|
Alles rund um Windows: Windows 7 - Internet (im Browser) geht nicht, nslookup funktioniert ebenfalls nichtWindows 7 Hilfe zu allen Windows-Betriebssystemen: Windows XP, Windows Vista, Windows 7, Windows 8(.1) und Windows 10 / Windows 11- als auch zu sämtlicher Windows-Software. Alles zu Windows 10 ist auch gerne willkommen. Bitte benenne etwaige Fehler oder Bluescreens unter Windows mit dem Wortlaut der Fehlermeldung und Fehlercode. Erste Schritte für Hilfe unter Windows. |
23.12.2014, 22:09 | #1 |
| Problem: Windows 7 - Internet (im Browser) geht nicht, nslookup funktioniert ebenfalls nicht Hallo habe mich grade angemeldet, weil das Forum fuer mich der letzte Schritt vor Neuinstallation des OS ist. Vielleicht schildere ich mein Problem mal ganz von Anfang an: OS: Windows 7 Home Premium 64 bit Hatte nun schon seit geraumer Zeit eine Fehlermeldung "Catalyst Control Center muss beendet werden" (nicht genauer Wortlaut), bei der ich immer erst nach PC-Start diese Meldung abwarten musste bevor ich etwas tun konnte, ansonsten hing sich alles auf. Gestern erschien diese Meldung (auch nach mehrmaligen Neustarts) nicht. Bin dann in abgesicherten Modus (mit Netzwerktreibern) um nach Loesung zu suchen. Dort kam Fehlermeldung nicht, habe per msconfig "CCC.exe" Autostarteintrag deaktiviert und mich dort schon gewundert, dass ich nicht ins Internet kam. Nach nochmaligem normalen Starten des PCs hing sich Rechner wieder auf, bin dann wieder in abgesicherten Modus, habe weitere, unnoetige, Autostarteintraege geloescht und zwecks Vorbereitung auf Neuinstallation angefangen Daten zu sichern, alte Programme zu deinstallieren. PC zufaellig nochmals normal gestartet und siehe da, PC hing sich auf Desktopseite nicht mehr auf, ABER seitdem kein Internetzugriff ueber Browser. Netzwerkverbindung geht, bzw. laut Lanverbindung mit Internet verbunden, Skype geht, Handy per WLAN geht (somit Fritzbox, die als Router an alicebox haengt auch ok), auch mein virtueller PC (von dem aus ich jetzt schreibe) hat Internetverbindung. Ping per cmd.exe geht ebenfalls, das einzige,was fehlschlaegt ist nslookup. Code:
ATTFilter nslookup www.google.de Server: UnKnown Address: 0.0.0.0 www.google.de wurde von UnKnown nicht gefunden: No response from server. Dachte mir vllt. hat noch jmd. eine Idee bevor ich wirklich alles neu aufsetzen und Softwaresicherungen einspielen muss. Auch wenn der 1. Teil sehr umfangreich ist, dachte ich mir ich schreib mal alles chronologisch auf Hoffe jmd. hat eine Idee, vielen Dank MfG laserjet |
23.12.2014, 23:41 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows 7 - Internet (im Browser) geht nicht, nslookup funktioniert ebenfalls nicht Anleitung / Hilfe Hi,
__________________Downloade dir bitte Farbar Service Scanner
Poste bitte den Inhalt hier. Und FRST Logs bitte: Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Alles in CODE-Tags posten: Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
24.12.2014, 00:19 | #3 |
| Windows 7 - Internet (im Browser) geht nicht, nslookup funktioniert ebenfalls nicht Details Hallo,
__________________danke fuer die schnelle Antwort. Erstmal ein Problem, die Links mit filepony.de konnte ich nicht oeffnen, kam Connection Timeout. Habe sie woanders gedownloadet. Hier die Logs: Code:
ATTFilter Farbar Service Scanner Version: 21-07-2014 Ran by Michael (administrator) on 23-12-2014 at 23:53:55 Running from "C:\Users\Michael\Desktop\Neuer Ordner" Microsoft Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Attempt to access Local Host IP returned error: Localhost is blocked: Other errors LAN connected. Attempt to access Google IP returned error. Other errors Attempt to access Google.com returned error: Other errors Attempt to access Yahoo.com returned error: Other errors Windows Firewall: ============= Firewall Disabled Policy: ================== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=DWORD:0 System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ Action Center Notification Icon =====> Unable to open HKLM\...\ShellServiceObjects\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A} key. The key does not exist. Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is set to Demand. The default start type is Auto. The ImagePath of WinDefend service is OK. The ServiceDll of WinDefend service is OK. Windows Defender Disabled Policy: ========================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] "DisableAntiSpyware"=DWORD:1 Other Services: ============== Checking FirewallRules of SharedAccess: ATTENTION!