:04	--------	d-----w-	c:\users\Default\AppData\Local\temp
2014-10-13 13:04 . 2014-10-13 13:04	--------	d-----w-	c:\users\Administrator\AppData\Local\temp
2014-10-13 12:42 . 2014-09-15 00:08	11578928	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{39DDA5D7-56A5-4C38-94EE-FBB2BCAB0FD8}\mpengine.dll
2014-10-13 12:17 . 2014-03-09 21:48	171160	----a-w-	c:\windows\system32\infocardapi.dll
2014-10-13 12:17 . 2014-03-09 21:48	1389208	----a-w-	c:\windows\system32\icardagt.exe
2014-10-13 12:17 . 2014-03-09 21:47	99480	----a-w-	c:\windows\SysWow64\infocardapi.dll
2014-10-13 12:17 . 2014-03-09 21:47	619672	----a-w-	c:\windows\SysWow64\icardagt.exe
2014-10-13 12:16 . 2014-06-30 22:24	8856	----a-w-	c:\windows\system32\icardres.dll
2014-10-13 12:16 . 2014-06-30 22:14	8856	----a-w-	c:\windows\SysWow64\icardres.dll
2014-10-13 12:16 . 2014-06-06 06:16	35480	----a-w-	c:\windows\SysWow64\TsWpfWrp.exe
2014-10-13 12:16 . 2014-06-06 06:12	35480	----a-w-	c:\windows\system32\TsWpfWrp.exe
2014-10-13 11:24 . 2014-07-07 02:06	1460736	----a-w-	c:\windows\system32\lsasrv.dll
2014-10-13 11:24 . 2014-07-07 02:06	728064	----a-w-	c:\windows\system32\kerberos.dll
2014-10-13 11:24 . 2014-07-07 01:40	22016	----a-w-	c:\windows\SysWow64\secur32.dll
2014-10-13 11:24 . 2014-07-07 01:40	550912	----a-w-	c:\windows\SysWow64\kerberos.dll
2014-10-13 11:24 . 2014-07-07 01:39	96768	----a-w-	c:\windows\SysWow64\sspicli.dll
2014-10-13 11:22 . 2014-06-16 02:10	985536	----a-w-	c:\windows\system32\drivers\dxgkrnl.sys
2014-10-13 11:22 . 2014-03-25 02:43	14175744	----a-w-	c:\windows\system32\shell32.dll
2014-10-13 11:22 . 2014-03-26 14:44	2002432	----a-w-	c:\windows\system32\msxml6.dll
2014-10-13 11:22 . 2014-03-26 14:44	1882112	----a-w-	c:\windows\system32\msxml3.dll
2014-10-13 11:22 . 2014-03-26 14:27	1389056	----a-w-	c:\windows\SysWow64\msxml6.dll
2014-10-13 11:22 . 2014-03-26 14:27	1237504	----a-w-	c:\windows\SysWow64\msxml3.dll
2014-10-13 11:22 . 2014-03-26 14:41	2048	----a-w-	c:\windows\system32\msxml6r.dll
2014-10-13 11:22 . 2014-03-26 14:41	2048	----a-w-	c:\windows\system32\msxml3r.dll
2014-10-13 11:22 . 2014-03-26 14:25	2048	----a-w-	c:\windows\SysWow64\msxml6r.dll
2014-10-13 11:22 . 2014-03-26 14:25	2048	----a-w-	c:\windows\SysWow64\msxml3r.dll
2014-10-13 11:20 . 2014-04-05 02:47	1903552	----a-w-	c:\windows\system32\drivers\tcpip.sys
2014-10-13 11:20 . 2014-04-05 02:47	288192	----a-w-	c:\windows\system32\drivers\FWPKCLNT.SYS
2014-10-13 11:20 . 2013-11-26 11:40	376768	----a-w-	c:\windows\system32\drivers\netio.sys
2014-10-13 11:20 . 2014-04-25 02:34	801280	----a-w-	c:\windows\system32\usp10.dll
2014-10-13 11:20 . 2014-04-25 02:06	626688	----a-w-	c:\windows\SysWow64\usp10.dll
2014-10-13 11:20 . 2013-11-27 01:41	343040	----a-w-	c:\windows\system32\drivers\usbhub.sys
2014-10-13 11:20 . 2013-11-27 01:41	99840	----a-w-	c:\windows\system32\drivers\usbccgp.sys
2014-10-13 11:20 . 2013-11-27 01:41	53248	----a-w-	c:\windows\system32\drivers\usbehci.sys
2014-10-13 11:20 . 2013-11-27 01:41	325120	----a-w-	c:\windows\system32\drivers\usbport.sys
2014-10-13 11:20 . 2013-11-27 01:41	25600	----a-w-	c:\windows\system32\drivers\usbohci.sys
2014-10-13 11:20 . 2013-11-27 01:41	30720	----a-w-	c:\windows\system32\drivers\usbuhci.sys
2014-10-13 11:20 . 2013-11-27 01:41	7808	----a-w-	c:\windows\system32\drivers\usbd.sys
2014-10-13 10:57 . 2014-10-13 11:08	--------	d-----w-	C:\CombooFix
2014-10-12 08:25 . 2014-10-12 08:27	--------	d-----w-	C:\FRST
2014-10-11 20:05 . 2014-10-11 20:05	--------	d-----w-	c:\programdata\Browser
2014-10-09 16:25 . 2014-10-09 16:25	--------	d-----w-	c:\windows\ERUNT
2014-10-09 13:56 . 2014-10-09 13:56	--------	d-----w-	c:\programdata\Malwarebytes
2014-10-09 13:29 . 2010-08-30 06:34	536576	----a-w-	c:\windows\SysWow64\sqlite3.dll
2014-10-09 13:28 . 2014-10-09 23:49	--------	d-----w-	C:\AdwCleaner
2014-10-09 01:52 . 2014-10-09 01:52	--------	d-----w-	c:\program files (x86)\Kalender1-Free
2014-10-09 00:14 . 2014-10-13 10:45	--------	d-----w-	c:\users\Sven\AppData\Local\MovieWizard
2014-10-09 00:14 . 2014-10-09 00:14	--------	d-----w-	c:\programdata\HhJanHrEZI
2014-10-09 00:09 . 2014-10-09 00:09	--------	d-----w-	c:\program files\LopeSoft
2014-10-01 00:16 . 2014-10-13 12:17	--------	d-----w-	c:\users\Sven\AppData\Roaming\vlc
2014-10-01 00:00 . 2014-10-01 00:00	--------	d-----w-	c:\program files\VideoLAN
2014-09-30 23:13 . 2007-03-05 11:55	15360	----a-w-	c:\windows\system32\Spool\prtprocs\x64\bookprnt.dll
2014-09-30 22:35 . 2014-09-30 22:35	--------	d-----w-	c:\program files (x86)\Etiketten-Designer 2
2014-09-30 22:17 . 2014-10-13 12:47	--------	d-----w-	c:\users\Sven\AppData\Roaming\AIMP3
2014-09-30 22:17 . 2014-09-30 22:17	--------	d-----w-	c:\program files (x86)\AIMP3
2014-09-26 14:25 . 2014-09-26 14:26	--------	d-----w-	c:\users\Sven\.ruslanka
2014-09-26 14:24 . 2014-09-26 14:24	--------	d-----w-	c:\program files (x86)\Ruslanka
2014-09-26 13:23 . 2014-09-26 13:23	--------	d-----w-	c:\users\Sven\AppData\Roaming\Langenscheidt
2014-09-26 13:23 . 2014-09-26 13:23	--------	d-----w-	c:\programdata\Langenscheidt
2014-09-26 13:10 . 2014-09-26 13:10	--------	d-----w-	c:\users\Sven\AppData\Roaming\VTrain
2014-09-26 13:10 . 2014-09-26 13:21	--------	d-----w-	c:\program files (x86)\VTrain
2014-09-26 12:15 . 2014-09-26 12:15	--------	d-----w-	C:\MemoStep6_14
2014-09-21 15:02 . 2014-09-21 15:02	--------	d-----w-	c:\program files (x86)\Common Files\DVDVideoSoft
2014-09-21 11:40 . 2014-09-21 11:40	--------	d-----w-	c:\users\Sven\AppData\Roaming\Vocup
2014-09-21 11:40 . 2014-09-21 11:40	--------	d-----w-	c:\users\Sven\AppData\Local\_0_
2014-09-21 11:40 . 2014-09-26 12:57	--------	d-----w-	c:\program files (x86)\Vocup
2014-09-21 11:31 . 2014-09-21 11:31	--------	d-----w-	c:\program files\JohnnyAnimation
2014-09-21 11:27 . 2014-09-26 13:04	--------	d-----w-	c:\program files (x86)\MemoStep6
2014-09-21 11:20 . 2014-09-30 22:35	87704	----a-w-	c:\windows\cadkasdeinst01.exe
2014-09-21 11:20 . 2014-09-26 12:57	--------	d-----w-	c:\program files (x86)\Vokabeltrainer 1
2014-09-21 09:44 . 2014-09-21 09:48	--------	d-----w-	c:\users\Sven\AppData\Roaming\jvlt
2014-09-21 09:14 . 2014-09-26 12:18	--------	d-----w-	c:\users\Sven\AppData\Roaming\voc2brain
2014-09-21 09:13 . 2014-09-21 09:13	--------	d-----w-	c:\program files (x86)\Voc2brain
2014-09-21 08:59 . 2014-09-26 12:58	--------	d--h--w-	c:\program files (x86)\InstallJammer Registry
2014-09-21 00:52 . 2014-09-21 00:52	--------	d-----w-	c:\users\Sven\AppData\Roaming\FireShot
2014-09-20 21:52 . 2014-09-26 13:55	--------	d-----w-	c:\program files (x86)\HotAlarmClock
2014-09-20 15:22 . 2014-09-20 15:22	--------	d-----w-	c:\program files (x86)\Google
2014-09-18 19:42 . 2014-09-18 19:48	--------	d-----w-	c:\users\Sven\AppData\Roaming\GeoSetter
2014-09-18 19:41 . 2014-09-18 19:41	--------	d-----w-	c:\program files (x86)\GeoSetter
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
2014-09-21 04:05 . 2013-12-28 01:18	71344	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-09-21 04:05 . 2013-12-28 01:18	701104	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2014-09-15 07:06 . 2010-04-11 02:15	278152	------w-	c:\windows\system32\MpSigStub.exe
2014-08-29 11:01 . 2012-02-10 14:06	101694776	----a-w-	c:\windows\system32\MRT.exe
2014-07-25 00:35 . 2014-07-25 00:35	875688	----a-w-	c:\windows\SysWow64\msvcr120_clr0400.dll
2014-07-24 21:47 . 2014-07-24 21:47	869544	----a-w-	c:\windows\system32\msvcr120_clr0400.dll
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
2013-09-11 02:09	131248	----a-w-	c:\users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
2013-09-11 02:09	131248	----a-w-	c:\users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
2013-09-11 02:09	131248	----a-w-	c:\users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
2013-09-11 02:09	131248	----a-w-	c:\users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
"AdobeBridge"="" [BU]
"NPSStartup"="" [BU]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\MAGIX\Common\Database\bin\fbserver.exe;c:\program files (x86)\MAGIX\Common\Database\bin\fbserver.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys;c:\windows\SYSNATIVE\Drivers\TFsExDisk.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R4 cbVSCService11;Cobian Backup 11 Volume Shadow Copy Requester;c:\program files (x86)\Cobian Backup 11\cbVSCService11.exe;c:\program files (x86)\Cobian Backup 11\cbVSCService11.exe [x]
R4 klflt;klflt;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x]
R4 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 LSFDLPRh;LSFDLPRh;c:\programdata\HhJanHrEZI\LSFDLPRh.exe;c:\programdata\HhJanHrEZI\LSFDLPRh.exe [x]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]
start [BU]
Inhalt des "geplante Tasks" Ordners
2014-10-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-28 04:05]
--------- X64 Entries -----------
2013-09-11 02:09	164016	----a-w-	c:\users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
2013-09-11 02:09	164016	----a-w-	c:\users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
2013-09-11 02:09	164016	----a-w-	c:\users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
2013-09-11 02:09	164016	----a-w-	c:\users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
------- Zusätzlicher Suchlauf -------
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:newtab
uDefault_Search_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
mStart Page = about:newtab
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2D06158FAC79A790.dll/cmsidewiki.html
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Zu Anti-Banner hinzufügen - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ie_banner_deny.htm
Trusted Zone: samsungsetup.com\www
TCP: DhcpNameServer =
FF - ProfilePath - c:\users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\
FF - prefs.js: browser.startup.homepage - about:home
- - - - Entfernte verwaiste Registrierungseinträge - - - -
Toolbar-10 - (no file)
Toolbar-10 - (no file)
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
@Denied: (Full) (Everyone)
------------------------ Weitere laufende Prozesse ------------------------
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
Zeit der Fertigstellung: 2014-10-13  15:15:10 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2014-10-13 13:15
Vor Suchlauf: 16 Verzeichnis(se), 119.013.740.544 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 119.576.932.352 Bytes frei
- - End Of File - - 6F8622901EA6AFFEE7F90F1A66F7C74F

