|
Plagegeister aller Art und deren Bekämpfung: Windows Vista SP2 64-bit - Virus / unerwünschtes Programm?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
03.11.2014, 23:05 | #1 |
| Windows Vista SP2 64-bit - Virus / unerwünschtes Programm? Hallo zusammen, ich bin ratlos und könnte Hilfe von einem Experten gebrauchen. könntet ihr euch mal die Log-Files anschauen, weil ich mir nicht sicher bin, ob der PC meines Vaters befallen ist. Anscheinend erschien vor 2 Tagen ein Popup auf, welches meinte, das eine neue Version von Java installiert werden sollte. Nach dem klicken auf OK, meldete Panda Free Antivirus einen Fund und stellte diesen in Quarantäne. (Habe ich dann gelöscht) Ich habe hier keine Log-File, also ausnahmsweise mal so: Ereignis: Trojaner erkannt Trj/Genetic.gen Speicherort: C:\Users\Home\Downloads\Setup.exe Malwarebytes und Panda haben anschließend keinen Fund mehr gehabt. Allerdings meldete der Eset Online Scanner 5 Funde. Alle habe ich gelöscht: Code:
ATTFilter C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2U9M35IT\ApnIC[1].0 Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UHXXFROW\ApnIC[1].0 Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung C:\Program Files (x86)\Panda Security\Panda Security Protection\Tools\PandaSecurityTb.exe Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\WINDOWS\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2U9M35IT\ApnIC[1].0 Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung gelöscht - in Quarantäne kopiert C:\WINDOWS\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UHXXFROW\ApnIC[1].0 Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung gelöscht - in Quarantäne kopiert Die folgenden Scans fürhte ich über Teamviewer per Fernsteuerung durch. Defogger Log-file: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 22:10 on 03/11/2014 (Home) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-11-2014 Ran by Home (administrator) on HOME-PC on 03-11-2014 22:12:27 Running from C:\Users\Home\Desktop Loaded Profile: Home (Available profiles: Home & Gast) Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 8 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ATI Technologies Inc.) C:\WINDOWS\System32\Ati2evxx.exe (Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe (ATI Technologies Inc.) C:\WINDOWS\System32\Ati2evxx.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\svchost.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Realtek Semiconductor) C:\WINDOWS\RAVCpl64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Desktop.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\conime.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RAVCpl64.exe [6150656 2008-03-26] (Realtek Semiconductor) HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [182808 2008-11-03] (Intel Corporation) HKLM-x32\...\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company) HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.) HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [37624 2014-07-24] (Panda Security, S.L.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {0061f5ed-6d18-11de-8b85-00221526174f} - K:\pcwstart.exe HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {6c5b72ba-ad02-11df-a44c-00221526174f} - wd_windows_tools\setup.exe HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {d68e194b-fafb-11df-bd8c-00221526174f} - J:\pushinst.exe HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {edfdbac5-a091-11de-8dc8-00221526174f} - starter.exe HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (Dropbox, Inc.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: http=127.0.0.1:14326;https=127.0.0.1:14326 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {1ABA2C13-E36C-4497-8234-1E146E69EAA4} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de SearchScopes: HKLM - {FB5DD038-132F-4EA1-8871-F5F9A3D5AC1E} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 SearchScopes: HKCU - {1ABA2C13-E36C-4497-8234-1E146E69EAA4} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=protegere SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} hxxp://www.celartem.com/en/download/data/djvu_autoinstall/DjVuControl_en_US.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2 FireFox: ======== FF ProfilePath: C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\0yk7tulu.default-1410973344085 FF Homepage: https://www.google.de FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll () FF Plugin: @java.com/DTPlugin,version=10.10.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll () FF Plugin-x32: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll No File FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll No File FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Bitdefender QuickScan - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\0yk7tulu.default-1410973344085\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2014-11-03] FF Extension: NoScript - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\0yk7tulu.default-1410973344085\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-09-17] FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-14] FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com) R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) [File not signed] R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129992 2008-02-03] (EasyBits Sofware AS) [File not signed] R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [438616 2014-08-07] (Garmin Ltd or its subsidiaries) S2 gupdate1ca23fa2f8d54a0; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107912 2014-10-21] (Google Inc.) R2 HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-03-14] (Hewlett-Packard) [File not signed] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed] R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-03-17] (Hewlett-Packard Company) [File not signed] S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [141560 2014-07-24] (Panda Security, S.L.) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-07-18] (Hewlett-Packard) [File not signed] R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [61688 2014-07-23] (Panda Security, S.L.) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-07-18] (Hewlett-Packard) [File not signed] R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [38136 2014-07-24] (Panda Security, S.L.) S3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [637952 2009-06-02] (Nokia.) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [714368 2010-10-22] (AVM GmbH) S3 GigasetGenericUSB_x64; C:\Windows\System32\DRIVERS\GigasetGenericUSB_x64.sys [54272 2009-02-20] (Siemens Home and Office Communication Devices GmbH & Co. KG) R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] () S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] () R1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [96800 2014-06-04] (Panda Security, S.L.) R1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [162336 2014-06-18] (Panda Security, S.L.) R1 NNSHTTPS; C:\Windows\System32\DRIVERS\NNSHttps.sys [112160 2014-06-04] (Panda Security, S.L.) R1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [115232 2014-06-04] (Panda Security, S.L.) R1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [46336 2014-01-16] (Panda Security, S.L.) R1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [95776 2014-06-04] (Panda Security, S.L.) R1 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [70176 2014-06-04] (Panda Security, S.L.) R1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [125984 2014-06-04] (Panda Security, S.L.) R1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [306720 2014-06-04] (Panda Security, S.L.) R1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [169504 2014-06-04] (Panda Security, S.L.) R1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [115744 2014-06-04] (Panda Security, S.L.) R1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [261152 2014-06-04] (Panda Security, S.L.) R1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [109088 2014-06-04] (Panda Security, S.L.) R3 Ps2; C:\Windows\System32\DRIVERS\PS2.sys [21504 2006-09-07] () R2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [160800 2014-07-24] (Panda Security, S.L.) R2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [120352 2014-07-24] (Panda Security, S.L.) R1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [195616 2014-07-24] (Panda Security, S.L.) R2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [122400 2014-07-24] (Panda Security, S.L.) R2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [132128 2014-07-24] (Panda Security, S.L.) R2 PSINReg; C:\Windows\System32\DRIVERS\PSINReg.sys [106016 2014-07-24] (Panda Security, S.L.) R3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [60400 2014-03-25] (Panda Security, S.L.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S0 Lbd; system32\DRIVERS\Lbd.sys [X] S3 nmwcdnsux64; system32\drivers\nmwcdnsux64.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 PCD5SRVC{E2AF211B-86DA020A-05040000}; \??\C:\PROGRA~2\PC-DOC~1\PCD5SRVC_x64.pkms [X] S3 upperdev; system32\DRIVERS\usbser_lowerfltx64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-03 22:12 - 2014-11-03 22:13 - 00018244 _____ () C:\Users\Home\Desktop\FRST.txt 2014-11-03 22:12 - 2014-11-03 22:12 - 00000000 ____D () C:\FRST 2014-11-03 22:10 - 2014-11-03 22:10 - 00000470 _____ () C:\Users\Home\Desktop\defogger_disable.log 2014-11-03 22:10 - 2014-11-03 22:10 - 00000000 _____ () C:\Users\Home\defogger_reenable 2014-11-03 22:06 - 2014-11-03 22:08 - 00000000 ____D () C:\Users\Home\Downloads\Analyse-Tools Viren 2014-11-03 22:05 - 2014-11-03 22:05 - 00380416 _____ () C:\Users\Home\Desktop\du4dgzz1.exe 2014-11-03 22:00 - 2014-11-03 22:00 - 02114560 _____ (Farbar) C:\Users\Home\Desktop\FRST64.exe 2014-11-03 21:59 - 2014-11-03 21:59 - 00050477 _____ () C:\Users\Home\Desktop\Defogger.exe 2014-11-03 21:44 - 2014-11-03 21:44 - 00001062 _____ () C:\Users\Home\Desktop\Eset_OnlineScanner.txt 2014-11-03 20:07 - 2014-11-03 20:07 - 02347384 _____ (ESET) C:\Users\Home\Downloads\esetsmartinstaller_deu.exe 2014-11-03 19:21 - 2014-11-03 19:21 - 00276912 _____ () C:\Windows\Minidump\Mini110314-01.dmp 2014-11-01 18:03 - 2014-11-01 18:03 - 00000000 ____D () C:\Users\Gast\AppData\Local\Macromedia 2014-11-01 18:01 - 2014-11-01 18:02 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Mozilla 2014-11-01 18:01 - 2014-11-01 18:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Mozilla 2014-11-01 17:13 - 2014-11-01 17:13 - 00090320 _____ () C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT 2014-11-01 17:13 - 2014-11-01 17:13 - 00000951 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000941 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000936 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000917 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000020 ___SH () C:\Users\Gast\ntuser.ini 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Vorlagen 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Startmenü 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Netzwerkumgebung 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Lokale Einstellungen 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Eigene Dateien 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Druckumgebung 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Musik 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Bilder 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Verlauf 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Anwendungsdaten 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Anwendungsdaten 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Panda Security 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\ATI 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Adobe 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Local\VirtualStore 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Local\ATI 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast 2014-11-01 17:13 - 2014-06-22 16:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Garmin 2014-11-01 17:13 - 2009-12-13 00:20 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Macromedia 2014-11-01 17:13 - 2008-06-17 21:54 - 00001076 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite Deluxe.lnk 2014-11-01 17:13 - 2008-01-21 04:20 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-11-01 17:13 - 2008-01-21 04:20 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-11-01 13:17 - 2014-11-01 13:21 - 00017456 _____ () C:\Users\Home\Desktop\VW Bank - Bearbeitungsentgelt Kredite.odt 2014-10-31 10:01 - 2014-10-31 10:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-10-20 11:08 - 2014-10-20 11:08 - 00638888 _____ (Oracle Corporation) C:\Users\Home\Downloads\jxpiinstall.exe 2014-10-17 12:58 - 2014-11-03 19:21 - 519873065 _____ () C:\Windows\MEMORY.DMP 2014-10-17 12:58 - 2014-11-03 19:21 - 00000000 ____D () C:\Windows\Minidump 2014-10-17 12:58 - 2014-10-17 12:58 - 00276912 _____ () C:\Windows\Minidump\Mini101714-01.dmp 2014-10-16 14:28 - 2014-09-17 07:57 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-10-16 