=====> Unable to open "SharedAccess\Defaults\FirewallPolicy\FirewallRules" registry key. The key does not exist. File Check: ======== C:\Windows\System32\nsisvc.dll => File is digitally signed C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed C:\Windows\System32\dhcpcore.dll => File is digitally signed C:\Windows\System32\drivers\afd.sys => File is digitally signed C:\Windows\System32\drivers\tdx.sys => File is digitally signed C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed C:\Windows\System32\dnsrslvr.dll => File is digitally signed C:\Windows\System32\mpssvc.dll => File is digitally signed C:\Windows\System32\bfe.dll => File is digitally signed C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed C:\Windows\System32\SDRSVC.dll => File is digitally signed C:\Windows\System32\vssvc.exe => File is digitally signed C:\Windows\System32\wscsvc.dll => File is digitally signed C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed C:\Windows\System32\wuaueng.dll => File is digitally signed C:\Windows\System32\qmgr.dll => File is digitally signed C:\Windows\System32\es.dll => File is digitally signed C:\Windows\System32\cryptsvc.dll => File is digitally signed C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed C:\Windows\System32\ipnathlp.dll => File is digitally signed C:\Windows\System32\iphlpsvc.dll => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed **** End of log **** FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-12-2014 Ran by Michael (administrator) on MICHAEL-PC on 23-12-2014 23:58:39 Running from C:\Users\Michael\Desktop\Neuer Ordner Loaded Profile: Michael (Available profiles: Michael) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (AMD) C:\Windows\System32\atiesrxx.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe (AVM Berlin) C:\Program Files\FRITZ!Fernzugang\avmike.exe (AVM Berlin) C:\Program Files\FRITZ!Fernzugang\certsrv.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Hewlett-Packard Company) C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe (Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE (AVM Berlin) C:\Program Files\FRITZ!Fernzugang\nwtsrv.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe () C:\OEM\USBDECTION\USBS3S4Detection.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE () C:\Users\Michael\AppData\LocalLow\WOT\IE\WOTUpdater.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Virtual PC\Virtual PC.exe (CM&V Hackbart) C:\Program Files (x86)\DVBViewer TE2\DVBViewerTE.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [SfWinStartInfo] => C:\SFIRM32\sfWinStartupInfo.exe [81496 2014-11-13] (Star Finanz - Software Entwicklung und Vertriebs GmbH) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-04] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard) HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware (cleanup)] => rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-3329511875-3327878259-967946423-1000\...\Run: [BackgroundContainer] => "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Michael\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun <===== ATTENTION HKU\S-1-5-21-3329511875-3327878259-967946423-1000\...\MountPoints2: {39a54202-8c57-11e1-add1-0008c9f03d51} - N:\setup.exe HKU\S-1-5-21-3329511875-3327878259-967946423-1000\...\MountPoints2: {4e9874dc-5100-11e2-b5dc-9d3955d32c9a} - L:\autorun.exe HKU\S-1-5-21-3329511875-3327878259-967946423-1000\...\MountPoints2: {5687c4a9-7cfa-11e1-9813-806e6f6e6963} - E:\Setup.exe HKU\S-1-5-21-3329511875-3327878259-967946423-1000\...\MountPoints2: {db52742b-fc85-11e2-b579-9c6e6319a395} - K:\Autorun.exe HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} AppInit_DLLs: c:\progra~2\movies~1\safety~1\x64\safety~2.dll => c:\progra~2\movies~1\safety~1\x64\safety~2.dll File Not Found AppInit_DLLs: C:\PROGRA~3\FASTAN~1\FASTAN~2.DLL => C:\ProgramData\Fast And Safe\FastAndSafe_x64.dll [4447744 2013-12-29] () AppInit_DLLs-x32: c:\progra~2\movies~1\safety~1\safety~2.dll => "c:\progra~2\movies~1\safety~1\safety~2.dll" File Not Found IFEO\dropbox.exe: [Debugger] "C:\Users\Michael\Downloads\TueUp14v1401089Portle-De_AZAD\TuneUp 2014 v14.0.1000.89 Portable de_AZAD\App\TuneUp\TUAutoReactivator64.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Server4PC.lnk ShortcutTarget: Server4PC.lnk -> C:\Program Files (x86)\TechniSat DVB\bin\Server4PC.exe (TechniSat Digital, S.A.) Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) BootExecute: autocheck autochk * sdnclean64.