/// the machine
/// TB-Ausbilder

Windows 7: Adware eingefangen - Standard

Windows 7: Adware eingefangen

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.

und ein frisches FRST log bitte.
--> Windows 7: Adware eingefangen

Windows 7: Adware eingefangen - Standard

Windows 7: Adware eingefangen

 Malwarebytes Anti-Malware 

Protection, 14.10.2014 13:06:08, SYSTEM, SVEN-PC, Protection, Malware Protection, Starting, 
Protection, 14.10.2014 13:06:08, SYSTEM, SVEN-PC, Protection, Malware Protection, Started, 
Protection, 14.10.2014 13:06:08, SYSTEM, SVEN-PC, Protection, Malicious Website Protection, Starting, 
Protection, 14.10.2014 13:06:08, SYSTEM, SVEN-PC, Protection, Malicious Website Protection, Failed, 
Error, 14.10.2014 13:06:08, SYSTEM, SVEN-PC, Protection, MWAC::CreateList - Block List, 3221225473, 
Update, 14.10.2014 13:06:21, SYSTEM, SVEN-PC, Manual, Rootkit Database, 2014.9.18.1, 2014.10.11.1, 
Update, 14.10.2014 13:07:38, SYSTEM, SVEN-PC, Manual, Malware Database, 2014.9.19.5, 2014.10.14.8, 
Protection, 14.10.2014 13:07:38, SYSTEM, SVEN-PC, Protection, Refresh, Starting, 
Protection, 14.10.2014 13:07:43, SYSTEM, SVEN-PC, Protection, Refresh, Success, 
Scan, 14.10.2014 13:20:53, SYSTEM, SVEN-PC, Manual, Start: % 1 "% 2", Dauer: % 1 min 10 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, 19-Malwareerkennung, 
Protection, 14.10.2014 13:24:01, SYSTEM, SVEN-PC, Protection, Malware Protection, Starting, 
Protection, 14.10.2014 13:24:01, SYSTEM, SVEN-PC, Protection, Malware Protection, Started, 
Protection, 14.10.2014 13:24:01, SYSTEM, SVEN-PC, Protection, Malicious Website Protection, Starting, 
Protection, 14.10.2014 13:24:20, SYSTEM, SVEN-PC, Protection, Malicious Website Protection, Failed, 
Error, 14.10.2014 13:24:20, SYSTEM, SVEN-PC, Protection, MWAC::CreateList - Block List, 3221225473, 


# AdwCleaner v4.000 - Bericht erstellt am 14/10/2014 um 13:36:28
# DB v2014-10-13.5
# Aktualisiert 12/10/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Sven - SVEN-PC
# Gestartet von : C:\Users\Sven\Desktop\AdwCleaner_4.000.exe
# Option : Löschen

***** [ Dienste ] *****

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\Browser

***** [ Tasks ] *****

Task Gelöscht : Express FilesUpdate
Task Gelöscht : LaunchSignup

***** [ Verknüpfungen ] *****

***** [ Registrierungsdatenbank ] *****

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17280

-\\ Mozilla Firefox v32.0 (x86 de)

-\\ Google Chrome v


AdwCleaner[R0].txt - [19956 octets] - [09/10/2014 15:28:46]
AdwCleaner[R1].txt - [1280 octets] - [09/10/2014 15:34:30]
AdwCleaner[R2].txt - [1400 octets] - [09/10/2014 15:41:19]
AdwCleaner[R3].txt - [1460 octets] - [09/10/2014 18:18:13]
AdwCleaner[R4].txt - [1520 octets] - [09/10/2014 23:30:43]
AdwCleaner[R5].txt - [1580 octets] - [10/10/2014 01:48:37]
AdwCleaner[R6].txt - [1386 octets] - [14/10/2014 13:33:03]
AdwCleaner[S0].txt - [17111 octets] - [09/10/2014 15:30:20]
AdwCleaner[S1].txt - [1274 octets] - [09/10/2014 15:38:25]
AdwCleaner[S2].txt - [1299 octets] - [14/10/2014 13:36:28]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1359 octets] ##########

Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.14.2014:1)
OS: Windows 7 Home Premium x64
Ran by Sven on 14.10.2014 at 14:06:20,66

~~~ Services

~~~ Registry Values

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011501160}

~~~ Files

~~~ Folders

~~~ FireFox

Successfully deleted: [Folder] C:\Users\Sven\AppData\Roaming\mozilla\firefox\profiles\9nkzu0yq.Standard-Benutzer\extensions\staged
Successfully deleted the following from C:\Users\Sven\AppData\Roaming\mozilla\firefox\profiles\jwywnhv7.default\prefs.js

user_pref("HomeTab_6787.global.DisplayRecentSearches", "true");
user_pref("browser.search.searchEnginesURL", "www.google.de");
Emptied folder: C:\Users\Sven\AppData\Roaming\mozilla\firefox\profiles\jwywnhv7.default\minidumps [214 files]

~~~ Event Viewer Logs were cleared

Scan was completed on 14.10.2014 at 14:21:02,88
End of JRT log

/// the machine
/// TB-Ausbilder

Windows 7: Adware eingefangen - Standard

Windows 7: Adware eingefangen

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?