14:28 - 2014-09-16 17:56 - 00066560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-10-16 14:27 - 2014-09-28 00:41 - 02782208 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-10-16 14:20 - 2014-06-15 23:18 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-10-16 14:20 - 2014-06-15 23:18 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2014-10-16 14:20 - 2014-06-13 19:22 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll 2014-10-16 14:20 - 2014-06-13 19:22 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll 2014-10-16 14:20 - 2014-06-13 18:36 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-10-16 14:20 - 2014-06-13 18:36 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-10-16 14:13 - 2014-09-05 00:38 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2014-10-15 16:40 - 2014-09-23 21:22 - 12473344 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 09329152 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 02359296 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 01538560 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-10-15 16:40 - 2014-09-23 21:22 - 01491968 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 01147904 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00742912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00459776 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00219136 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 11083264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 06004224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 02006016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 01469440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-10-15 16:40 - 2014-09-23 21:08 - 01214976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00916992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00630784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00387584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00105984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00055808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00055296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00043520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00019456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\corpol.dll 2014-10-15 16:40 - 2014-09-23 20:15 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-10-15 16:40 - 2014-09-23 20:02 - 00162816 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-10-15 16:40 - 2014-09-23 20:02 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-10-15 16:40 - 2014-09-23 20:01 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-10-15 16:40 - 2014-09-23 20:01 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-10-15 16:40 - 2014-09-23 19:38 - 00385024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-10-15 16:40 - 2014-09-23 19:31 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2014-10-15 16:40 - 2014-09-23 19:31 - 00133632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-10-15 16:40 - 2014-09-23 19:30 - 01638912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-10-15 16:40 - 2014-09-23 19:30 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-10-05 19:04 - 2014-10-05 19:04 - 00000000 _____ () C:\Windows\setuperr.log 2014-10-05 19:04 - 2014-10-05 19:04 - 00000000 _____ () C:\Windows\setupact.log ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-03 22:10 - 2009-07-05 20:55 - 00000000 ____D () C:\Users\Home 2014-11-03 21:56 - 2006-11-02 16:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-03 21:56 - 2006-11-02 16:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-03 21:52 - 2013-03-28 10:57 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-11-03 21:47 - 2009-08-23 15:10 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-11-03 20:30 - 2009-08-23 15:10 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-11-03 20:05 - 2009-12-02 16:53 - 00000000 ____D () C:\Users\Home\AppData\Roaming\QuickScan 2014-11-03 19:28 - 2008-06-18 07:22 - 00628742 _____ () C:\Windows\system32\perfh007.dat 2014-11-03 19:28 - 2008-06-18 07:22 - 00126486 _____ () C:\Windows\system32\perfc007.dat 2014-11-03 19:28 - 2006-11-02 13:46 - 01445546 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-03 19:24 - 2012-07-07 08:13 - 01295300 _____ () C:\Windows\WindowsUpdate.log 2014-11-03 19:21 - 2014-10-03 09:12 - 00013070 _____ () C:\Windows\PFRO.log 2014-11-03 19:21 - 2006-11-02 16:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-03 19:04 - 2009-07-05 21:14 - 00003956 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{6118DBC4-466A-4EC0-9522-19066FBBCC47} 2014-11-03 19:04 - 2009-07-05 21:14 - 00000416 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{6118DBC4-466A-4EC0-9522-19066FBBCC47}.job 2014-11-03 18:50 - 2006-11-02 16:42 - 00032530 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-11-02 19:59 - 2014-05-31 13:09 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-11-02 19:56 - 2014-05-31 13:08 - 00000903 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-11-02 19:56 - 2014-05-31 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-11-02 19:56 - 2014-05-31 13:08 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-11-02 15:00 - 2014-09-22 19:52 - 00000394 ____H () C:\Windows\Tasks\{82897433-0E25-4B1B-ABA7-05D73E386117}.job 2014-11-01 11:08 - 2013-03-10 10:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-10-28 06:34 - 2009-10-04 00:55 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-10-27 19:27 - 2013-01-06 15:44 - 00049259 _____ () C:\Users\Home\Desktop\Malteser_StundenZettel_2013.ods 2014-10-21 17:42 - 2009-08-23 15:10 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-10-21 17:42 - 2009-08-23 15:10 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-10-20 11:13 - 2014-10-03 11:07 - 00000000 ____D () C:\ProgramData\Oracle 2014-10-20 11:11 - 2014-10-03 11:06 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-10-20 11:11 - 2014-10-03 11:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-10-20 11:10 - 2014-10-03 11:06 - 00000000 ____D () C:\Program Files (x86)\Java 2014-10-20 11:03 - 2013-03-28 10:57 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-10-20 11:03 - 2012-04-30 23:31 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-10-20 11:03 - 2011-08-21 09:27 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-10-20 11:01 - 2014-07-08 13:05 - 00000000 ____D () C:\Users\Home\AppData\Local\Adobe 2014-10-19 07:59 - 2014-09-22 19:52 - 00003250 _____ () C:\Windows\System32\Tasks\{82897433-0E25-4B1B-ABA7-05D73E386117} 2014-10-16 14:47 - 2009-07-07 07:16 - 00000680 _____ () C:\Users\Home\AppData\Local\d3d9caps.dat 2014-10-16 14:45 - 2006-11-02 16:21 - 00375016 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-10-16 14:13 - 2013-09-02 11:31 - 00000000 ____D () C:\Windows\system32\MRT 2014-10-16 14:00 - 2006-11-02 13:35 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe Files to move or delete: ==================== C:\Windows\Tasks\{82897433-0E25-4B1B-ABA7-05D73E386117}.job C:\Windows\Tasks\{9885EFF2-BAE1-4847-87F4-87821C063D76}.job ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-03 19:27 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-11-2014 Ran by Home at 2014-11-03 22:13:29 Running from C:\Users\Home\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Panda Free Antivirus (Enabled - Up to date) {3456760B-FDAA-FFFD-06C2-7BB528D2066C} AS: Panda Free Antivirus (Enabled - Up to date) {8F3797EF-DB90-F073-3C72-40C753554CD1} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Panda Firewall (Disabled) {0C6DF72E-B7C5-FEA5-2D9D-D280D6014117} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (Version: 2.2.5 - Hewlett-Packard) Hidden Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.189 - Adobe Systems Incorporated) Adobe Reader X (10.1.12) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.12 - Adobe Systems Incorporated) ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden ATI Catalyst Install Manager (HKLM\...\{53EAA030-4FE6-0B32-DD63-1DB9C02AA917}) (Version: 3.0.664.0 - ATI Technologies, Inc.) AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version: - AVM Berlin) Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - ) Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.) Canon MG5300 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5300_series) (Version: - Canon Inc.) Canon MP Navigator EX 5.0 (HKLM-x32\...\MP Navigator EX 5.0) (Version: - ) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.) Catalyst Control Center - Branding (HKLM-x32\...\{2E4609A3-F5AF-4408-B0C4-B8B84BC753DF}) (Version: 1.00.0000 - ATI) ccc-core-static (x32 Version: 2008.0225.2153.39091 - Ihr Firmenname) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.17 - Piriform) Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) ConsumerUpdate (HKLM-x32\...\{77D339DC-2A1E-403F-B4BA-1E6C98394009}) (Version: 3.1.2.0 - Fuzhou Rockchip) CyberLink DVD Suite Deluxe (HKLM-x32\...\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 5.5.1329 - CyberLink Corp.) CyberLink PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 6.5.2726 - CyberLink Corp.) DivX Plus DirectShow Filters (HKLM-x32\...\DivX Plus DirectShow Filters) (Version: - DivX, Inc.) Dropbox (HKCU\...\Dropbox) (Version: 1.4.12 - Dropbox, Inc.) Elevated Installer (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden File Uploader (HKLM-x32\...\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}) (Version: 1.2.5 - Nikon) Garmin Express (HKLM-x32\...\{b43ffffb-1adc-4bcb-b277-7844ebff94da}) (Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Garmin Express (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express Tray (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden Gigaset QuickSync (HKLM\...\{a325d0b9-0b5e-4ad1-9c5f-e39aa43f8c9d}) (Version: 7.1.0841.3 - Gigaset Communications GmbH) Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden Hewlett-Packard Active Check for Health Check (x32 Version: 1.1.15.2 - Hewlett-Packard) Hidden Hewlett-Packard Asset Agent for Health Check (x32 Version: 2.0.63.2 - HP) Hidden HP Customer Experience Enhancements (HKLM-x32\...\{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}) (Version: 5.6.0.2510 - Hewlett-Packard) HP Easy Setup - Frontend (HKLM-x32\...\{E1476612-02D6-42A3-BDC1-E292B4115738}) (Version: 5.7.0.2611 - Hewlett-Packard) HP Total Care Advisor (HKLM-x32\...\{F31E534B-4199-4552-8154-5C130710D68E}) (Version: 2.4.6651.2902 - Ihr Firmenname) HP Update (HKLM-x32\...\{FE57DE70-95DE-4B64-9266-84DA811053DB}) (Version: 4.000.012.001 - Hewlett-Packard) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle) Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation) LabelPrint (HKLM-x32\...\{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.2.2529 - CyberLink Corp.) LightScribe System Software (HKLM-x32\...\{7F10292C-A190-4176-A665-A1ED3478DF86}) (Version: 1.18.3.2 - LightScribe) Lizardtech DjVu Control (autoinstall) (HKLM-x32\...\DjVu) (Version: - ) Logitech QuickCam-Treiberpaket (HKLM\...\lvdrivers_11.80) (Version: - ) Logitech Webcam Software (HKLM\...\{987FE247-4E69-4A2E-A961-D14F901FDBF6}) (Version: 12.10.1113 - Logitech Inc.) MAGIX Foto Designer 7 (HKLM-x32\...\MAGIX_{2DCD52EE-1AE1-4128-9819-A79F7D09B6B3}) (Version: 7.0.1.1 - MAGIX AG) MAGIX Foto Designer 7 (Version: 7.0.1.1 - MAGIX AG) Hidden Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Media Markt Fotoservice (HKLM-x32\...\Media Markt Fotoservice_is1) (Version: - ) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (German) (HKLM-x32\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{09298F26-A95C-31E2-9D95-2C60F586F075}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Works (HKLM-x32\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 33.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.0.2 (x86 de)) (Version: 33.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSVC80_x64 (Version: 1.0.1.0 - Nokia) Hidden MSVC80_x86 (x32 Version: 1.0.1.0 - Nokia) Hidden MSXML 4.0 SP2 (KB927978) (HKLM-x32\...\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nikon Message Center (HKLM-x32\...\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}) (Version: 0.92.000 - Nikon) Nikon Transfer (HKLM-x32\...\{E9757890-7EC5-46C8-99AB-B00F07B6525C}) (Version: 1.5.3 - Nikon) Nitro PDF Professional (HKLM\...\{853F9C53-2518-4AD0-ABA2-A72EDF4441A4}) (Version: 5.5.2.0 - Nitro PDF Software ) OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) Optimierte Multimedia-Tastatur-Lösung (HKLM-x32\...\KBD) (Version: - Hewlett-Packard) Panda Devices Agent (HKLM-x32\...\Panda Devices Agent) (Version: 1.03.03 - Panda Security) Panda Devices Agent (x32 Version: 1.05.00 - Panda Security) Hidden Panda Free Antivirus (HKLM-x32\...\Panda Universal Agent Endpoint) (Version: 15.00.01.0000 - Panda Security) Panda Free Antivirus (Version: 7.23.00.0000 - Panda Security) Hidden PC Connectivity Solution (HKLM-x32\...\{0C973594-7DDF-4BD0-84ED-3517F7622037}) (Version: 9.23.3.0 - Nokia) Picture Control Utility (HKLM-x32\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.1.9 - Nikon) Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.3917 - CyberLink Corp.) Python 2.5 (HKLM-x32\...