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-3329511875-3327878259-967946423-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www2.delta-search.com/?babsrc=HP_ss&mntrId=CE8C0008C9F03D51&affID=123639&tsp=4993 HKU\S-1-5-21-3329511875-3327878259-967946423-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com HKU\S-1-5-21-3329511875-3327878259-967946423-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.b1.org/?bsrc=4hixr&chid=c167991 HKU\S-1-5-21-3329511875-3327878259-967946423-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.kfz-steuer.de/kfz-steuer_nutzfahrzeuge35t.phphxxp://tools.ogamecentral.com/defence-calculator HKU\S-1-5-21-3329511875-3327878259-967946423-1000\Software\Microsoft\Internet Explorer\Main,Start Page Before = hxxp://uni2.xorbit.de/frames.php URLSearchHook: HKLM-x32 - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.) URLSearchHook: HKU\S-1-5-21-3329511875-3327878259-967946423-1000 - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.) SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3329511875-3327878259-967946423-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3329511875-3327878259-967946423-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: TrustMediaViewerV1alpha4681 -> {2c7ce1be-99e0-481d-b4b9-a0a5dd6b8b2e} -> C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha4681\ie\TrustMediaViewerV1alpha4681x64.dll () BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKU\.DEFAULT -> No Name - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No File Toolbar: HKU\S-1-5-21-3329511875-3327878259-967946423-1000 -> No Name - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No File DPF: HKLM-x32 {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.9.0.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5-x64 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5-x64 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll" Tcpip\Parameters: [DhcpNameServer] 0.0.0.0 Tcpip\..\Interfaces\{DD2E5512-787B-414E-B38F-A568A0E3E1FD}: [NameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\iawhxesd.default FF DefaultSearchEngine,S: FF DefaultSearchUrl: FF SearchEngineOrder.1: Ask.com FF SearchEngineOrder.1,S: FF SelectedSearchEngine,S: FF Homepage: about:newtab FF Keyword.URL: hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=2&CUI=UN11021949200182446&UM=&q= FF NetworkProxy: "backup.ftp", "" FF NetworkProxy: "backup.ftp_port", 0 FF NetworkProxy: "backup.socks", "" FF NetworkProxy: "backup.socks_port", 0 FF NetworkProxy: "backup.ssl", "" FF NetworkProxy: "backup.ssl_port", 0 FF NetworkProxy: "ftp", "195.40.6.43" FF NetworkProxy: "ftp_port", 3128 FF NetworkProxy: "http", "5.9.187.106" FF NetworkProxy: "http_port", 8080 FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "195.40.6.43" FF NetworkProxy: "socks_port", 3128 FF NetworkProxy: "ssl", "195.40.6.43" FF NetworkProxy: "ssl_port", 3128 FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3329511875-3327878259-967946423-1000: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-3329511875-3327878259-967946423-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Siedler 7\Data\Base\_Dbg\Bin\Release\orbit\npuplaypc.dll No File FF user.js: detected! => C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\iawhxesd.default\user.js FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\iawhxesd.default\searchplugins\Ask.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\Ask.xml FF Extension: BlockTheAds - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\iawhxesd.default\Extensions\6pns_a@aeyatboo-.edu [2014-01-31] FF Extension: Live HTTP Headers - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\iawhxesd.default\Extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [2014-02-20] FF Extension: DownloadHelper - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\iawhxesd.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-09-10] FF Extension: Block site - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\iawhxesd.default\Extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc} [2014-02-02] FF Extension: Alldebrid - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\iawhxesd.default\Extensions\alldebrid@alldebrid.com.xpi [2014-02-09] FF Extension: NoScript - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\iawhxesd.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-02-02] FF Extension: ReloadEvery - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\iawhxesd.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi [2014-02-20] FF Extension: Adblock Plus - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\iawhxesd.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-20] FF Extension: Greasemonkey - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\iawhxesd.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2014-12-08] FF Extension: QuickStores-Toolbar - C:\Program Files (x86)\Mozilla Firefox\extensions\quickstores@quickstores.de [2014-12-09] FF HKLM-x32\...\Firefox\Extensions: [ext@RichMediaViewV1release618.net] - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release618\ff FF Extension: Rich Media View - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release618\ff [2014-05-13] FF HKLM-x32\...