Windows 7: Adware eingefangen - Standard

Windows 7: Adware eingefangen

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=
# OnlineScanner.ocx=
# api_version=3.0.2
# EOSSerial=758a918598bfa042ac3525090b114ef3
# engine=20607
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-10-15 04:09:36
# local_time=2014-10-15 06:09:36 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Kaspersky Internet Security'
# compatibility_mode=1292 16777214 100 100 25878 44863798 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 30700 165019226 0 0
# scanned=559524
# found=17
# cleaned=0
# scan_time=24965
sh=052529D1B57123707DE6304CA2A2E8832E80A1F1 ft=1 fh=487ceb503c81f5f9 vn="Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Conduit\Community Alerts\Alert.dll.vir"
sh=410B32FD3FE4642644AD91AC60C69B86EC2762DD ft=1 fh=0e378a435beab91a vn="Variante von Win32/Adware.Yontoo.B Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll.vir"
sh=4F1EC034FA273DF15EBEF1E3FA66F819DB8A1943 ft=1 fh=752909aa377c6468 vn="Variante von Win32/RegistryBooster evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Sven\AppData\Roaming\OpenCandy\OpenCandy_E8C296CD8F7E40249A61E71271E4F1D1\registrybooster(9).exe.vir"
sh=0DBEC8AE9731917332AC3586DBBB6B5D788E736A ft=1 fh=a6305a67b679b1f8 vn="Variante von MSIL/Adware.PullUpdate.C Anwendung" ac=I fn="C:\ProgramData\HhJanHrEZI\dat\UUOrRoduiDc.dll"
sh=0DBEC8AE9731917332AC3586DBBB6B5D788E736A ft=1 fh=a6305a67b679b1f8 vn="Variante von MSIL/Adware.PullUpdate.C Anwendung" ac=I fn="C:\Users\All Users\HhJanHrEZI\dat\UUOrRoduiDc.dll"
sh=E781FA9D24E9CD76092DD0AE897906CB69790024 ft=1 fh=b0b5e08c4e592cd4 vn="NSIS/StartPage.CC Trojaner" ac=I fn="C:\Users\Sven\Desktop\Neue Downloads\vlc-2.1.5-win64.exe"
sh=79A4C780524D954794F0B2F71700D91BFF42108A ft=1 fh=7a35a830d8dcb46e vn="Variante von Win32/WinloadSDA.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Sven\Desktop\Neue Downloads\Frank Buschmann - Am Ende Kackt die Ente\ABBYY-Lingvo-x3-lnstall.exe"
sh=E1FF212CE56455D90CF6401DED1DB34F65675843 ft=1 fh=843a4dbdfe31ff8e vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\X\Privat\Heiko\Homepage\NVU\KompoZer - CHIP-Downloader.exe"
sh=E1FF212CE56455D90CF6401DED1DB34F65675843 ft=1 fh=843a4dbdfe31ff8e vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\X\Privat\Homepage\NVU\KompoZer - CHIP-Downloader.exe"
sh=DCED01C2BFF0D66AC8D0225281779B29BB8420BE ft=1 fh=470feae295438596 vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="E:\X\Privat\Noten\SoftonicDownloader_fuer_gitarrenkurs-band-i.exe"
sh=15C574DF65F4253CF4A5D86B66A95D22B8D2EDFD ft=1 fh=ad1f51270cfc99f0 vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="E:\X\Privat\Noten\SoftonicDownloader_fuer_gitarrenkurs-band-ii.exe"
sh=052529D1B57123707DE6304CA2A2E8832E80A1F1 ft=1 fh=487ceb503c81f5f9 vn="Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung" ac=I fn="Y:\29.12.2013\C\Program Files (x86)\Conduit\Community Alerts\Alert.dll"
sh=410B32FD3FE4642644AD91AC60C69B86EC2762DD ft=1 fh=0e378a435beab91a vn="Variante von Win32/Adware.Yontoo.B Anwendung" ac=I fn="Y:\29.12.2013\C\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll"
sh=E1FF212CE56455D90CF6401DED1DB34F65675843 ft=1 fh=843a4dbdfe31ff8e vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="Y:\29.12.2013\X\Privat\Heiko\Homepage\NVU\KompoZer - CHIP-Downloader.exe"
sh=E1FF212CE56455D90CF6401DED1DB34F65675843 ft=1 fh=843a4dbdfe31ff8e vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="Y:\29.12.2013\X\Privat\Homepage\NVU\KompoZer - CHIP-Downloader.exe"
sh=DCED01C2BFF0D66AC8D0225281779B29BB8420BE ft=1 fh=470feae295438596 vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="Y:\29.12.2013\X\Privat\Noten\SoftonicDownloader_fuer_gitarrenkurs-band-i.exe"
sh=15C574DF65F4253CF4A5D86B66A95D22B8D2EDFD ft=1 fh=ad1f51270cfc99f0 vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="Y:\29.12.2013\X\Privat\Noten\SoftonicDownloader_fuer_gitarrenkurs-band-ii.exe"
 Results of screen317's Security Check version 0.99.87  
 Windows 7 Service Pack 1 x64 (UAC is disabled!)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
Kaspersky Internet Security   
 Antivirus up to date!  (On Access scanning disabled!) 
`````````Anti-malware/Other Utilities Check:````````` 
 Java 7 Update 45  
 Java version out of Date! 
 Adobe Flash Player  
 Adobe Reader XI  
 Mozilla Firefox (32.0) 
````````Process Check: objlist.exe by Laurent````````  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````

/// the machine
/// TB-Ausbilder

Windows 7: Adware eingefangen - Standard

Windows 7: Adware eingefangen

Alt 17.10.2014, 05:37   #11
Windows 7: Adware eingefangen - Standard

Windows 7: Adware eingefangen

Ab und zu hakt der Browser beim Laden von Videos und es öffnet sich ab und zu ein Werbefenster. Ich weiß aber nicht, ob das nun mit der Infizierung zusammen hängt, oder nicht. Jedenfalls war vorher davon nichts zu bemerken.
Beim darauf folgenden Scan mit ESET hat er immer noch 17 infizierte Dateien erkannt!!! Deshalb glaube ich nicht, dass der Rechner nun sauber ist.

Java konnte ich nicht aktualisieren. Also hab ich es gelöscht und neu runter geladen. Die Neuinstallation schlug aber mehrmals fehl(Fehler: 1603). Also hab ich es erst mal ganz sein gelassen.

ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=
# OnlineScanner.ocx=
# api_version=3.0.2
# EOSSerial=3bddffb7edb238419d0392edb8b88b21
# engine=20637
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-10-17 03:31:01
# local_time=2014-10-17 05:31:01 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Kaspersky Internet Security'
# compatibility_mode=1292 16777214 100 100 17821 44991083 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 28277 165146511 0 0
# scanned=557944
# found=17
# cleaned=0
# scan_time=9715
sh=052529D1B57123707DE6304CA2A2E8832E80A1F1 ft=1 fh=487ceb503c81f5f9 vn="Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Conduit\Community Alerts\Alert.dll.vir"
sh=410B32FD3FE4642644AD91AC60C69B86EC2762DD ft=1 fh=0e378a435beab91a vn="Variante von Win32/Adware.Yontoo.B Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll.vir"
sh=4F1EC034FA273DF15EBEF1E3FA66F819DB8A1943 ft=1 fh=752909aa377c6468 vn="Variante von Win32/RegistryBooster evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Sven\AppData\Roaming\OpenCandy\OpenCandy_E8C296CD8F7E40249A61E71271E4F1D1\registrybooster(9).exe.vir"
sh=0DBEC8AE9731917332AC3586DBBB6B5D788E736A ft=1 fh=a6305a67b679b1f8 vn="Variante von MSIL/Adware.PullUpdate.C Anwendung" ac=I fn="C:\ProgramData\HhJanHrEZI\dat\UUOrRoduiDc.dll"
sh=0DBEC8AE9731917332AC3586DBBB6B5D788E736A ft=1 fh=a6305a67b679b1f8 vn="Variante von MSIL/Adware.PullUpdate.C Anwendung" ac=I fn="C:\Users\All Users\HhJanHrEZI\dat\UUOrRoduiDc.dll"
sh=E781FA9D24E9CD76092DD0AE897906CB69790024 ft=1 fh=b0b5e08c4e592cd4 vn="NSIS/StartPage.CC Trojaner" ac=I fn="C:\Users\Sven\Desktop\Neue Downloads\vlc-2.1.5-win64.exe"
sh=79A4C780524D954794F0B2F71700D91BFF42108A ft=1 fh=7a35a830d8dcb46e vn="Variante von Win32/WinloadSDA.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Sven\Desktop\Neue Downloads\Frank Buschmann - Am Ende Kackt die Ente\ABBYY-Lingvo-x3-lnstall.exe"
sh=E1FF212CE56455D90CF6401DED1DB34F65675843 ft=1 fh=843a4dbdfe31ff8e vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\X\Privat\Heiko\Homepage\NVU\KompoZer - CHIP-Downloader.exe"
sh=E1FF212CE56455D90CF6401DED1DB34F65675843 ft=1 fh=843a4dbdfe31ff8e vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\X\Privat\Homepage\NVU\KompoZer - CHIP-Downloader.exe"
sh=DCED01C2BFF0D66AC8D0225281779B29BB8420BE ft=1 fh=470feae295438596 vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="E:\X\Privat\Noten\SoftonicDownloader_fuer_gitarrenkurs-band-i.exe"
sh=15C574DF65F4253CF4A5D86B66A95D22B8D2EDFD ft=1 fh=ad1f51270cfc99f0 vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="E:\X\Privat\Noten\SoftonicDownloader_fuer_gitarrenkurs-band-ii.exe"
sh=052529D1B57123707DE6304CA2A2E8832E80A1F1 ft=1 fh=487ceb503c81f5f9 vn="Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung" ac=I fn="Y:\29.12.2013\C\Program Files (x86)\Conduit\Community Alerts\Alert.dll"
sh=410B32FD3FE4642644AD91AC60C69B86EC2762DD ft=1 fh=0e378a435beab91a vn="Variante von Win32/Adware.Yontoo.B Anwendung" ac=I fn="Y:\29.12.2013\C\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll"
sh=E1FF212CE56455D90CF6401DED1DB34F65675843 ft=1 fh=843a4dbdfe31ff8e vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="Y:\29.12.2013\X\Privat\Heiko\Homepage\NVU\KompoZer - CHIP-Downloader.exe"
sh=E1FF212CE56455D90CF6401DED1DB34F65675843 ft=1 fh=843a4dbdfe31ff8e vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="Y:\29.12.2013\X\Privat\Homepage\NVU\KompoZer - CHIP-Downloader.exe"
sh=DCED01C2BFF0D66AC8D0225281779B29BB8420BE ft=1 fh=470feae295438596 vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="Y:\29.12.2013\X\Privat\Noten\SoftonicDownloader_fuer_gitarrenkurs-band-i.exe"
sh=15C574DF65F4253CF4A5D86B66A95D22B8D2EDFD ft=1 fh=ad1f51270cfc99f0 vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="Y:\29.12.2013\X\Privat\Noten\SoftonicDownloader_fuer_gitarrenkurs-band-ii.exe"
 Results of screen317's Security Check version 0.99.87  
 Windows 7 Service Pack 1 x64 (UAC is disabled!)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Security Center service is not running! This report may not be accurate! 
Kaspersky Internet Security   
 Antivirus up to date!  (On Access scanning disabled!) 
`````````Anti-malware/Other Utilities Check:````````` 
 Adobe Flash Player  
 Adobe Reader XI  
 Mozilla Firefox (33.0) 
````````Process Check: objlist.exe by Laurent````````  
 Kaspersky Lab Kaspersky Internet Security 14.0.0 avpui.exe  
 Kaspersky Lab Kaspersky Internet Security 14.0.0 avp.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````