\{0A2C5854-557E-48C8-835A-3B9F074BDCAA}) (Version: 2.5.150 - Martin v. Löwis) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5591 - Realtek Semiconductor Corp.) Sicherheitsupdate für Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2478663) (HKLM-x32\...\{0E3DAF3D-FF69-345A-A99E-1FED304CA083}.KB2478663) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870) (HKLM-x32\...\{0E3DAF3D-FF69-345A-A99E-1FED304CA083}.KB2518870) (Version: 1 - Microsoft Corporation) Skins (x32 Version: 2008.0225.2153.39091 - ATI) Hidden Skype™ 6.18 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.7.1018 - SUPERAntiSpyware.com) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.32494 - TeamViewer) Testversion von Microsoft Office Home and Student 2007 (HKLM\...\OfficeTrial) (Version: - ) Update 4.0.3 for Microsoft .NET Framework 4 Client Profile (KB2600211) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2600211) (Version: 1 - Microsoft Corporation) ViewNX (HKLM-x32\...\{F007CBCE-D714-4C0B-8CE9-9B0D78116468}) (Version: 1.5.2 - Nikon) Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM-x32\...\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation) VLC media player 1.0.0 (HKLM-x32\...\VLC media player) (Version: 1.0.0 - VideoLAN Team) Windows-Treiberpaket - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.) Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) WinRAR (HKLM-x32\...\WinRAR archiver) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-2310858669-3201491733-1471162819-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Home\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2310858669-3201491733-1471162819-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2310858669-3201491733-1471162819-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2310858669-3201491733-1471162819-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2310858669-3201491733-1471162819-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ==================== Restore Points ========================= ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 13:34 - 2006-09-18 22:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0415C28D-7897-496D-BCFB-2F44E8C7EDDC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-20] (Adobe Systems Incorporated) Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {1E7D71B9-A8F9-4058-95A8-EB9C05518344} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\SDP\RemEngine.exe [2008-03-17] () Task: {2369EDF4-4255-458B-8463-1FC5CC979B81} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.) Task: {275E459F-973C-4719-A41F-A7455526F88A} - System32\Tasks\{4CDB68A9-376B-46EA-906F-29B15EBEFA36} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-07-24] (Skype Technologies S.A.) Task: {2C7D6D84-2897-4EB7-87D3-6A771EB0D511} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.) Task: {39BF4947-BD2C-4B2D-A885-75CBC391681C} - \Media_Play_AIR+-updater No Task File <==== ATTENTION Task: {43A778FB-9D87-4DF5-9143-189B56D22B1D} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation) Task: {45A1EAEE-7175-4519-B9AD-FE21E706FFEA} - \Media_Play_AIR+-codedownloader No Task File <==== ATTENTION Task: {550B715B-5680-4FE8-824A-468346CAF60A} - System32\Tasks\{5AC164FF-0685-4173-B523-0273C63B3B91} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=4.1.0.136.259&LastError=206 Task: {569D2214-C6EF-4BCC-8D0B-E64669353577} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe [2014-08-07] () Task: {58E6C8FA-AFB3-43D5-BC93-FCE84E6B1C44} - System32\Tasks\{DB965085-31C7-41CC-B126-9D83CE554DA1} => Firefox.exe hxxp://ui.skype.com/ui/0/6.11.0.102/de/eula Task: {7C638E5B-ECE5-4424-A7E5-2C913CA682E9} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {84E21F9F-6251-49CC-80A6-D6A995C6D17C} - \Media_Play_AIR+-firefoxinstaller No Task File <==== ATTENTION Task: {875187FE-AC14-477B-84C3-2941554C504D} - System32\Tasks\RecoveryCD => C:\Program Files (x86)\Hewlett-Packard\SDP\RemEngine.exe [2008-03-17] () Task: {95628B80-3AD3-4F4E-AA3E-CF81B41C1311} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION Task: {A9FE2A9A-F4CE-4399-AD0F-AA22F66C17E0} - \Media_Play_AIR+-chromeinstaller No Task File <==== ATTENTION Task: {AF1B7FB2-1D27-4B42-9DF4-C27211185FB4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd) Task: {B1F614E1-2F46-48E1-AB7C-954AFA1C2CDE} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-12-27] (Lavasoft Limited ) Task: {C4D11BD0-5FBC-49EF-A1DE-E5E67288AEDF} - System32\Tasks\{9885EFF2-BAE1-4847-87F4-87821C063D76} => C:\Program Files (x86)\Panda Security\Panda Security Protection\JobLauncher.exe [2014-07-15] (Panda Security, S.L.) Task: {CCC1F0C9-0B3E-4AA5-86FF-2FB3760D30B2} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION Task: {D5301171-DC31-4ED5-8A18-0481EDBC8DE5} - System32\Tasks\{82897433-0E25-4B1B-ABA7-05D73E386117} => C:\Program Files (x86)\Panda Security\Panda Security Protection\JobLauncher.exe [2014-07-15] (Panda Security, S.L.) Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {F2142D1C-398A-4877-8C83-DDA21084244E} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Home => C:\Program Files\Windows Calendar\WinCal.exe [2008-01-21] (Microsoft Corporation) Task: {F822BF49-3BB1-44D3-9319-61E8B30FC7D5} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => c:\program files\windows defender\MpCmdRun.exe [2008-01-21] (Microsoft Corporation) Task: {FC2C1D5D-1799-41C7-A6BB-6D5FBA87625D} - System32\Tasks\{F875BEB7-1449-4220-9405-7CC9A65BDF20} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=4.1.0.136.259&LastError=206 Task: {FD19804B-0BCB-482E-846C-58DDFA282C5F} - \Media_Play_AIR+-enabler No Task File <==== ATTENTION Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\User_Feed_Synchronization-{6118DBC4-466A-4EC0-9522-19066FBBCC47}.job => C:\Windows\system32\msfeedssync.exe Task: C:\Windows\Tasks\{82897433-0E25-4B1B-ABA7-05D73E386117}.job => C:\Program Files (x86)\Panda Security\Panda Security Protection\JobLauncher.exe Task: C:\Windows\Tasks\{9885EFF2-BAE1-4847-87F4-87821C063D76}.job => C:\Program Files (x86)\Panda Security\Panda Security Protection\JobLauncher.exe ==================== Loaded Modules (whitelisted) ============= 2008-01-08 07:09 - 2008-01-08 07:09 - 00846336 _____ () c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll 2009-07-10 12:15 - 2008-06-19 23:41 - 00062464 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll 2008-06-17 21:38 - 2008-02-25 23:10 - 00116736 _____ () C:\Windows\system32\atitmm64.dll 2013-04-12 18:23 - 2013-04-12 18:23 - 00612664 _____ () C:\Program Files (x86)\Panda Security\Panda Security Protection\SQLite3.dll 2014-10-31 10:01 - 2014-10-31 10:01 - 03649648 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:9D718DA3 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NanoServiceMain => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSUAService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NanoServiceMain => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PSUAService => ""="Service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^Home^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupfolder: C:^Users^Home^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Produktregistrierung.lnk => C:\Windows\pss\Logitech . Produktregistrierung.lnk.Startup MSCONFIG\startupfolder: C:^Users^Home^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk => C:\Windows\pss\OpenOffice.org 3.1.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: LogitechQuickCamRibbon => "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide MSCONFIG\startupreg: Nikon Transfer Monitor => C:\Program Files (x86)\Common Files\Nikon\Monitor\NkMonitor.exe MSCONFIG\startupreg: Nitro PDF Printer Monitor => "C:\Program Files (x86)\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe" MSCONFIG\startupreg: SAFEOEM HotKeys => "C:\Program Files (x86)\Steganos Safe OEM\SteganosHotKeyService.exe" MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" ========================= Accounts: ========================== Administrator (S-1-5-21-2310858669-3201491733-1471162819-500 - Administrator - Disabled) Gast (S-1-5-21-2310858669-3201491733-1471162819-501 - Limited - Enabled) => C:\Users\Gast Home (S-1-5-21-2310858669-3201491733-1471162819-1000 - Administrator - Enabled) => C:\Users\Home ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/03/2014 10:06:22 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen bereits aktiven Komponentenversion. Die widersprüchlichen Komponenten sind: Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest. Error: (11/03/2014 08:07:49 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen bereits aktiven Komponentenversion. Die widersprüchlichen Komponenten sind: Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest. Error: (11/03/2014 08:07:39 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen bereits aktiven Komponentenversion. Die widersprüchlichen Komponenten sind: Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest. Error: (11/03/2014 07:22:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/03/2014 06:52:02 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/03/2014 06:50:33 PM) (Source: EventSystem) (EventID: 4621) (User: ) Description: 80070005EventSystem.EventSubscription{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000} Error: (11/03/2014 09:06:36 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/02/2014 10:10:58 PM) (Source: EventSystem) (EventID: 4621) (User: ) Description: 80070005EventSystem.EventSubscription{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000} Error: (11/02/2014 07:25:43 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/02/2014 02:50:42 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (11/03/2014 07:22:03 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Lbd Error: (11/03/2014 07:22:03 PM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: ScRegSetValueExWFailureActions%%5 Error: (11/03/2014 07:21:39 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 03.11.2014 um 19:19:34 unerwartet heruntergefahren. Error: (11/03/2014 06:52:05 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Lbd Error: (11/03/2014 06:52:05 PM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: ScRegSetValueExWFailureActions%%5 Error: (11/03/2014 01:48:30 PM) (Source: Dhcpv6) (EventID: 1000) (User: ) Description: Die Lease dieses Computers zu der IP-Adresse *ÇpAàP über die Netzwerkkarte mit der Netzwerkadresse BC054301FD35 ist verloren gegangen. Error: (11/03/2014 09:06:37 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Lbd Error: (11/03/2014 09:06:37 AM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: ScRegSetValueExWFailureActions%%5 Error: (11/02/2014 07:25:43 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Lbd Error: (11/02/2014 07:25:43 PM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: ScRegSetValueExWFailureActions%%5 Microsoft Office Sessions: ========================= Error: (11/03/2014 10:06:22 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifestC:\Users\Home\Downloads\esetsmartinstaller_deu.exe Error: (11/03/2014 08:07:49 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifestC:\Users\Home\Downloads\esetsmartinstaller_deu.exe Error: (11/03/2014 08:07:39 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifestC:\Users\Home\Downloads\esetsmartinstaller_deu.exe Error: (11/03/2014 07:22:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/03/2014 06:52:02 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/03/2014 06:50:33 PM) (Source: EventSystem) (EventID: 4621) (User: ) Description: 80070005EventSystem.EventSubscription{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000} Error: (11/03/2014 09:06:36 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/02/2014 10:10:58 PM) (Source: EventSystem) (EventID: 4621) (User: ) Description: 80070005EventSystem.EventSubscription{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000} Error: (11/02/2014 07:25:43 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/02/2014 02:50:42 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2014-11-03 22:12:59.741 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\WINDOWS\System32\drivers\PSINReg.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-03 22:12:59.576 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\WINDOWS\System32\drivers\PSINReg.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-03 22:12:59.413 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\WINDOWS\System32\drivers\PSINReg.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-03 22:12:59.238 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\WINDOWS\System32\drivers\PSINReg.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-03 22:12:59.030 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\WINDOWS\System32\drivers\PSINProt.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-03 22:12:58.869 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\WINDOWS\System32\drivers\PSINProt.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-03 22:12:58.706 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\WINDOWS\System32\drivers\PSINProt.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-03 22:12:58.545 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\WINDOWS\System32\drivers\PSINProt.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-03 22:12:58.346 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\WINDOWS\System32\drivers\PSINProc.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-03 22:12:58.179 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\WINDOWS\System32\drivers\PSINProc.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz Percentage of memory in use: 51% Total physical RAM: 4094.39 MB Available physical RAM: 1993.95 MB Total Pagefile: 8383.92 MB Available Pagefile: 6059.64 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (HP) (Fixed) (Total:584.5 GB) (Free:495.35 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (FACTORY_IMAGE) (Fixed) (Total:11.67 GB) (Free:1.56 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 596.2 GB) (Disk ID: 1549F232) Partition 1: (Active) - (Size=584.5 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=11.7 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Vielen Dank schon mal vorab für eure Hilfe, Moni |