\Firefox\Extensions: [ext@TrustMediaViewerV1alpha4681.net] - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha4681\ff FF Extension: Trust Media Viewer - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha4681\ff [2014-06-29] FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-12-06] FF HKU\S-1-5-21-3329511875-3327878259-967946423-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR Profile: C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Wallet) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-12] CHR Extension: (WOT) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\nphjeokkkbngjpiofnfpnafjeofjomfb [2013-09-11] CHR Extension: (BlockTheAds) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\oblhnadppkbopibejcpjhedfdmdbfjbo [2014-02-12] CHR Extension: (Media View) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojladjkipdojafpfdafpjmkbdpkolnlo [2014-04-19] CHR Extension: (CheapMe) - C:\ProgramData\faohpljmdfchbomgodgbkggabemgmfbg\ [2014-04-19] CHR HKLM-x32\...\Chrome\Extension: [adfcciiaijaiigalkpbogfidnpcneiom] - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha4681\ch\TrustMediaViewerV1alpha4681.crx [2014-06-26] CHR HKLM-x32\...\Chrome\Extension: [eiojbdhoalmaobpdnhbcbglchjgnbpdi] - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release618\ch\RichMediaViewV1release618.crx [2014-05-13] CHR HKLM-x32\...\Chrome\Extension: [hahpjplbmicfkmoccokbjejahjjpnena] - C:\Users\Michael\AppData\Local\B1E\B1Tool.crx [2013-02-17] CHR HKLM-x32\...\Chrome\Extension: [nphjeokkkbngjpiofnfpnafjeofjomfb] - C:\Users\Michael\AppData\LocalLow\WOT\CHROME\WOT.crx [2012-01-12] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 AntiVirFirewallService; C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe [1044784 2014-11-04] (Avira Operations GmbH & Co. KG) S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [805112 2014-12-04] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-04] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-04] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [992560 2014-12-04] (Avira Operations GmbH & Co. KG) R2 avmike; C:\Program Files\FRITZ!Fernzugang\avmike.exe [336248 2012-02-02] (AVM Berlin) S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-03] (Microsoft Corporation) R2 certsrv; C:\Program Files\FRITZ!Fernzugang\certsrv.exe [143736 2011-10-31] (AVM Berlin) S3 CrypKey License; C:\Windows\system32\crypserv.exe [126976 2011-10-19] (CrypKey (Canada) Ltd.) [File not signed] S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2013-08-22] (Microsoft Corporation) [File not signed] R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed] R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed] R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89352 2014-09-15] (Hewlett-Packard Company) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed] S2 mi-raysat_3dsmax2013_64; C:\Program Files\Autodesk\3ds Max 2013\NVIDIA\raysat_3dsmax2013_64server.exe [86016 2011-09-14] () [File not signed] R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed] R2 nwtsrv; C:\Program Files\FRITZ!Fernzugang\nwtsrv.exe [189304 2011-10-31] (AVM Berlin) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed] S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed] R2 USBS3S4Detection; C:\OEM\USBDECTION\USBS3S4Detection.exe [76320 2009-12-09] () S3 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [87728 2013-10-04] (Microsoft Corporation) R2 WOTUpdater; C:\Users\Michael\AppData\LocalLow\WOT\IE\WOTUpdater.exe [18432 2012-01-12] () [File not signed] S3 64af91bf; "C:\Windows\system32\rundll32.exe" "c:\progra~3\fastan~1\FastAndSafeSvc.dll",service S4 BstHdAndroidSvc; "C:\Program Files (x86)\BlueStacks\HD-Service.exe" BstHdAndroidSvc Android [X] S4 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [X] S4 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-03-05] () R3 avfwim; C:\Windows\System32\DRIVERS\avfwim.sys [114608 2013-01-25] (Avira GmbH) R1 avfwot; C:\Windows\System32\DRIVERS\avfwot.sys [141376 2013-01-25] (Avira GmbH) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-07] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-07] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG) S3 CEDRIVER60; C:\Program Files (x86)\Cheat Engine 6.1\dbk64.sys [50688 2011-06-12] () [File not signed] R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-08-04] (DT Soft Ltd) S2 dvdmmg; C:\Windows\SysWOW64\drivers\dvdmmg.sys [5504 2007-09-06] () [File not signed] S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-03-05] () R1 NetworkX; C:\Windows\System32\ckldrv.sys [30272 2010-03-19] () R3 NWIM; C:\Windows\System32\DRIVERS\avmnwim.sys [412024 2011-07-05] (AVM Berlin) R0 sfdrv01; C:\Windows\System32\drivers\sfdrv01.sys [75384 2009-02-03] (Protection Technology (StarForce)) R0 sfvfs02; C:\Windows\System32\drivers\sfvfs02.sys [107384 2007-02-08] (Protection Technology (StarForce)) R3 SKYNETU2C; C:\Windows\System32\DRIVERS\SkyNetU2C_AMD64.SYS [270424 2010-05-10] (TechniSat Digital, S.A.) R0 snapman378; C:\Windows\System32\DRIVERS\snman378.sys [237600 2014-12-21] (Acronis) R0 tdrpman124; C:\Windows\System32\DRIVERS\tdrpm124.sys [1547808 2014-12-21] (Acronis) U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] () R1 vmm; C:\Windows\system32\Treiber\vmm.sys [294248 2012-04-19] (Microsoft Corporation) S2 BstHdDrv; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [X] S3 OSFMount; \??