Alt 18.10.2014, 03:42   #13
Windows 7: Adware eingefangen - Standard

Windows 7: Adware eingefangen

FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-10-2014
Ran by Sven (administrator) on SVEN-PC on 18-10-2014 04:37:59
Running from C:\Users\Sven\Desktop
Loaded Profiles: Sven &  (Available profiles: Sven & Administrator)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [NPSStartup] => [X]
HKU\S-1-5-21-2267789081-3611541687-2111919439-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2267789081-3611541687-2111919439-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2267789081-3611541687-2111919439-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [AdobeBridge] => [X]

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2A8C04551BCDCC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
DPF: HKLM {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
Filter: AutorunsDisabled - No CLSID Value - No File
Filter-x32: AutorunsDisabled - No CLSID Value - No File
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default
FF SearchEngineOrder.2: www.ebay.de
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @phonostar.de/phonostar -> C:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll No File
FF SearchPlugin: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\searchplugins\youtube-videosuche.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: German Dictionary - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\de-DE@dictionaries.addons.mozilla.org [2014-07-30]
FF Extension: British English Dictionary (Updated) - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\en-gb@flyingtophat.co.uk [2013-10-23]
FF Extension: Russian spellchecking dictionary - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\ru@dictionaries.addons.mozilla.org [2014-09-21]
FF Extension: Garmin Communicator - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2014-07-07]
FF Extension: Flashblock - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2014-09-30]
FF Extension: EPUBReader - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F} [2014-09-21]
FF Extension: YouTube ALL HTML5 - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\jid1-qj0w91o64N7Eeg@jetpack.xpi [2014-10-17]
FF Extension: Quick Translator - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\{5C655500-E712-41e7-9349-CE462F844B19}.xpi [2014-01-19]
FF Extension: YouTube High Definition - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2014-09-29]
FF Extension: Easy Youtube Video Downloader Express - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2014-06-19]
FF Extension: Adblock Plus - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\jwywnhv7.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-01-07]
FF HKLM-x32\...\Firefox\Extensions:  - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: 卡巴斯基網址顧問 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-02-21]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: 虛擬鍵盤 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-02-21]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: 惡意網站攔截器 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-02-21]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Chặn quảng cáo - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-02-21]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-02-21]