04.11.2014, 06:41 | #2 |
/// the machine /// TB-Ausbilder | Windows Vista SP2 64-bit - Virus / unerwünschtes Programm? hi,
__________________Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
04.11.2014, 20:53 | #3 |
| Windows Vista SP2 64-bit - Virus / unerwünschtes Programm? Hallo,
__________________vielen Dank für die schnelle Antwort! Hier die Logs: Malwarebytes: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 04.11.2014 Suchlauf-Zeit: 19:48:16 Logdatei: mbam.txt Administrator: Ja Version: 2.00.3.1025 Malware Datenbank: v2014.11.04.06 Rootkit Datenbank: v2014.11.01.02 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows Vista Service Pack 2 CPU: x64 Dateisystem: NTFS Benutzer: Home Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 361803 Verstrichene Zeit: 12 Min, 31 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente erkannt) Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 0 (Keine schädliche Elemente erkannt) Registrierungswerte: 0 (Keine schädliche Elemente erkannt) Registrierungsdaten: 0 (Keine schädliche Elemente erkannt) Ordner: 0 (Keine schädliche Elemente erkannt) Dateien: 0 (Keine schädliche Elemente erkannt) Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) Code:
ATTFilter # AdwCleaner v4.002 - Bericht erstellt am 04/11/2014 um 20:18:45 # DB v2014-11-02.1 # Aktualisiert 27/10/2014 von Xplode # Betriebssystem : Windows (TM) Vista Home Premium Service Pack 2 (64 bits) # Benutzername : Home - HOME-PC # Gestartet von : C:\Users\Home\Desktop\AdwCleaner_4.002.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** [!] Ordner Gelöscht : C:\ProgramData\PC Drivers HeadQuarters [!] Ordner Gelöscht : C:\Program Files (x86)\PC Drivers HeadQuarters ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe ***** [ Browser ] ***** -\\ Internet Explorer v8.0.6001.19569 -\\ Mozilla Firefox v33.0.2 (x86 de) ************************* AdwCleaner[R0].txt - [3824 octets] - [17/09/2014 18:08:38] AdwCleaner[R1].txt - [1242 octets] - [04/11/2014 20:15:51] AdwCleaner[S0].txt - [3350 octets] - [17/09/2014 18:28:45] AdwCleaner[S1].txt - [1063 octets] - [04/11/2014 20:18:45] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1123 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.3.5 (10.31.2014:1) OS: Windows (TM) Vista Home Premium x64 Ran by Home on 04.11.2014 at 20:30:12,47 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update raving reyven Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\util raving reyven ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 04.11.2014 at 20:34:44,46 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Grüße, Moni Hallo, hier ist das frische FRST log: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-11-2014 Ran by Home (administrator) on HOME-PC on 04-11-2014 20:48:24 Running from C:\Users\Home\Desktop Loaded Profile: Home (Available profiles: Home & Gast) Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 8 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ATI Technologies Inc.) C:\WINDOWS\System32\Ati2evxx.exe (Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe (ATI Technologies Inc.) C:\WINDOWS\System32\Ati2evxx.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\svchost.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Realtek Semiconductor) C:\WINDOWS\RAVCpl64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe (Microsoft Corporation) C:\WINDOWS\System32\mobsync.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Desktop.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\conime.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RAVCpl64.exe [6150656 2008-03-26] (Realtek Semiconductor) HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [182808 2008-11-03] (Intel Corporation) HKLM-x32\...\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company) HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.) HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [37624 2014-07-24] (Panda Security, S.L.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {0061f5ed-6d18-11de-8b85-00221526174f} - K:\pcwstart.exe HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {6c5b72ba-ad02-11df-a44c-00221526174f} - wd_windows_tools\setup.exe HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {d68e194b-fafb-11df-bd8c-00221526174f} - J:\pushinst.exe HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {edfdbac5-a091-11de-8dc8-00221526174f} - starter.exe HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (Dropbox, Inc.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: http=127.0.0.1:14326;https=127.0.0.1:14326 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {1ABA2C13-E36C-4497-8234-1E146E69EAA4} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de SearchScopes: HKLM - {FB5DD038-132F-4EA1-8871-F5F9A3D5AC1E} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 SearchScopes: HKCU - {1ABA2C13-E36C-4497-8234-1E146E69EAA4} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=protegere SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} hxxp://www.celartem.com/en/download/data/djvu_autoinstall/DjVuControl_en_US.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2 FireFox: ======== FF ProfilePath: C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\0yk7tulu.default-1410973344085 FF Homepage: https://www.google.de FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll () FF Plugin: @java.com/DTPlugin,version=10.10.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll () FF Plugin-x32: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll No File FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll No File FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Bitdefender QuickScan - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\0yk7tulu.default-1410973344085\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2014-11-03] FF Extension: NoScript - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\0yk7tulu.default-1410973344085\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-09-17] FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-14] FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com) R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) [File not signed] R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129992 2008-02-03] (EasyBits Sofware AS) [File not signed] R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [438616 2014-08-07] (Garmin Ltd or its subsidiaries) S2 gupdate1ca23fa2f8d54a0; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107912 2014-10-21] (Google Inc.) R2 HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-03-14] (Hewlett-Packard) [File not signed] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed] R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-03-17] (Hewlett-Packard Company) [File not signed] S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [141560 2014-07-24] (Panda Security, S.L.) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-07-18] (Hewlett-Packard) [File not signed] R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [61688 2014-07-23] (Panda Security, S.L.) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-07-18] (Hewlett-Packard) [File not signed] R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [38136 2014-07-24] (Panda Security, S.L.) S3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [637952 2009-06-02] (Nokia.) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [714368 2010-10-22] (AVM GmbH) S3 GigasetGenericUSB_x64; C:\Windows\System32\DRIVERS\GigasetGenericUSB_x64.sys [54272 2009-02-20] (Siemens Home and Office Communication Devices GmbH & Co. KG) R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] () S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] () R1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [96800 2014-06-04] (Panda Security, S.L.) R1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [162336 2014-06-18] (Panda Security, S.L.) R1 NNSHTTPS; C:\Windows\System32\DRIVERS\NNSHttps.sys [112160 2014-06-04] (Panda Security, S.L.) R1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [115232 2014-06-04] (Panda Security, S.L.) R1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [46336 2014-01-16] (Panda Security, S.L.) R1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [95776 2014-06-04] (Panda Security, S.L.) R1 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [70176 2014-06-04] (Panda Security, S.L.) R1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [125984 2014-06-04] (Panda Security, S.L.) R1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [306720 2014-06-04] (Panda Security, S.L.) R1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [169504 2014-06-04] (Panda Security, S.L.) R1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [115744 2014-06-04] (Panda Security, S.L.) R1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [261152 2014-06-04] (Panda Security, S.L.) R1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [109088 2014-06-04] (Panda Security, S.L.) R3 Ps2; C:\Windows\System32\DRIVERS\PS2.sys [21504 2006-09-07] () R2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [160800 2014-07-24] (Panda Security, S.L.) R2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [120352 2014-07-24] (Panda Security, S.L.) R1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [195616 2014-07-24] (Panda Security, S.L.) R2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [122400 2014-07-24] (Panda Security, S.L.) R2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [132128 2014-07-24] (Panda Security, S.L.) R2 PSINReg; C:\Windows\System32\DRIVERS\PSINReg.sys [106016 2014-07-24] (Panda Security, S.L.) R3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [60400 2014-03-25] (Panda Security, S.L.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S0 Lbd; system32\DRIVERS\Lbd.sys [X] S3 nmwcdnsux64; system32\drivers\nmwcdnsux64.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 PCD5SRVC{E2AF211B-86DA020A-05040000}; \??