\C:\Users\Michael\Downloads\Bluestacks RootEZ 32_64\bin\OSFMount.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2023-11-25 00:59 - 2023-11-25 00:59 - 00001023 _____ () C:\Users\Public\Desktop\Crazybump.lnk 2023-11-25 00:59 - 2023-11-25 00:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crazybump 2023-11-25 00:59 - 2023-11-25 00:59 - 00000000 ____D () C:\ProgramData\licensecb 2023-11-25 00:59 - 2023-11-25 00:59 - 00000000 ____D () C:\ProgramData\CrazyBump 2023-11-25 00:59 - 2013-03-26 01:11 - 00000000 ____D () C:\Users\Michael\AppData\Local\licensecb 2023-11-25 00:58 - 2023-11-25 00:58 - 00000000 ____D () C:\Users\Michael\AppData\Local\CrazyBump 2023-11-25 00:58 - 2023-11-25 00:58 - 00000000 ____D () C:\Program Files (x86)\Crazybump 2014-12-23 23:58 - 2014-12-23 23:59 - 00000000 ____D () C:\FRST 2014-12-23 19:39 - 2014-12-23 19:39 - 00000000 ____D () C:\Users\Michael\Documents\DVRemote 2014-12-23 01:19 - 2014-12-23 01:19 - 00000000 __SHD () C:\Users\Michael\AppData\Local\EmieBrowserModeList 2014-12-23 01:04 - 2014-12-23 01:04 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-12-23 01:04 - 2014-12-23 01:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-12-22 22:28 - 2014-12-22 22:28 - 00000000 ____D () C:\Program Files (x86)\CheapMe 2014-12-22 21:30 - 2014-12-22 21:30 - 00000000 ____D () C:\Users\Michael\.swt 2014-12-22 00:46 - 2014-12-22 00:46 - 00000033 _____ () C:\Users\Michael\Documents\erledigung.txt 2014-12-21 19:16 - 2014-12-21 19:16 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Acronis 2014-12-21 17:21 - 2014-12-21 17:21 - 00000000 ____D () C:\ProgramData\Acronis 2014-12-21 17:16 - 2014-12-21 17:16 - 01547808 _____ (Acronis) C:\Windows\system32\Drivers\tdrpm124.sys 2014-12-21 17:16 - 2014-12-21 17:16 - 00878624 _____ (Acronis) C:\Windows\system32\Drivers\timntr.sys 2014-12-21 17:16 - 2014-12-21 17:16 - 00237600 _____ (Acronis) C:\Windows\system32\Drivers\snman378.sys 2014-12-21 17:16 - 2014-12-21 17:16 - 00083488 _____ (Acronis) C:\Windows\system32\Drivers\tifsfilt.sys 2014-12-21 17:15 - 2014-12-21 17:15 - 00001103 _____ () C:\Users\Public\Desktop\Acronis True Image Home 2009.lnk 2014-12-21 17:15 - 2014-12-21 17:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis 2014-12-21 17:15 - 2014-12-21 17:15 - 00000000 ____D () C:\Program Files (x86)\Acronis 2014-12-21 14:58 - 2014-12-21 14:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ITefix 2014-12-20 23:11 - 2014-12-20 23:11 - 00000000 __SHD () C:\found.003 2014-12-18 12:05 - 2014-12-18 14:05 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\BoL 2014-12-17 19:06 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-12-17 19:06 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-12-17 00:56 - 2014-12-17 00:56 - 00000000 ____D () C:\ProgramData\FreeWorldApp 2014-12-16 23:43 - 2014-12-16 23:43 - 00000921 _____ () C:\Users\Michael\Desktop\Falco Freeware Website.lnk 2014-12-16 23:43 - 2011-07-19 03:05 - 00000046 _____ () C:\Program Files (x86)\Falco.url 2014-12-14 14:55 - 2014-12-14 14:55 - 00002850 _____ () C:\Users\Michael\AppData\Local\recently-used.xbel 2014-12-10 07:54 - 2014-12-23 20:44 - 00003382 _____ () C:\Windows\System32\Tasks\BackgroundContainer Startup Task 2014-12-10 02:24 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2014-12-10 02:24 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2014-12-10 02:24 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2014-12-10 02:24 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2014-12-10 02:24 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2014-12-10 02:24 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2014-12-10 02:24 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2014-12-10 02:24 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2014-12-10 02:24 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2014-12-10 02:24 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2014-12-09 20:45 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-12-09 20:45 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-12-09 20:45 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-12-09 20:45 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-12-09 20:45 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-12-09 20:45 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-12-09 20:45 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-12-09 20:45 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-12-09 20:45 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-12-09 20:45 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-12-09 20:45 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-12-09 20:45 