CHR Profile: C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa []
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [koalekbhpbggkcfhkkbolikjoaobbppi] - C:\Program Files (x86)\PutLockerDownloader\PutLockerDownloader10.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
S4 cbVSCService11; C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe [67584 2012-05-25] (CobianSoft, Luis Cobian) [File not signed]
S4 FirebirdServerMAGIXInstance; C:\Program Files (x86)\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
S3 MpsSvc; . [0 2014-10-18] () [File not signed]
S4 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [27648 2008-01-19] (Microsoft Corporation)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-02-22] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-04-01] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-04-01] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-02-22] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-02-22] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-10-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-10-01] (Malwarebytes Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
U5 usbser; C:\Windows\System32\Drivers\usbser.sys [32768 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-18 04:37 - 2014-10-18 04:39 - 00014234 _____ () C:\Users\Sven\Desktop\FRST.txt
2014-10-18 04:34 - 2014-10-18 04:34 - 02112000 _____ (Farbar) C:\Users\Sven\Desktop\FRST64.exe
2014-10-18 04:32 - 2014-10-18 04:32 - 02112000 _____ (Farbar) C:\Users\Sven\Desktop\FRST64.exe.part
2014-10-18 04:27 - 2014-10-18 04:27 - 00000056 _____ () C:\Windows\setupact.log
2014-10-18 04:27 - 2014-10-18 04:27 - 00000000 _____ () C:\Windows\setuperr.log
2014-10-17 05:52 - 2014-10-17 06:07 - 00002345 _____ () C:\Windows\WindowsUpdate.log
2014-10-17 02:40 - 2014-10-17 02:40 - 02347384 _____ (ESET) C:\Users\Sven\Desktop\esetsmartinstaller_deu.exe
2014-10-17 01:18 - 2014-10-17 01:18 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\46ED0FE7.sys
2014-10-17 00:26 - 2014-10-17 00:26 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-10-17 00:08 - 2014-10-17 00:08 - 00000754 _____ () C:\Users\Sven\Desktop\JRT.txt
2014-10-17 00:03 - 2014-03-10 10:50 - 00000000 ____D () C:\Users\Sven\Desktop\Vikas Swarup - Rupien! Rupien! - Slumdog Millionär
2014-10-15 18:40 - 2014-10-15 18:40 - 00854417 _____ () C:\Users\Sven\Desktop\SecurityCheck.exe
2014-10-15 13:48 - 2014-10-15 13:48 - 00003602 _____ () C:\Windows\System32\Tasks\Kalender1-Free Erinnerung
2014-10-14 13:45 - 2014-10-14 13:43 - 01705698 _____ (Thisisu) C:\Users\Sven\Desktop\JRT_NEW.exe
2014-10-14 13:06 - 2014-10-18 04:28 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-14 13:05 - 2014-10-14 13:05 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-10-14 13:05 - 2014-10-14 13:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-10-14 13:05 - 2014-10-14 13:05 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-10-14 13:05 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-14 13:05 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-14 13:05 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-13 15:15 - 2014-10-13 15:15 - 00017082 _____ () C:\ComboFix.txt
2014-10-13 14:54 - 2014-10-13 15:16 - 00000000 ____D () C:\ComboFix
2014-10-13 14:32 - 2014-08-19 20:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-13 14:32 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-10-13 14:32 - 2014-08-19 01:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-13 14:32 - 2014-08-19 00:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-13 14:32 - 2014-08-19 00:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-13 14:32 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-10-13 14:32 - 2014-08-19 00:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-13 14:32 - 2014-08-19 00:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-13 14:32 - 2014-08-19 00:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-13 14:32 - 2014-08-19 00:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-13 14:32 - 2014-08-19 00:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-13 14:32 - 2014-08-19 00:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-13 14:32 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-10-13 14:32 - 2014-08-19 00:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-13 14:32 - 2014-08-19 00:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-13 14:32 - 2014-08-19 00:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-13 14:32 - 2014-08-19 00:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-13 14:32 - 2014-08-19 00:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-13 14:32 - 2014-08-19 00:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-13 14:32 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-10-13 14:32 - 2014-08-18 23:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-13 14:32 - 2014-08-18 23:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-13 14:32 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-10-13 14:32 - 2014-08-18 23:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-13 14:32 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-10-13 14:32 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-10-13 14:32 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-10-13 14:32 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-10-13 14:32 - 2014-08-18 23:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-13 14:32 - 2014-08-18 23:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-13 14:32 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-10-13 14:32 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-10-13 14:32 - 2014-08-18 23:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-13 14:32 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-10-13 14:32 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-10-13 14:32 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-10-13 14:32 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-10-13 14:32 - 2014-08-18 23:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-13 14:32 - 2014-08-18 23:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-13 14:32 - 2014-08-18 23:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-13 14:32 - 2014-08-18 23:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-13 14:32 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-13 14:32 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-10-13 14:32 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-10-13 14:32 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-10-13 14:32 - 2014-08-18 23:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-13 14:32 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-10-13 14:32 - 2014-08-18 23:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-13 14:32 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-10-13 14:32 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-10-13 14:32 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-10-13 14:32 - 2014-08-18 22:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-13 14:32 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-10-13 14:32 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-10-13 14:32 - 2014-08-18 22:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-13 14:32 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-10-13 14:17 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-10-13 14:17 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-10-13 14:17 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-10-13 14:17 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-10-13 14:16 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-10-13 14:16 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-10-13 14:16 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-10-13 14:16 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-10-13 13:26 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-10-13 13:26 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-10-13 13:26 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-10-13 13:26 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-10-13 13:26 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-10-13 13:26 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-10-13 13:26 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-10-13 13:26 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-10-13 13:26 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-10-13 13:26 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-10-13 13:26 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-10-13 13:26 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-10-13 13:26 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-13 13:26 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-10-13 13:26 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-13 13:26 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-10-13 13:26 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-10-13 13:26 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-10-13 13:26 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-10-13 13:26 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-10-13 13:26 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-13 13:26 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-10-13 13:26 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-10-13 13:26 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-10-13 13:26 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-10-13 13:26 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-10-13 13:26 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-10-13 13:26 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-10-13 13:26 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-10-13 13:26 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-10-13 13:26 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-10-13 13:26 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-10-13 13:26 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-10-13 13:26 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-10-13 13:26 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-10-13 13:26 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-10-13 13:26 - 2013-12-25 01:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-10-13 13:26 - 2013-12-25 00:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-10-13 13:26 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-10-13 13:26 - 2013-11-23 00:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-10-13 13:24 - 2014-07-07 04:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-10-13 13:24 - 2014-07-07 04:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-10-13 13:24 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-10-13 13:24 - 2014-07-07 03:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-10-13 13:24 - 2014-07-07 03:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-10-13 13:23 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-10-13 13:23 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-10-13 13:23 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-13 13:23 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-10-13 13:23 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-10-13 13:23 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-10-13 13:23 