\C:\PROGRA~2\PC-DOC~1\PCD5SRVC_x64.pkms [X] S3 upperdev; system32\DRIVERS\usbser_lowerfltx64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-04 20:34 - 2014-11-04 20:34 - 00000899 _____ () C:\Users\Home\Desktop\JRT.txt 2014-11-04 20:25 - 2014-11-04 20:25 - 01706359 _____ (Thisisu) C:\Users\Home\Desktop\JRT.exe 2014-11-04 20:07 - 2014-11-04 20:07 - 01998336 _____ () C:\Users\Home\Desktop\AdwCleaner_4.002.exe 2014-11-04 20:05 - 2014-11-04 20:05 - 00001204 _____ () C:\Users\Home\Desktop\mbam.txt 2014-11-03 22:13 - 2014-11-03 22:13 - 00036129 _____ () C:\Users\Home\Desktop\Addition.txt 2014-11-03 22:12 - 2014-11-04 20:48 - 00018227 _____ () C:\Users\Home\Desktop\FRST.txt 2014-11-03 22:12 - 2014-11-04 20:48 - 00000000 ____D () C:\FRST 2014-11-03 22:10 - 2014-11-03 22:10 - 00000470 _____ () C:\Users\Home\Desktop\defogger_disable.log 2014-11-03 22:10 - 2014-11-03 22:10 - 00000000 _____ () C:\Users\Home\defogger_reenable 2014-11-03 22:06 - 2014-11-03 22:08 - 00000000 ____D () C:\Users\Home\Downloads\Analyse-Tools Viren 2014-11-03 22:05 - 2014-11-03 22:05 - 00380416 _____ () C:\Users\Home\Desktop\du4dgzz1.exe 2014-11-03 22:00 - 2014-11-03 22:00 - 02114560 _____ (Farbar) C:\Users\Home\Desktop\FRST64.exe 2014-11-03 21:59 - 2014-11-03 21:59 - 00050477 _____ () C:\Users\Home\Desktop\Defogger.exe 2014-11-03 21:44 - 2014-11-03 21:44 - 00001062 _____ () C:\Users\Home\Desktop\Eset_OnlineScanner.txt 2014-11-03 20:07 - 2014-11-03 20:07 - 02347384 _____ (ESET) C:\Users\Home\Downloads\esetsmartinstaller_deu.exe 2014-11-03 19:21 - 2014-11-03 19:21 - 00276912 _____ () C:\Windows\Minidump\Mini110314-01.dmp 2014-11-01 18:03 - 2014-11-01 18:03 - 00000000 ____D () C:\Users\Gast\AppData\Local\Macromedia 2014-11-01 18:01 - 2014-11-01 18:02 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Mozilla 2014-11-01 18:01 - 2014-11-01 18:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Mozilla 2014-11-01 17:13 - 2014-11-01 17:13 - 00090320 _____ () C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT 2014-11-01 17:13 - 2014-11-01 17:13 - 00000951 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000941 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000936 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000917 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000020 ___SH () C:\Users\Gast\ntuser.ini 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Vorlagen 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Startmenü 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Netzwerkumgebung 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Lokale Einstellungen 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Eigene Dateien 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Druckumgebung 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Musik 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Bilder 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Verlauf 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Anwendungsdaten 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Anwendungsdaten 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Panda Security 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\ATI 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Adobe 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Local\VirtualStore 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Local\ATI 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast 2014-11-01 17:13 - 2014-06-22 16:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Garmin 2014-11-01 17:13 - 2009-12-13 00:20 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Macromedia 2014-11-01 17:13 - 2008-06-17 21:54 - 00001076 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite Deluxe.lnk 2014-11-01 17:13 - 2008-01-21 04:20 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-11-01 17:13 - 2008-01-21 04:20 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-11-01 13:17 - 2014-11-01 13:21 - 00017456 _____ () C:\Users\Home\Desktop\VW Bank - Bearbeitungsentgelt Kredite.odt 2014-10-31 10:01 - 2014-10-31 10:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-10-20 11:08 - 2014-10-20 11:08 - 00638888 _____ (Oracle Corporation) C:\Users\Home\Downloads\jxpiinstall.exe 2014-10-17 12:58 - 2014-11-03 19:21 - 519873065 _____ () C:\Windows\MEMORY.DMP 2014-10-17 12:58 - 2014-11-03 19:21 - 00000000 ____D () C:\Windows\Minidump 2014-10-17 12:58 - 2014-10-17 12:58 - 00276912 _____ () C:\Windows\Minidump\Mini101714-01.dmp 2014-10-16 14:28 - 2014-09-17 07:57 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-10-16 14:28 - 2014-09-16 17:56 - 00066560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-10-16 14:27 - 2014-09-28 00:41 - 02782208 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-10-16 14:20 - 2014-06-15 23:18 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-10-16 14:20 - 2014-06-15 23:18 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2014-10-16 14:20 - 2014-06-13 19:22 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll 2014-10-16 14:20 - 2014-06-13 19:22 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll 2014-10-16 14:20 - 2014-06-13 18:36 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-10-16 14:20 - 2014-06-13 18:36 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-10-16 14:13 - 2014-09-05 00:38 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2014-10-15 16:40 - 2014-09-23 21:22 - 12473344 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 09329152 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 02359296 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 01538560 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-10-15 16:40 - 2014-09-23 21:22 - 01491968 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 01147904 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00742912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00459776 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00219136 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 11083264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 06004224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 02006016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 01469440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-10-15 16:40 - 2014-09-23 21:08 - 01214976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00916992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00630784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00387584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00105984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00055808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00055296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00043520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00019456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\corpol.dll 2014-10-15 16:40 - 2014-09-23 20:15 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-10-15 16:40 - 2014-09-23 20:02 - 00162816 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-10-15 16:40 - 2014-09-23 20:02 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-10-15 16:40 - 2014-09-23 20:01 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-10-15 16:40 - 2014-09-23 20:01 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-10-15 16:40 - 2014-09-23 19:38 - 00385024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-10-15 16:40 - 2014-09-23 19:31 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2014-10-15 16:40 - 2014-09-23 19:31 - 00133632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-10-15 16:40 - 2014-09-23 19:30 - 01638912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-10-15 16:40 - 2014-09-23 19:30 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-10-05 19:04 - 2014-10-05 19:04 - 00000000 _____ () C:\Windows\setuperr.log 2014-10-05 19:04 - 2014-10-05 19:04 - 00000000 _____ () C:\Windows\setupact.log ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-04 20:47 - 2009-08-23 15:10 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-11-04 20:27 - 2008-06-18 07:22 - 00628742 _____ () C:\Windows\system32\perfh007.dat 2014-11-04 20:27 - 2008-06-18 07:22 - 00126486 _____ () C:\Windows\system32\perfc007.dat 2014-11-04 20:27 - 2006-11-02 13:46 - 01445546 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-04 20:25 - 2012-07-07 08:13 - 01343731 _____ () C:\Windows\WindowsUpdate.log 2014-11-04 20:21 - 2014-10-03 09:12 - 00013874 _____ () C:\Windows\PFRO.log 2014-11-04 20:21 - 2009-08-23 15:10 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-11-04 20:21 - 2006-11-02 16:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-04 20:21 - 2006-11-02 16:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-04 20:21 - 2006-11-02 16:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-04 20:20 - 2006-11-02 16:42 - 00032530 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-11-04 20:18 - 2014-09-17 18:08 - 00000000 ____D () C:\AdwCleaner 2014-11-04 19:52 - 2013-03-28 10:57 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-11-04 19:47 - 2014-05-31 13:09 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-11-04 19:36 - 2009-07-05 21:14 - 00003958 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{6118DBC4-466A-4EC0-9522-19066FBBCC47} 2014-11-04 19:36 - 2009-07-05 21:14 - 00000416 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{6118DBC4-466A-4EC0-9522-19066FBBCC47}.job 2014-11-03 22:10 - 2009-07-05 20:55 - 00000000 ____D () C:\Users\Home 2014-11-03 20:05 - 2009-12-02 16:53 - 00000000 ____D () C:\Users\Home\AppData\Roaming\QuickScan 2014-11-02 19:56 - 2014-05-31 13:08 - 00000903 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-11-02 19:56 - 2014-05-31 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-11-02 19:56 - 2014-05-31 13:08 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-11-02 15:00 - 2014-09-22 19:52 - 00000394 ____H () C:\Windows\Tasks\{82897433-0E25-4B1B-ABA7-05D73E386117}.job 2014-11-01 11:08 - 2013-03-10 10:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-10-28 06:34 - 2009-10-04 00:55 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-10-27 19:27 - 2013-01-06 15:44 - 00049259 _____ () C:\Users\Home\Desktop\Malteser_StundenZettel_2013.ods 2014-10-21 17:42 - 2009-08-23 15:10 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-10-21 17:42 - 2009-08-23 15:10 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-10-20 11:13 - 2014-10-03 11:07 - 00000000 ____D () C:\ProgramData\Oracle 2014-10-20 11:11 - 2014-10-03 11:06 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-10-20 11:11 - 2014-10-03 11:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-10-20 11:10 - 2014-10-03 11:06 - 00000000 ____D () C:\Program Files (x86)\Java 2014-10-20 11:03 - 2013-03-28 10:57 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-10-20 11:03 - 2012-04-30 23:31 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-10-20 11:03 - 2011-08-21 09:27 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-10-20 11:01 - 2014-07-08 13:05 - 00000000 ____D () C:\Users\Home\AppData\Local\Adobe 2014-10-19 07:59 - 2014-09-22 19:52 - 00003250 _____ () C:\Windows\System32\Tasks\{82897433-0E25-4B1B-ABA7-05D73E386117} 2014-10-16 14:47 - 2009-07-07 07:16 - 00000680 _____ () C:\Users\Home\AppData\Local\d3d9caps.dat 2014-10-16 14:45 - 2006-11-02 16:21 - 00375016 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-10-16 14:13 - 2013-09-02 11:31 - 00000000 ____D () C:\Windows\system32\MRT 2014-10-16 14:00 - 2006-11-02 13:35 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe Files to move or delete: ==================== C:\Windows\Tasks\{82897433-0E25-4B1B-ABA7-05D73E386117}.job C:\Windows\Tasks\{9885EFF2-BAE1-4847-87F4-87821C063D76}.job Some content of TEMP: ==================== C:\Users\Home\AppData\Local\Temp\Quarantine.exe C:\Users\Home\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-04 20:27 ==================== End Of Log ============================ --- --- --- Wie sieht es jetzt aus? Danke! |
05.11.2014, 14:55 | #4 |
/// the machine /// TB-Ausbilder | Windows Vista SP2 64-bit - Virus / unerwünschtes Programm?ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
05.11.2014, 21:20 | #5 |
| Windows Vista SP2 64-bit - Virus / unerwünschtes Programm? Hallo, Eset Online Scanner hat zum Glück nichts mehr gefunden. LOG: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=6f44bf28ca0adb44bc76b267368792fa # engine=20945 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-11-05 07:20:29 # local_time=2014-11-05 08:20:29 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode_1='Panda Cloud Antivirus' # compatibility_mode=1552 16777213 75 93 4312740 201411203 0 0 # compatibility_mode_1='' # compatibility_mode=5892 16776573 100 100 90991 252739135 0 0 # scanned=219287 # found=0 # cleaned=0 # scan_time=5565 Code:
ATTFilter Results of screen317's Security Check version 0.99.89 Windows Vista Service Pack 2 x64 (UAC is enabled) Internet Explorer 8 Out of date! Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` Panda Free Antivirus WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 67 Java 8 Update 25 Adobe Flash Player 15.0.0.189 Adobe Reader 10.1.12 Adobe Reader out of Date! Mozilla Firefox (33.0.2) ````````Process Check: objlist.exe by Laurent```````` Windows Defender MSASCui.exe Windows Defender MSASCui.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` "Trojaner gelöscht Trj/Genetic.gen" in C:\Users\Home\Desktop\SecurityCheck.exe wurde in die Quarantäne gestellt. Ich hoffe, das ist eine Fehlmeldung? Hi, hier noch die frische FRST Log: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-11-2014 Ran by Home (administrator) on HOME-PC on 05-11-2014 21:10:47 Running from C:\Users\Home\Desktop Loaded Profile: Home (Available profiles: Home & Gast) Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 8 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ATI Technologies Inc.) C:\WINDOWS\System32\Ati2evxx.exe (Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe (ATI Technologies Inc.) C:\WINDOWS\System32\Ati2evxx.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\svchost.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe (Microsoft Corporation) C:\WINDOWS\System32\mobsync.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Realtek Semiconductor) C:\WINDOWS\RAVCpl64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Desktop.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RAVCpl64.exe [6150656 2008-03-26] (Realtek Semiconductor) HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [182808 2008-11-03] (Intel Corporation) HKLM-x32\...\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company) HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.) HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [37624 2014-07-24] (Panda Security, S.L.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {0061f5ed-6d18-11de-8b85-00221526174f} - K:\pcwstart.exe HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {6c5b72ba-ad02-11df-a44c-00221526174f} - wd_windows_tools\setup.exe HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {d68e194b-fafb-11df-bd8c-00221526174f} - J:\pushinst.exe HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {edfdbac5-a091-11de-8dc8-00221526174f} - starter.exe HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (Dropbox, Inc.