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-12-09 20:45 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-12-09 20:45 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-12-09 20:45 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-12-09 20:45 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-12-09 20:45 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-12-09 20:45 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-12-09 20:45 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-12-09 20:45 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-12-09 20:45 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-12-09 20:45 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-12-09 20:45 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-12-09 20:45 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-12-09 20:45 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-12-09 20:45 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-12-09 20:45 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-12-09 20:45 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-12-09 20:45 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-12-09 20:45 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-12-09 20:45 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-12-09 20:45 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-12-09 20:45 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-12-09 20:45 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-12-09 20:45 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-12-09 20:45 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-12-09 20:45 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-12-09 20:45 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-12-09 20:45 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-12-09 20:45 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-12-09 20:45 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-12-09 20:45 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-12-09 20:45 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-12-09 20:45 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-12-09 20:45 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-12-09 20:45 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-12-09 20:45 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-12-09 20:45 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-12-09 20:45 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-12-09 20:45 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-12-09 20:45 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-12-09 20:45 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-12-09 20:45 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-12-09 20:45 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-12-09 20:21 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-12-09 20:21 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-12-09 20:12 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2014-12-09 20:03 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-12-09 20:03 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-12-09 20:03 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe 2014-12-09 20:03 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe 2014-12-09 20:03 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2014-12-09 20:03 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2014-12-09 20:03 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2014-12-09 20:03 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2014-12-09 20:03 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2014-12-09 20:03 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2014-12-09 20:03 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll 2014-12-09 20:03 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2014-12-09 20:03 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll 2014-12-09 20:03 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe 2014-12-09 10:41 - 2014-12-09 10:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-12-06 18:27 - 2014-12-06 18:27 - 00002171 _____ () C:\Users\Public\Desktop\HP Photosmart Essential 3.5.lnk 2014-12-06 18:26 - 2014-12-06 18:26 - 00001361 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\HP Solution Center.lnk 2014-12-06 18:26 - 2014-12-06 18:26 - 00001355 _____ () C:\Users\Public\Desktop\HP Solution Center.lnk 2014-12-06 18:26 - 2014-12-06 18:26 - 00001060 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR-Registrierung.lnk 2014-12-06 18:26 - 2014-12-06 18:26 - 00000000 ____D () C:\ProgramData\HP Product Assistant 2014-12-06 18:25 - 2014-12-06 18:25 - 00001193 _____ () C:\Users\Public\Desktop\Shop für HP Zubehör.lnk 2014-12-06 18:25 - 2014-12-06 18:25 - 00000000 ____D () C:\Windows\SysWOW64\spool 2014-12-06 14:29 - 2014-12-06 14:29 - 00001011 