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-10-13 13:23 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-10-13 13:23 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-10-13 13:23 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-13 13:23 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-10-13 13:23 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-10-13 13:23 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-10-13 13:23 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-10-13 13:23 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-10-13 13:23 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-10-13 13:23 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-10-13 13:23 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-10-13 13:23 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-10-13 13:23 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-10-13 13:23 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-10-13 13:23 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-10-13 13:23 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-10-13 13:23 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-10-13 13:23 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-10-13 13:23 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-10-13 13:23 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-10-13 13:23 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-10-13 13:23 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-10-13 13:23 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-10-13 13:22 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-10-13 13:22 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-10-13 13:22 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-10-13 13:22 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-10-13 13:22 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-10-13 13:22 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-10-13 13:22 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-10-13 13:22 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-10-13 13:22 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-10-13 13:22 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-10-13 13:22 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-10-13 13:20 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-10-13 13:20 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-10-13 13:20 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-10-13 13:20 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-10-13 13:20 - 2013-11-27 03:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-10-13 13:20 - 2013-11-27 03:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-10-13 13:20 - 2013-11-27 03:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-10-13 13:20 - 2013-11-27 03:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-10-13 13:20 - 2013-11-27 03:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-10-13 13:20 - 2013-11-27 03:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-10-13 13:20 - 2013-11-27 03:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-10-13 13:20 - 2013-11-26 13:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-10-13 13:09 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-10-13 13:09 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-10-13 13:09 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-10-13 13:09 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-10-13 13:09 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-10-13 13:09 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-10-13 13:09 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-10-13 13:09 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-10-13 13:09 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-10-13 13:09 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-10-13 13:09 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-10-13 13:09 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-10-13 13:09 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-10-13 13:09 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-10-13 12:53 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-10-13 12:53 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-10-13 12:53 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-10-13 12:53 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-10-13 12:53 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-10-13 12:53 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-10-13 12:53 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-10-13 12:53 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-10-13 12:52 - 2014-10-14 13:23 - 00000000 ____D () C:\Windows\erdnt
2014-10-13 12:52 - 2014-10-13 15:15 - 00000000 ____D () C:\Qoobox
2014-10-12 10:25 - 2014-10-18 04:38 - 00000000 ____D () C:\FRST
2014-10-12 08:59 - 2014-10-12 08:59 - 00000000 _____ () C:\Users\Sven\defogger_reenable
2014-10-12 08:58 - 2014-10-12 08:58 - 00050477 _____ () C:\Users\Sven\Desktop\Defogger.exe
2014-10-12 08:58 - 2014-10-12 08:58 - 00050477 _____ () C:\Users\Sven\Desktop\Defogger.exe
2014-10-09 18:25 - 2014-10-09 18:25 - 00000000 ____D () C:\Windows\ERUNT
2014-10-09 15:56 - 2014-10-09 15:56 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-09 15:29 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-10-09 15:28 - 2014-10-16 23:59 - 00000000 ____D () C:\AdwCleaner
2014-10-09 03:52 - 2014-10-09 03:52 - 00002585 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kalender1-Free.lnk
2014-10-09 03:52 - 2014-10-09 03:52 - 00000000 ____D () C:\Program Files (x86)\Kalender1-Free
2014-10-09 02:14 - 2014-10-14 13:23 - 00000000 ____D () C:\ProgramData\HhJanHrEZI
2014-10-09 02:09 - 2014-10-09 02:09 - 00000000 ____D () C:\Program Files\LopeSoft
2014-10-01 07:49 - 2014-10-01 08:00 - 00000052 _____ () C:\Windows\BookPrintXP.ini
2014-10-01 02:16 - 2014-10-14 15:40 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\vlc
2014-10-01 02:00 - 2014-10-01 02:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-10-01 02:00 - 2014-10-01 02:00 - 00000000 ____D () C:\Program Files\VideoLAN
2014-10-01 00:35 - 2014-10-01 00:35 - 00001102 _____ () C:\Users\Sven\Desktop\Etiketten-Designer 2.1.lnk
2014-10-01 00:35 - 2014-10-01 00:35 - 00001102 _____ () C:\Users\Administrator\Desktop\Etiketten-Designer 2.1.lnk
2014-10-01 00:35 - 2014-10-01 00:35 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Etiketten-Designer 2.1
2014-10-01 00:35 - 2014-10-01 00:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Etiketten-Designer 2.1
2014-10-01 00:35 - 2014-10-01 00:35 - 00000000 ____D () C:\Program Files (x86)\Etiketten-Designer 2
2014-10-01 00:34 - 2014-10-01 00:34 - 00000000 ____D () C:\Users\Sven\Downloads\Etiketten-Designer
2014-10-01 00:17 - 2014-10-17 07:32 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\AIMP3
2014-10-01 00:17 - 2014-10-01 00:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3
2014-10-01 00:17 - 2014-10-01 00:17 - 00000000 ____D () C:\Program Files (x86)\AIMP3
2014-09-29 09:48 - 2014-09-29 09:59 - 00047264 _____ () C:\Users\Sven\Desktop\Russisch Deutsch.xlsx
2014-09-26 16:25 - 2014-09-26 16:26 - 00000000 ____D () C:\Users\Sven\.ruslanka
2014-09-26 16:24 - 2014-09-26 16:24 - 00001901 _____ () C:\Users\Public\Desktop\Ruslanka.lnk
2014-09-26 16:24 - 2014-09-26 16:24 - 00001901 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ruslanka.lnk
2014-09-26 16:24 - 2014-09-26 16:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ruslanka
2014-09-26 16:24 - 2014-09-26 16:24 - 00000000 ____D () C:\Program Files (x86)\Ruslanka
2014-09-26 15:23 - 2014-09-26 15:23 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Langenscheidt
2014-09-26 15:23 - 2014-09-26 15:23 - 00000000 ____D () C:\ProgramData\Langenscheidt
2014-09-26 15:22 - 2014-09-26 15:22 - 00000000 ____D () C:\Users\Sven\Desktop\vokabel_
2014-09-26 15:10 - 2014-09-26 15:22 - 00000000 ____D () C:\Users\Sven\Desktop\VTrain
2014-09-26 15:10 - 2014-09-26 15:21 - 00000976 _____ () C:\Users\Sven\Desktop\VTrain Free.lnk
2014-09-26 15:10 - 2014-09-26 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTrain
2014-09-26 15:10 - 2014-09-26 15:21 - 00000000 ____D () C:\Program Files (x86)\VTrain
2014-09-26 15:10 - 2014-09-26 15:10 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\VTrain
2014-09-26 14:57 - 2014-09-26 14:57 - 00000909 _____ () C:\Users\Public\Desktop\Vocup.lnk
2014-09-26 14:57 - 2014-09-26 14:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vocup
2014-09-26 14:16 - 2014-09-26 14:16 - 00000000 ____D () C:\Users\Sven\Desktop\Vokabelhefte
2014-09-26 14:15 - 2014-09-26 14:15 - 00000000 ____D () C:\MemoStep6_14
2014-09-21 13:40 - 2014-09-26 14:57 - 00000000 ____D () C:\Program Files (x86)\Vocup
2014-09-21 13:40 - 2014-09-21 13:40 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Vocup
2014-09-21 13:40 - 2014-09-21 13:40 - 00000000 ____D () C:\Users\Sven\AppData\Local\_0_
2014-09-21 13:31 - 2014-09-21 13:31 - 00000000 ____D () C:\Program Files\JohnnyAnimation
2014-09-21 13:27 - 2014-09-26 15:04 - 00000000 ____D () C:\Program Files (x86)\MemoStep6
2014-09-21 13:20 - 2014-10-01 00:35 - 00087704 _____ () C:\Windows\cadkasdeinst01.exe
2014-09-21 13:20 - 2014-09-26 14:57 - 00000000 ____D () C:\Program Files (x86)\Vokabeltrainer 1
2014-09-21 13:20 - 2014-09-21 13:37 - 00001069 _____ () C:\Users\Administrator\Desktop\Vokabeltrainer 1.0.lnk
2014-09-21 13:20 - 2014-09-21 13:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vokabeltrainer 1.0
2014-09-21 13:07 - 2014-09-21 13:07 - 00000000 ____D () C:\Users\Sven\Downloads\ImTranslator
2014-09-21 12:05 - 2014-09-26 14:17 - 00009216 _____ () C:\Users\Sven\Vocabulator(English-Russian).vcb
2014-09-21 11:44 - 2014-09-21 11:48 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\jvlt
2014-09-21 11:14 - 2014-09-26 14:18 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\voc2brain
2014-09-21 11:13 - 2014-09-21 11:13 - 00001033 _____ () C:\Users\Public\Desktop\Voc2brain.lnk
2014-09-21 11:13 - 2014-09-21 11:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Voc2Brain
2014-09-21 11:13 - 2014-09-21 11:13 - 00000000 ____D () C:\Program Files (x86)\Voc2brain
2014-09-21 11:01 - 2014-09-21 12:03 - 00009216 _____ () C:\Users\Sven\Vocabulator(German-English).vcb
2014-09-21 10:59 - 2014-09-26 14:58 - 00000000 ___HD () C:\Program Files (x86)\InstallJammer Registry
2014-09-21 02:52 - 2014-09-21 02:52 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\FireShot
2014-09-21 02:32 - 2014-09-21 02:32 - 00000355 _____ () C:\Users\Sven\Desktop\Computer.lnk
2014-09-20 23:52 - 2014-09-26 15:55 - 00000000 ____D () C:\Program Files (x86)\HotAlarmClock
2014-09-20 21:36 - 2014-10-12 16:02 - 00000000 ____D () C:\Users\Sven\Desktop\Word Dateien
2014-09-20 21:35 - 2014-10-16 16:50 - 00000000 ____D () C:\Users\Sven\Desktop\PDF
2014-09-20 17:22 - 2014-09-20 17:22 - 00002212 _____ () C:\Users\Public\Desktop\Google Earth.lnk
2014-09-20 17:22 - 2014-09-20 17:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2014-09-20 17:22 - 2014-09-20 17:22 - 00000000 ____D () C:\Program Files (x86)\Google
2014-09-18 21:42 - 2014-09-18 21:48 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\GeoSetter
2014-09-18 21:41 - 2014-09-18 21:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GeoSetter
2014-09-18 21:41 - 2014-09-18 21:41 - 00000000 ____D () C:\Program Files (x86)\GeoSetter