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: http=127.0.0.1:14326;https=127.0.0.1:14326 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {1ABA2C13-E36C-4497-8234-1E146E69EAA4} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de SearchScopes: HKLM - {FB5DD038-132F-4EA1-8871-F5F9A3D5AC1E} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 SearchScopes: HKCU - {1ABA2C13-E36C-4497-8234-1E146E69EAA4} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=protegere SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} hxxp://www.celartem.com/en/download/data/djvu_autoinstall/DjVuControl_en_US.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2 FireFox: ======== FF ProfilePath: C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\0yk7tulu.default-1410973344085 FF Homepage: https://www.google.de FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll () FF Plugin: @java.com/DTPlugin,version=10.10.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll () FF Plugin-x32: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll No File FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll No File FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Bitdefender QuickScan - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\0yk7tulu.default-1410973344085\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2014-11-03] FF Extension: NoScript - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\0yk7tulu.default-1410973344085\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-09-17] FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-14] FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com) R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) [File not signed] R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129992 2008-02-03] (EasyBits Sofware AS) [File not signed] R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [438616 2014-08-07] (Garmin Ltd or its subsidiaries) S2 gupdate1ca23fa2f8d54a0; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107912 2014-10-21] (Google Inc.) R2 HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-03-14] (Hewlett-Packard) [File not signed] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed] R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-03-17] (Hewlett-Packard Company) [File not signed] S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [141560 2014-07-24] (Panda Security, S.L.) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-07-18] (Hewlett-Packard) [File not signed] R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [61688 2014-07-23] (Panda Security, S.L.) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-07-18] (Hewlett-Packard) [File not signed] R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [38136 2014-07-24] (Panda Security, S.L.) S3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [637952 2009-06-02] (Nokia.) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [714368 2010-10-22] (AVM GmbH) S3 GigasetGenericUSB_x64; C:\Windows\System32\DRIVERS\GigasetGenericUSB_x64.sys [54272 2009-02-20] (Siemens Home and Office Communication Devices GmbH & Co. KG) R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] () S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] () R1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [96800 2014-06-04] (Panda Security, S.L.) R1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [162336 2014-06-18] (Panda Security, S.L.) R1 NNSHTTPS; C:\Windows\System32\DRIVERS\NNSHttps.sys [112160 2014-06-04] (Panda Security, S.L.) R1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [115232 2014-06-04] (Panda Security, S.L.) R1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [46336 2014-01-16] (Panda Security, S.L.) R1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [95776 2014-06-04] (Panda Security, S.L.) R1 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [70176 2014-06-04] (Panda Security, S.L.) R1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [125984 2014-06-04] (Panda Security, S.L.) R1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [306720 2014-06-04] (Panda Security, S.L.) R1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [169504 2014-06-04] (Panda Security, S.L.) R1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [115744 2014-06-04] (Panda Security, S.L.) R1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [261152 2014-06-04] (Panda Security, S.L.) R1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [109088 2014-06-04] (Panda Security, S.L.) R3 Ps2; C:\Windows\System32\DRIVERS\PS2.sys [21504 2006-09-07] () R2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [160800 2014-07-24] (Panda Security, S.L.) R2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [120352 2014-07-24] (Panda Security, S.L.) R1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [195616 2014-07-24] (Panda Security, S.L.) R2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [122400 2014-07-24] (Panda Security, S.L.) R2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [132128 2014-07-24] (Panda Security, S.L.) R2 PSINReg; C:\Windows\System32\DRIVERS\PSINReg.sys [106016 2014-07-24] (Panda Security, S.L.) R3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [60400 2014-03-25] (Panda Security, S.L.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S0 Lbd; system32\DRIVERS\Lbd.sys [X] S3 nmwcdnsux64; system32\drivers\nmwcdnsux64.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 PCD5SRVC{E2AF211B-86DA020A-05040000}; \??\C:\PROGRA~2\PC-DOC~1\PCD5SRVC_x64.pkms [X] R4 PsBoot; system32\Drivers\PsBoot.sys [X] S3 upperdev; system32\DRIVERS\usbser_lowerfltx64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-05 18:39 - 2014-11-05 18:39 - 02347384 _____ (ESET) C:\Users\Home\Desktop\esetsmartinstaller_deu.exe 2014-11-04 20:34 - 2014-11-04 20:34 - 00000899 _____ () C:\Users\Home\Desktop\JRT.txt 2014-11-04 20:25 - 2014-11-04 20:25 - 01706359 _____ (Thisisu) C:\Users\Home\Desktop\JRT.exe 2014-11-04 20:07 - 2014-11-04 20:07 - 01998336 _____ () C:\Users\Home\Desktop\AdwCleaner_4.002.exe 2014-11-04 20:05 - 2014-11-04 20:05 - 00001204 _____ () C:\Users\Home\Desktop\mbam.txt 2014-11-03 22:13 - 2014-11-03 22:13 - 00036129 _____ () C:\Users\Home\Desktop\Addition.txt 2014-11-03 22:12 - 2014-11-05 21:10 - 00018215 _____ () C:\Users\Home\Desktop\FRST.txt 2014-11-03 22:12 - 2014-11-05 21:10 - 00000000 ____D () C:\FRST 2014-11-03 22:10 - 2014-11-03 22:10 - 00000470 _____ () C:\Users\Home\Desktop\defogger_disable.log 2014-11-03 22:10 - 2014-11-03 22:10 - 00000000 _____ () C:\Users\Home\defogger_reenable 2014-11-03 22:06 - 2014-11-03 22:08 - 00000000 ____D () C:\Users\Home\Downloads\Analyse-Tools Viren 2014-11-03 22:05 - 2014-11-03 22:05 - 00380416 _____ () C:\Users\Home\Desktop\du4dgzz1.exe 2014-11-03 22:00 - 2014-11-03 22:00 - 02114560 _____ (Farbar) C:\Users\Home\Desktop\FRST64.exe 2014-11-03 21:59 - 2014-11-03 21:59 - 00050477 _____ () C:\Users\Home\Desktop\Defogger.exe 2014-11-03 21:44 - 2014-11-03 21:44 - 00001062 _____ () C:\Users\Home\Desktop\Eset_OnlineScanner.txt 2014-11-03 19:21 - 2014-11-03 19:21 - 00276912 _____ () C:\Windows\Minidump\Mini110314-01.dmp 2014-11-01 18:03 - 2014-11-01 18:03 - 00000000 ____D () C:\Users\Gast\AppData\Local\Macromedia 2014-11-01 18:01 - 2014-11-01 18:02 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Mozilla 2014-11-01 18:01 - 2014-11-01 18:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Mozilla 2014-11-01 17:13 - 2014-11-01 17:13 - 00090320 _____ () C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT 2014-11-01 17:13 - 2014-11-01 17:13 - 00000951 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000941 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000936 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000917 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000020 ___SH () C:\Users\Gast\ntuser.ini 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Vorlagen 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Startmenü 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Netzwerkumgebung 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Lokale Einstellungen 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Eigene Dateien 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Druckumgebung 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Musik 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Bilder 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Verlauf 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Anwendungsdaten 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Anwendungsdaten 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Panda Security 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\ATI 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Adobe 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Local\VirtualStore 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Local\ATI 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast 2014-11-01 17:13 - 2014-06-22 16:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Garmin 2014-11-01 17:13 - 2009-12-13 00:20 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Macromedia 2014-11-01 17:13 - 2008-06-17 21:54 - 00001076 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite Deluxe.lnk 2014-11-01 17:13 - 2008-01-21 04:20 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-11-01 17:13 - 2008-01-21 04:20 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-11-01 13:17 - 2014-11-01 13:21 - 00017456 _____ () C:\Users\Home\Desktop\VW Bank - Bearbeitungsentgelt Kredite.odt 2014-10-31 10:01 - 2014-10-31 10:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-10-20 11:08 - 2014-10-20 11:08 - 00638888 _____ (Oracle Corporation) C:\Users\Home\Downloads\jxpiinstall.exe 2014-10-17 12:58 - 2014-11-03 19:21 - 519873065 _____ () C:\Windows\MEMORY.DMP 2014-10-17 12:58 - 2014-11-03 19:21 - 00000000 ____D () C:\Windows\Minidump 2014-10-17 12:58 - 2014-10-17 12:58 - 00276912 _____ () C:\Windows\Minidump\Mini101714-01.dmp 2014-10-16 14:28 - 2014-09-17 07:57 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-10-16 14:28 - 2014-09-16 17:56 - 00066560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-10-16 14:27 - 2014-09-28 00:41 - 02782208 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-10-16 14:20 - 2014-06-15 23:18 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-10-16 14:20 - 2014-06-15 23:18 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2014-10-16 14:20 - 2014-06-13 19:22 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll 2014-10-16 14:20 - 2014-06-13 19:22 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll 2014-10-16 14:20 - 2014-06-13 18:36 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-10-16 14:20 - 2014-06-13 18:36 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-10-16 14:13 - 2014-09-05 00:38 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2014-10-15 16:40 - 2014-09-23 21:22 - 12473344 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 09329152 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 02359296 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 01538560 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-10-15 16:40 - 2014-09-23 21:22 - 01491968 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 01147904 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00742912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00459776 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00219136 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 11083264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 06004224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 02006016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 01469440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-10-15 16:40 - 2014-09-23 21:08 - 01214976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00916992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00630784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00387584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00105984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00055808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00055296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00043520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00019456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\corpol.dll 2014-10-15 16:40 - 2014-09-23 20:15 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-10-15 16:40 - 2014-09-23 20:02 - 00162816 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-10-15 16:40 - 2014-09-23 20:02 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-10-15 16:40 - 2014-09-23 20:01 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-10-15 16:40 - 2014-09-23 20:01 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-10-15 16:40 - 2014-09-23 19:38 - 00385024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-10-15 