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat_com.lnk 2014-12-06 14:20 - 2014-12-06 14:20 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2014-12-06 14:20 - 2014-12-06 14:20 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\com.adobe.mauby 2014-12-06 14:17 - 2014-12-06 14:17 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant 2014-12-06 14:16 - 2014-12-06 14:16 - 00001047 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download Assistant.lnk 2014-12-06 14:16 - 2014-12-06 14:16 - 00001035 _____ () C:\Users\Public\Desktop\Adobe Download Assistant.lnk 2014-12-06 14:16 - 2014-12-06 14:16 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia 2014-12-06 14:16 - 2014-12-06 14:16 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia 2014-12-06 12:33 - 2014-12-06 12:33 - 00000000 ____D () C:\Program Files\Tracker Software 2014-12-06 10:39 - 2014-12-06 10:39 - 00000000 ____D () C:\Users\Michael\AppData\Local\Hewlett-Packard 2014-12-06 10:39 - 2014-12-06 10:39 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard 2014-12-05 23:22 - 2014-12-06 18:20 - 00245229 ____N () C:\Windows\hpoins19.dat.temp 2014-12-05 22:21 - 2014-12-05 22:21 - 00002008 _____ () C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk 2014-12-05 22:18 - 2014-12-05 22:18 - 00000328 _____ () C:\Users\Michael\Desktop\HP Druckerdiagnosetools.url 2014-12-04 21:13 - 2014-12-04 21:13 - 00002409 _____ () C:\Windows\COMBIT.LOG 2014-12-04 17:55 - 2014-12-16 12:37 - 08159232 _____ () C:\Users\Michael\Desktop\HV HU 2012 richtiges 2-Kontenmodell-Briefkastenaufteilung- a kt u e l l.hvd 2014-12-04 12:12 - 2014-12-04 18:03 - 00000000 ____D () C:\Hausverwalter 2014 ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-23 23:59 - 2012-04-02 20:34 - 01797524 _____ () C:\Windows\WindowsUpdate.log 2014-12-23 23:58 - 2014-02-10 10:27 - 00000000 ____D () C:\Users\Michael\Desktop\Neuer Ordner 2014-12-23 23:29 - 2012-05-05 11:46 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-12-23 22:45 - 2012-04-07 03:16 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Mozilla 2014-12-23 22:27 - 2013-09-06 19:14 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\TS3Client 2014-12-23 21:30 - 2014-02-02 01:31 - 00000000 ____D () C:\Users\Michael\AppData\Local\SwvUpdater 2014-12-23 21:17 - 2013-02-17 12:46 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\B1Toolbar 2014-12-23 21:16 - 2013-10-05 23:42 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Adobe64x 2014-12-23 20:52 - 2009-07-14 05:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-23 20:52 - 2009-07-14 05:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-23 20:51 - 2012-04-03 06:26 - 00701570 _____ () C:\Windows\system32\perfh007.dat 2014-12-23 20:51 - 2012-04-03 06:26 - 00150492 _____ () C:\Windows\system32\perfc007.dat 2014-12-23 20:51 - 2009-07-14 06:13 - 01622164 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-23 20:44 - 2014-02-02 01:31 - 00000374 _____ () C:\Windows\Tasks\AmiUpdXp.job 2014-12-23 20:44 - 2014-01-08 00:17 - 00030190 _____ () C:\Windows\setupact.log 2014-12-23 20:44 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-23 20:43 - 2014-07-16 11:39 - 00033990 _____ () C:\Windows\errord.log 2014-12-23 19:56 - 2012-04-21 18:09 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\vlc 2014-12-23 13:42 - 2012-05-01 17:40 - 02209280 ___SH () C:\Users\Michael\Documents\Thumbs.db 2014-12-23 13:03 - 2013-02-11 22:26 - 00493568 ___SH () C:\Users\Michael\Thumbs.db 2014-12-23 12:35 - 2012-04-17 22:56 - 00000000 ___HD () C:\Users\Michael\Documents\Eigene virtuelle Computer 2014-12-23 12:19 - 2014-03-27 08:01 - 00000000 ____D () C:\Users\Michael\Downloads\FirefoxPortable 2014-12-23 02:07 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-12-23 01:57 - 2014-01-08 08:04 - 00896736 _____ () C:\Windows\PFRO.log 2014-12-23 01:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-12-23 01:05 - 2012-05-04 18:52 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Skype 2014-12-23 01:04 - 2011-03-16 13:51 - 00000000 ____D () C:\ProgramData\Skype 2014-12-23 00:00 - 2012-04-02 22:11 - 00000000 ____D () C:\Users\Michael 2014-12-22 22:56 - 2014-01-31 05:23 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-12-22 22:52 - 2013-12-31 02:31 - 00000000 ____D () C:\ProgramData\CheapMe 2014-12-22 22:46 - 2013-04-13 10:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VSO 2014-12-22 22:46 - 2013-04-13 10:42 - 00000055 _____ () C:\Users\Michael\AppData\Roaming\pcouffin.log 2014-12-22 22:46 - 2013-04-13 10:42 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Vso 2014-12-22 22:45 - 2013-07-15 03:38 - 00000000 ____D () C:\Program Files (x86)\NCH Software 2014-12-22 22:45 - 2013-04-13 10:42 - 00099384 _____ () C:\Users\Michael\AppData\Roaming\inst.exe 2014-12-22 22:45 - 2013-04-13 10:42 - 00082816 _____ (VSO Software) C:\Users\Michael\AppData\Roaming\pcouffin.sys 