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-18 04:35 - 2009-07-14 06:45 - 00020224 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-18 04:35 - 2009-07-14 06:45 - 00020224 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-18 04:28 - 2010-04-12 01:40 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-10-18 04:27 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-17 20:51 - 2009-07-14 19:58 - 00705074 _____ () C:\Windows\system32\perfh007.dat
2014-10-17 20:51 - 2009-07-14 19:58 - 00151468 _____ () C:\Windows\system32\perfc007.dat
2014-10-17 20:51 - 2009-07-14 07:13 - 01635716 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-17 20:43 - 2014-01-18 14:17 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-17 07:17 - 2012-08-14 09:58 - 00000072 _____ () C:\Users\Public\LMDebug.log
2014-10-17 06:10 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-10-16 21:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2014-10-16 20:49 - 2014-05-15 16:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-10-16 20:31 - 2013-05-23 21:09 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-10-16 19:41 - 2014-07-11 20:56 - 00000000 ____D () C:\Users\Sven\AppData\Local\Adobe
2014-10-16 19:33 - 2014-01-18 14:17 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-10-16 19:33 - 2013-12-28 03:18 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-10-16 19:33 - 2013-12-28 03:18 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-10-13 15:15 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-10-13 15:06 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-10-13 14:52 - 2010-04-11 03:56 - 00000000 ____D () C:\Users\Sven
2014-10-13 14:50 - 2009-07-14 06:45 - 05021552 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-13 14:48 - 2009-07-14 20:18 - 00000000 ____D () C:\Program Files\Windows Journal
2014-10-13 14:48 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-10-13 14:28 - 2010-11-15 21:13 - 01609060 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-10-13 14:25 - 2014-01-01 18:03 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-12 17:54 - 2014-09-11 11:27 - 00000000 ____D () C:\Users\Sven\Desktop\Rennrad
2014-10-12 17:54 - 2014-09-11 11:27 - 00000000 ____D () C:\Users\Sven\Desktop\Rennrad
2014-10-12 17:18 - 2014-07-07 23:51 - 00000000 ____D () C:\Users\Sven\Desktop\E-mails
2014-10-12 17:18 - 2014-07-07 23:51 - 00000000 ____D () C:\Users\Sven\Desktop\E-mails
2014-10-10 01:11 - 2013-10-23 16:57 - 00000000 ____D () C:\Users\Sven\Desktop\MP3s
2014-10-10 01:11 - 2013-10-23 16:57 - 00000000 ____D () C:\Users\Sven\Desktop\MP3s
2014-10-09 16:44 - 2013-11-29 22:51 - 00000000 ____D () C:\Users\Sven\AppData\Local\Kalender1-Free
2014-10-09 03:37 - 2012-01-08 06:27 - 00000000 ____D () C:\Users\Sven\AppData\Local\Downloaded Installations
2014-10-01 09:03 - 2013-12-11 23:28 - 00000000 ____D () C:\Users\Sven\Desktop\Lesestoff
2014-10-01 09:03 - 2013-12-11 23:28 - 00000000 ____D () C:\Users\Sven\Desktop\Lesestoff
2014-10-01 08:00 - 2009-07-14 04:34 - 00000478 _____ () C:\Windows\win.ini
2014-10-01 07:54 - 2010-04-12 00:01 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Adobe
2014-10-01 07:34 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-10-01 01:51 - 2011-02-24 00:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2014-09-30 02:18 - 2012-11-04 03:22 - 00000000 ____D () C:\Program Files (x86)\JDownloader
2014-09-26 14:59 - 2012-02-09 18:09 - 00000000 ____D () C:\Windows\pss
2014-09-26 14:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-09-26 14:28 - 2014-09-09 15:19 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SanDisk
2014-09-26 11:48 - 2010-04-18 20:03 - 00000000 ____D () C:\Program Files (x86)\MP3Gain
2014-09-21 17:03 - 2014-07-10 08:47 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-09-21 17:03 - 2012-11-12 02:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-09-21 17:02 - 2014-07-10 08:45 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DVDVideoSoft
2014-09-20 23:58 - 2010-04-12 08:24 - 00130344 _____ () C:\Users\Sven\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-20 21:00 - 2012-01-15 01:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinHTTrack (Webseiten abspeichern)