16:40 - 2014-09-23 19:31 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2014-10-15 16:40 - 2014-09-23 19:31 - 00133632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-10-15 16:40 - 2014-09-23 19:30 - 01638912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-10-15 16:40 - 2014-09-23 19:30 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-05 21:07 - 2014-10-03 09:12 - 00015486 _____ () C:\Windows\PFRO.log 2014-11-05 21:07 - 2009-08-23 15:10 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-11-05 21:07 - 2006-11-02 16:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-05 21:07 - 2006-11-02 16:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-05 21:07 - 2006-11-02 16:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-05 21:06 - 2012-07-07 08:13 - 01371555 _____ () C:\Windows\WindowsUpdate.log 2014-11-05 21:06 - 2006-11-02 16:42 - 00032530 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-11-05 20:52 - 2013-03-28 10:57 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-11-05 20:47 - 2009-08-23 15:10 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-11-05 20:29 - 2009-07-05 21:14 - 00003958 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{6118DBC4-466A-4EC0-9522-19066FBBCC47} 2014-11-05 20:29 - 2009-07-05 21:14 - 00000416 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{6118DBC4-466A-4EC0-9522-19066FBBCC47}.job 2014-11-05 18:29 - 2008-06-18 07:22 - 00628742 _____ () C:\Windows\system32\perfh007.dat 2014-11-05 18:29 - 2008-06-18 07:22 - 00126486 _____ () C:\Windows\system32\perfc007.dat 2014-11-05 18:29 - 2006-11-02 13:46 - 01445546 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-04 20:18 - 2014-09-17 18:08 - 00000000 ____D () C:\AdwCleaner 2014-11-04 19:47 - 2014-05-31 13:09 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-11-03 22:10 - 2009-07-05 20:55 - 00000000 ____D () C:\Users\Home 2014-11-03 20:05 - 2009-12-02 16:53 - 00000000 ____D () C:\Users\Home\AppData\Roaming\QuickScan 2014-11-02 19:56 - 2014-05-31 13:08 - 00000903 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-11-02 19:56 - 2014-05-31 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-11-02 19:56 - 2014-05-31 13:08 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-11-02 15:00 - 2014-09-22 19:52 - 00000394 ____H () C:\Windows\Tasks\{82897433-0E25-4B1B-ABA7-05D73E386117}.job 2014-11-01 11:08 - 2013-03-10 10:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-10-28 06:34 - 2009-10-04 00:55 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-10-27 19:27 - 2013-01-06 15:44 - 00049259 _____ () C:\Users\Home\Desktop\Malteser_StundenZettel_2013.ods 2014-10-21 17:42 - 2009-08-23 15:10 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-10-21 17:42 - 2009-08-23 15:10 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-10-20 11:13 - 2014-10-03 11:07 - 00000000 ____D () C:\ProgramData\Oracle 2014-10-20 11:11 - 2014-10-03 11:06 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-10-20 11:11 - 2014-10-03 11:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-10-20 11:10 - 2014-10-03 11:06 - 00000000 ____D () C:\Program Files (x86)\Java 2014-10-20 11:03 - 2013-03-28 10:57 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-10-20 11:03 - 2012-04-30 23:31 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-10-20 11:03 - 2011-08-21 09:27 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-10-20 11:01 - 2014-07-08 13:05 - 00000000 ____D () C:\Users\Home\AppData\Local\Adobe 2014-10-19 07:59 - 2014-09-22 19:52 - 00003250 _____ () C:\Windows\System32\Tasks\{82897433-0E25-4B1B-ABA7-05D73E386117} 2014-10-16 14:47 - 2009-07-07 07:16 - 00000680 _____ () C:\Users\Home\AppData\Local\d3d9caps.dat 2014-10-16 14:45 - 2006-11-02 16:21 - 00375016 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-10-16 14:13 - 2013-09-02 11:31 - 00000000 ____D () C:\Windows\system32\MRT 2014-10-16 14:00 - 2006-11-02 13:35 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe Files to move or delete: ==================== C:\Windows\Tasks\{82897433-0E25-4B1B-ABA7-05D73E386117}.job C:\Windows\Tasks\{9885EFF2-BAE1-4847-87F4-87821C063D76}.job Some content of TEMP: ==================== C:\Users\Home\AppData\Local\Temp\Quarantine.exe C:\Users\Home\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-05 18:28 ==================== End Of Log ============================ --- --- --- --- --- --- Ich hoffe nur, das Panda einen Fehlalarm hatte? Noch eine andere Frage - soll der Windows Defender zusätzlich aktiviert sein, wenn man eine Antivirus Software hat? Wahrscheinlich nicht, oder? VG, Moni |
06.11.2014, 13:22 | #6 |
/// the machine /// TB-Ausbilder | Windows Vista SP2 64-bit - Virus / unerwünschtes Programm? Das ist ne Fehlermeldung . Java updaten. Defender kann aus bleiben. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ProxyServer: http=127.0.0.1:14326;https=127.0.0.1:14326 S3 PCD5SRVC{E2AF211B-86DA020A-05040000}; \??\C:\PROGRA~2\PC-DOC~1\PCD5SRVC_x64.pkms [X] Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Frisches FRST log bitte.
__________________ --> Windows Vista SP2 64-bit - Virus / unerwünschtes Programm? |
07.11.2014, 19:09 | #7 |
| Windows Vista SP2 64-bit - Virus / unerwünschtes Programm? Hallo, danke! Java ist aktuell und die alte Version ist deinstalliert. Fixlog: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-11-2014 Ran by Home at 2014-11-07 18:54:09 Run:1 Running from C:\Users\Home\Desktop Loaded Profile: Home (Available profiles: Home & Gast) Boot Mode: Normal ============================================== Content of fixlist: ***************** GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ProxyServer: http=127.0.0.1:14326;https=127.0.0.1:14326 S3 PCD5SRVC{E2AF211B-86DA020A-05040000}; \??\C:\PROGRA~2\PC-DOC~1\PCD5SRVC_x64.pkms [X] ***************** C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. PCD5SRVC{E2AF211B-86DA020A-05040000} => Service deleted successfully. The system needed a reboot. ==== End of Fixlog ==== FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-11-2014 Ran by Home (administrator) on HOME-PC on 07-11-2014 19:01:43 Running from C:\Users\Home\Desktop Loaded Profile: Home (Available profiles: Home & Gast) Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 8 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ATI Technologies Inc.) C:\WINDOWS\System32\Ati2evxx.exe (Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe (ATI Technologies Inc.) C:\WINDOWS\System32\Ati2evxx.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\svchost.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe (Realtek Semiconductor) C:\WINDOWS\RAVCpl64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\WINDOWS\System32\wbem\WMIADAP.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Desktop.exe (Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe (Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RAVCpl64.exe [6150656 2008-03-26] (Realtek Semiconductor) HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [182808 2008-11-03] (Intel Corporation) HKLM-x32\...\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company) HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.) HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [37624 2014-07-24] (Panda Security, S.L.) HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {0061f5ed-6d18-11de-8b85-00221526174f} - K:\pcwstart.exe HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {6c5b72ba-ad02-11df-a44c-00221526174f} - wd_windows_tools\setup.exe HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {d68e194b-fafb-11df-bd8c-00221526174f} - J:\pushinst.exe HKU\S-1-5-21-2310858669-3201491733-1471162819-1000\...\MountPoints2: {edfdbac5-a091-11de-8dc8-00221526174f} - starter.exe HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Home\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {1ABA2C13-E36C-4497-8234-1E146E69EAA4} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de SearchScopes: HKLM - {FB5DD038-132F-4EA1-8871-F5F9A3D5AC1E} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 SearchScopes: HKCU - {1ABA2C13-E36C-4497-8234-1E146E69EAA4} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=protegere SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} hxxp://www.celartem.com/en/download/data/djvu_autoinstall/DjVuControl_en_US.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2 FireFox: ======== FF ProfilePath: C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\0yk7tulu.default-1410973344085 FF Homepage: https://www.google.de FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll () FF Plugin: @java.com/DTPlugin,version=10.10.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll () FF Plugin-x32: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll No File FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll No File FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Bitdefender QuickScan - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\0yk7tulu.default-1410973344085\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2014-11-03] FF Extension: NoScript - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\0yk7tulu.default-1410973344085\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-09-17] FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-14] FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com) R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) [File not signed] R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129992 2008-02-03] (EasyBits Sofware AS) [File not signed] R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [438616 2014-08-07] (Garmin Ltd or its subsidiaries) S2 gupdate1ca23fa2f8d54a0; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107912 2014-10-21] (Google Inc.) R2 HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-03-14] (Hewlett-Packard) [File not signed] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed] R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-03-17] (Hewlett-Packard Company) [File not signed] S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [141560 2014-07-24] (Panda Security, S.L.) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-07-18] (Hewlett-Packard) [File not signed] R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [61688 2014-07-23] (Panda Security, S.L.) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-07-18] (Hewlett-Packard) [File not signed] R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [38136 2014-07-24] (Panda Security, S.L.) S3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [637952 2009-06-02] (Nokia.) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [714368 2010-10-22] (AVM GmbH) S3 GigasetGenericUSB_x64; C:\Windows\System32\DRIVERS\GigasetGenericUSB_x64.sys [54272 2009-02-20] (Siemens Home and Office Communication Devices GmbH & Co. KG) R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] () S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] () R1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [96800 2014-06-04] (Panda Security, S.L.) R1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [162336 2014-06-18] (Panda Security, S.L.) R1 NNSHTTPS; C:\Windows\System32\DRIVERS\NNSHttps.sys [112160 2014-06-04] (Panda Security, S.L.) R1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [115232 2014-06-04] (Panda Security, S.L.) R1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [46336 2014-01-16] (Panda Security, S.L.) R1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [95776 2014-06-04] (Panda Security, S.L.) R1 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [70176 2014-06-04] (Panda Security, S.L.) R1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [125984 2014-06-04] (Panda Security, S.L.) R1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [306720 2014-06-04] (Panda Security, S.L.) R1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [169504 2014-06-04] (Panda Security, S.L.) R1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [115744 2014-06-04] (Panda Security, S.L.) R1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [261152 2014-06-04] (Panda Security, S.L.) R1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [109088 2014-06-04] (Panda Security, S.L.) R3 Ps2; C:\Windows\System32\DRIVERS\PS2.sys [21504 2006-09-07] () R2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [160800 2014-07-24] (Panda Security, S.L.) R2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [120352 2014-07-24] (Panda Security, S.L.) R1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [195616 2014-07-24] (Panda Security, S.L.) R2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [122400 2014-07-24] (Panda Security, S.L.) R2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [132128 2014-07-24] (Panda Security, S.L.) R2 PSINReg; C:\Windows\System32\DRIVERS\PSINReg.sys [106016 2014-07-24] (Panda Security, S.L.) R3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [60400 2014-03-25] (Panda Security, S.L.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S0 Lbd; system32\DRIVERS\Lbd.sys [X] S3 nmwcdnsux64; system32\drivers\nmwcdnsux64.