Some content of TEMP:

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2014-10-17 05:56

==================== End Of Log ============================
--- --- ---

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-10-2014
Ran by Sven at 2014-10-18 04:39:42
Running from C:\Users\Sven\Desktop
Boot Mode: Normal

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Kaspersky Internet Security (Disabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Internet Security (Disabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Disabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

==================== End Of Log ============================

Alt 18.10.2014, 16:16   #15
Windows 7: Adware eingefangen - Standard

Windows 7: Adware eingefangen

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-10-2014
Ran by Sven at 2014-10-18 17:11:43 Run:1
Running from C:\Users\Sven\Desktop
Loaded Profile: Sven (Available profiles: Sven & Administrator)
Boot Mode: Normal

Content of fixlist:

C:\ProgramData\HhJanHrEZI => Moved successfully.

==== End of Fixlog ====
Farbar Service Scanner Version: 21-07-2014
Ran by Sven (administrator) on 18-10-2014 at 17:14:07
Running from "C:\Users\Sven\Desktop"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Normal

Internet Services:
Dnscache Service is not running. Checking service configuration:
The start type of Dnscache service is set to Demand. The default start type is Auto.
The ImagePath of Dnscache service is OK.
The ServiceDll of Dnscache service is OK.

Connection Status:
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.

Windows Firewall:
mpsdrv Service is not running. Checking service configuration:
The start type of mpsdrv service is OK.
The ImagePath of mpsdrv service is OK.

MpsSvc Service is not running. Checking service configuration:
The start type of MpsSvc service is set to Demand. The default start type is Auto.
The ImagePath of MpsSvc: ".".
Checking ServiceDll: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.

bfe Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.

Firewall Disabled Policy: 

System Restore:

System Restore Disabled Policy: 

Action Center:

wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is set to Disabled. The default start type is Auto.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.

Windows Update:
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is set to Disabled. The default start type is Auto.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv service is OK.

Windows Autoupdate Disabled Policy: 

Windows Defender:

Other Services:

File Check:
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed

**** End of log ****