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 upperdev; system32\DRIVERS\usbser_lowerfltx64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-05 18:39 - 2014-11-05 18:39 - 02347384 _____ (ESET) C:\Users\Home\Desktop\esetsmartinstaller_deu.exe 2014-11-04 20:34 - 2014-11-04 20:34 - 00000899 _____ () C:\Users\Home\Desktop\JRT.txt 2014-11-04 20:25 - 2014-11-04 20:25 - 01706359 _____ (Thisisu) C:\Users\Home\Desktop\JRT.exe 2014-11-04 20:07 - 2014-11-04 20:07 - 01998336 _____ () C:\Users\Home\Desktop\AdwCleaner_4.002.exe 2014-11-04 20:05 - 2014-11-04 20:05 - 00001204 _____ () C:\Users\Home\Desktop\mbam.txt 2014-11-03 22:13 - 2014-11-03 22:13 - 00036129 _____ () C:\Users\Home\Desktop\Addition.txt 2014-11-03 22:12 - 2014-11-07 19:01 - 00017930 _____ () C:\Users\Home\Desktop\FRST.txt 2014-11-03 22:12 - 2014-11-07 19:01 - 00000000 ____D () C:\FRST 2014-11-03 22:10 - 2014-11-03 22:10 - 00000470 _____ () C:\Users\Home\Desktop\defogger_disable.log 2014-11-03 22:10 - 2014-11-03 22:10 - 00000000 _____ () C:\Users\Home\defogger_reenable 2014-11-03 22:06 - 2014-11-03 22:08 - 00000000 ____D () C:\Users\Home\Downloads\Analyse-Tools Viren 2014-11-03 22:05 - 2014-11-03 22:05 - 00380416 _____ () C:\Users\Home\Desktop\du4dgzz1.exe 2014-11-03 22:00 - 2014-11-03 22:00 - 02114560 _____ (Farbar) C:\Users\Home\Desktop\FRST64.exe 2014-11-03 21:59 - 2014-11-03 21:59 - 00050477 _____ () C:\Users\Home\Desktop\Defogger.exe 2014-11-03 21:44 - 2014-11-03 21:44 - 00001062 _____ () C:\Users\Home\Desktop\Eset_OnlineScanner.txt 2014-11-03 19:21 - 2014-11-03 19:21 - 00276912 _____ () C:\Windows\Minidump\Mini110314-01.dmp 2014-11-01 18:03 - 2014-11-01 18:03 - 00000000 ____D () C:\Users\Gast\AppData\Local\Macromedia 2014-11-01 18:01 - 2014-11-01 18:02 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Mozilla 2014-11-01 18:01 - 2014-11-01 18:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Mozilla 2014-11-01 17:13 - 2014-11-01 17:13 - 00090320 _____ () C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT 2014-11-01 17:13 - 2014-11-01 17:13 - 00000951 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000941 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000936 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000917 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk 2014-11-01 17:13 - 2014-11-01 17:13 - 00000020 ___SH () C:\Users\Gast\ntuser.ini 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Vorlagen 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Startmenü 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Netzwerkumgebung 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Lokale Einstellungen 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Eigene Dateien 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Druckumgebung 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Musik 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Bilder 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Verlauf 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Anwendungsdaten 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 _SHDL () C:\Users\Gast\Anwendungsdaten 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Panda Security 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\ATI 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Adobe 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Local\VirtualStore 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast\AppData\Local\ATI 2014-11-01 17:13 - 2014-11-01 17:13 - 00000000 ____D () C:\Users\Gast 2014-11-01 17:13 - 2014-06-22 16:13 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Garmin 2014-11-01 17:13 - 2009-12-13 00:20 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Macromedia 2014-11-01 17:13 - 2008-06-17 21:54 - 00001076 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite Deluxe.lnk 2014-11-01 17:13 - 2008-01-21 04:20 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-11-01 17:13 - 2008-01-21 04:20 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-11-01 13:17 - 2014-11-01 13:21 - 00017456 _____ () C:\Users\Home\Desktop\VW Bank - Bearbeitungsentgelt Kredite.odt 2014-10-31 10:01 - 2014-11-07 18:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-10-20 11:08 - 2014-10-20 11:08 - 00638888 _____ (Oracle Corporation) C:\Users\Home\Downloads\jxpiinstall.exe 2014-10-17 12:58 - 2014-11-03 19:21 - 519873065 _____ () C:\Windows\MEMORY.DMP 2014-10-17 12:58 - 2014-11-03 19:21 - 00000000 ____D () C:\Windows\Minidump 2014-10-17 12:58 - 2014-10-17 12:58 - 00276912 _____ () C:\Windows\Minidump\Mini101714-01.dmp 2014-10-16 14:28 - 2014-09-17 07:57 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-10-16 14:28 - 2014-09-16 17:56 - 00066560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-10-16 14:27 - 2014-09-28 00:41 - 02782208 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-10-16 14:20 - 2014-06-15 23:18 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-10-16 14:20 - 2014-06-15 23:18 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2014-10-16 14:20 - 2014-06-13 19:22 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll 2014-10-16 14:20 - 2014-06-13 19:22 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll 2014-10-16 14:20 - 2014-06-13 18:36 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-10-16 14:20 - 2014-06-13 18:36 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-10-16 14:13 - 2014-09-05 00:38 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2014-10-15 16:40 - 2014-09-23 21:22 - 12473344 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 09329152 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 02359296 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 01538560 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-10-15 16:40 - 2014-09-23 21:22 - 01491968 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 01147904 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00742912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00459776 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00219136 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-10-15 16:40 - 2014-09-23 21:22 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 11083264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 06004224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 02006016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 01469440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-10-15 16:40 - 2014-09-23 21:08 - 01214976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00916992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00630784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00387584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00105984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00055808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00055296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00043520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-10-15 16:40 - 2014-09-23 21:08 - 00019456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\corpol.dll 2014-10-15 16:40 - 2014-09-23 20:15 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-10-15 16:40 - 2014-09-23 20:02 - 00162816 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-10-15 16:40 - 2014-09-23 20:02 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-10-15 16:40 - 2014-09-23 20:01 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-10-15 16:40 - 2014-09-23 20:01 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-10-15 16:40 - 2014-09-23 19:38 - 00385024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-10-15 16:40 - 2014-09-23 19:31 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2014-10-15 16:40 - 2014-09-23 19:31 - 00133632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-10-15 16:40 - 2014-09-23 19:30 - 01638912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-10-15 16:40 - 2014-09-23 19:30 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-07 19:01 - 2008-06-18 07:22 - 00628742 _____ () C:\Windows\system32\perfh007.dat 2014-11-07 19:01 - 2008-06-18 07:22 - 00126486 _____ () C:\Windows\system32\perfc007.dat 2014-11-07 19:01 - 2006-11-02 13:46 - 01445546 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-07 18:59 - 2012-07-07 08:13 - 01414514 _____ () C:\Windows\WindowsUpdate.log 2014-11-07 18:58 - 2009-08-23 15:10 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-11-07 18:56 - 2014-05-30 18:22 - 00000008 __RSH () C:\ProgramData\ntuser.pol 2014-11-07 18:55 - 2014-10-03 09:12 - 00016082 _____ () C:\Windows\PFRO.log 2014-11-07 18:55 - 2006-11-02 16:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-07 18:55 - 2006-11-02 16:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-07 18:55 - 2006-11-02 16:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-07 18:54 - 2006-11-02 16:42 - 00032530 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-11-07 18:54 - 2006-11-02 14:34 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-11-07 18:52 - 2013-03-28 10:57 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-11-07 18:49 - 2014-10-03 11:06 - 00000000 ____D () C:\Program Files (x86)\Java 2014-11-07 18:47 - 2009-08-23 15:10 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-11-07 17:44 - 2009-07-05 21:14 - 00003958 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{6118DBC4-466A-4EC0-9522-19066FBBCC47} 2014-11-07 17:44 - 2009-07-05 21:14 - 00000416 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{6118DBC4-466A-4EC0-9522-19066FBBCC47}.job 2014-11-04 20:18 - 2014-09-17 18:08 - 00000000 ____D () C:\AdwCleaner 2014-11-04 19:47 - 2014-05-31 13:09 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-11-03 22:10 - 2009-07-05 20:55 - 00000000 ____D () C:\Users\Home 2014-11-03 20:05 - 2009-12-02 16:53 - 00000000 ____D () C:\Users\Home\AppData\Roaming\QuickScan 2014-11-02 19:56 - 2014-05-31 13:08 - 00000903 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-11-02 19:56 - 2014-05-31 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-11-02 19:56 - 2014-05-31 13:08 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-11-02 15:00 - 2014-09-22 19:52 - 00000394 ____H () C:\Windows\Tasks\{82897433-0E25-4B1B-ABA7-05D73E386117}.job 2014-11-01 11:08 - 2013-03-10 10:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-10-28 06:34 - 2009-10-04 00:55 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-10-27 19:27 - 2013-01-06 15:44 - 00049259 _____ () C:\Users\Home\Desktop\Malteser_StundenZettel_2013.ods 2014-10-21 17:42 - 2009-08-23 15:10 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-10-21 17:42 - 2009-08-23 15:10 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-10-20 11:13 - 2014-10-03 11:07 - 00000000 ____D () C:\ProgramData\Oracle 2014-10-20 11:11 - 2014-10-03 11:06 - 00272296 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-10-20 11:11 - 2014-10-03 11:06 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-10-20 11:11 - 2014-10-03 11:06 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-10-20 11:11 - 2014-10-03 11:06 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-10-20 11:11 - 2014-10-03 11:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-10-20 11:03 - 2013-03-28 10:57 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-10-20 11:03 - 2012-04-30 23:31 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-10-20 11:03 - 2011-08-21 09:27 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-10-20 11:01 - 2014-07-08 13:05 - 00000000 ____D () C:\Users\Home\AppData\Local\Adobe 2014-10-19 07:59 - 2014-09-22 19:52 - 00003250 _____ () C:\Windows\System32\Tasks\{82897433-0E25-4B1B-ABA7-05D73E386117} 2014-10-16 14:47 - 2009-07-07 07:16 - 00000680 _____ () C:\Users\Home\AppData\Local\d3d9caps.dat 2014-10-16 14:45 - 2006-11-02 16:21 - 00375016 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-10-16 14:13 - 2013-09-02 11:31 - 00000000 ____D () C:\Windows\system32\MRT 2014-10-16 14:00 - 2006-11-02 13:35 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe Files to move or delete: ==================== C:\Windows\Tasks\{82897433-0E25-4B1B-ABA7-05D73E386117}.job C:\Windows\Tasks\{9885EFF2-BAE1-4847-87F4-87821C063D76}.job Some content of TEMP: ==================== C:\Users\Home\AppData\Local\Temp\Quarantine.exe C:\Users\Home\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-07 17:45 ==================== End Of Log ============================ --- --- --- Grüße, Moni |
08.11.2014, 08:05 | #8 |
/// the machine /// TB-Ausbilder | Windows Vista SP2 64-bit - Virus / unerwünschtes Programm? Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.11.2014, 14:12 | #9 |
| Windows Vista SP2 64-bit - Virus / unerwünschtes Programm? Hallo, alles erledigt - vielen Dank für die super Hilfe! Moni |
09.11.2014, 07:44 | #10 |
/// the machine /// TB-Ausbilder | Windows Vista SP2 64-bit - Virus / unerwünschtes Programm? Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows Vista SP2 64-bit - Virus / unerwünschtes Programm? |
ad-aware, antivirus, branding, browser, canon, error, fehler, firefox, flash player, helper, home, homepage, iexplore.exe, lws.exe, mozilla, popup, programm, realtek, registry, scan, security, software, stick, trojaner, usb, virus, vista, windows |