2014-12-22 22:45 - 2013-04-13 10:42 - 00007859 _____ () C:\Users\Michael\AppData\Roaming\pcouffin.cat 2014-12-22 22:45 - 2013-03-21 17:39 - 00000000 ____D () C:\Users\Michael\AppData\Local\Unity 2014-12-22 22:38 - 2014-04-25 21:15 - 00000000 ____D () C:\Program Files (x86)\MediaBuzzV1 2014-12-22 22:38 - 2014-03-23 13:54 - 00000000 ____D () C:\Program Files (x86)\MediaWatchV1 2014-12-22 22:38 - 2014-02-27 23:54 - 00000000 ____D () C:\Program Files (x86)\MediaViewV1 2014-12-22 22:38 - 2014-02-24 08:54 - 00000000 ____D () C:\Program Files (x86)\MediaViewerV1 2014-12-22 22:38 - 2014-02-17 23:54 - 00000000 ____D () C:\Program Files (x86)\MediaPlayerV1 2014-12-22 22:37 - 2014-01-06 18:15 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\inkscape 2014-12-22 22:35 - 2014-01-03 01:02 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GitHub, Inc 2014-12-22 22:35 - 2013-11-10 19:14 - 00000000 ____D () C:\Users\Michael\AppData\Local\Deployment 2014-12-22 22:32 - 2012-07-20 19:49 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\GameRanger 2014-12-22 22:32 - 2011-03-16 13:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer GameZone 2014-12-22 22:32 - 2011-03-16 13:38 - 00000000 ____D () C:\Program Files (x86)\Acer GameZone 2014-12-22 22:32 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-12-22 22:31 - 2012-05-13 13:53 - 00000000 ____D () C:\Program Files (x86)\Fraps 2014-12-22 22:30 - 2014-03-03 10:09 - 00000000 ____D () C:\Program Files (x86)\FreeTime 2014-12-22 22:29 - 2012-09-12 15:32 - 00000000 ____D () C:\ProgramData\Electronic Arts 2014-12-22 22:29 - 2012-08-04 23:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus 2014-12-22 22:29 - 2012-08-04 23:20 - 00000000 ____D () C:\Program Files (x86)\DivX 2014-12-22 22:29 - 2012-08-04 23:18 - 00000000 ____D () C:\ProgramData\DivX 2014-12-22 22:28 - 2013-12-31 02:31 - 00000000 ____D () C:\ProgramData\ebeb058aafa58756 2014-12-22 22:28 - 2013-02-23 15:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAXON 2014-12-22 22:27 - 2013-08-12 22:30 - 00000000 ____D () C:\Program Files\Lurkers_Battle_of_Yavin_v1.3.1 2014-12-22 22:26 - 2014-02-01 21:05 - 00000000 ____D () C:\Program Files (x86)\ElcomSoft 2014-12-22 22:26 - 2013-04-17 19:54 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Allegorithmic 2014-12-22 22:26 - 2011-03-16 14:19 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-12-22 22:20 - 2012-11-23 19:22 - 00000000 ____D () C:\ProgramData\eMule 2014-12-22 22:19 - 2013-05-19 17:18 - 00000000 ____D () C:\Users\Michael\AppData\Local\JDownloader v2.0 2014-12-22 22:19 - 2012-05-05 23:50 - 00000000 ____D () C:\Program Files (x86)\Armagetron Advanced 2014-12-22 22:09 - 2013-04-17 19:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Allegorithmic 2014-12-22 21:34 - 2012-04-07 03:22 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Azureus 2014-12-22 21:27 - 2014-02-18 11:38 - 00000000 ____D () C:\Users\Michael\Documents\Vorgarten Planung neu nach Maß 2014-12-22 20:26 - 2012-11-04 17:57 - 00000000 ____D () C:\Users\Michael\VirtualBox VMs 2014-12-22 18:10 - 2014-07-16 11:39 - 00096596 _____ () C:\Windows\error.log 2014-12-22 18:10 - 2009-07-14 03:34 - 00000533 _____ () C:\Windows\win.ini 2014-12-22 18:06 - 2014-10-27 07:59 - 00000000 ____D () C:\Windows\pss 2014-12-22 10:59 - 2012-06-23 14:48 - 00000000 ____D () C:\Users\Michael\dwhelper 2014-12-22 07:28 - 2012-06-11 22:32 - 00000000 ____D () C:\Users\Michael\Desktop\eclipse 2014-12-21 13:49 - 2012-04-22 12:58 - 00000000 ____D () C:\SFIRM32 2014-12-21 01:07 - 2014-05-13 23:57 - 00000000 ____D () C:\Users\Michael\Desktop\vbox 2014-12-20 02:54 - 2013-11-27 22:02 - 00000484 _____ () C:\Windows\Tasks\SDMsgUpdate (Local).job 2014-12-20 02:54 - 2013-11-27 22:02 - 00000476 _____ () C:\Windows\Tasks\SDMsgUpdate (TE).job 2014-12-18 19:04 - 2014-03-30 15:46 - 00000000 ____D () C:\Simba 2014-12-17 00:56 - 2013-08-11 09:49 - 00000000 ____D () C:\ProgramData\InstallMate 2014-12-16 22:49 - 2014-01-18 11:21 - 00000000 ____D () C:\Windows\system32\FxsTmp 2014-12-16 13:16 - 2012-04-17 20:13 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\SoftGrid Client 2014-12-16 12:52 - 2012-05-20 18:16 - 00000000 ____D () C:\Hausverwalter 2012 2014-12-15 19:54 - 2012-04-23 01:13 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-12-15 19:54 - 2012-04-23 01:13 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-12-14 03:03 - 2012-05-26 10:45 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-12-14 03:03 - 2012-04-23 01:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-12-14 03:01 - 2013-04-28 15:06 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-12-12 23:06 - 2012-04-29 15:46 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\HpUpdate 2014-12-10 16:29 - 2012-05-05 11:46 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-12-10 16:29 - 2012-05-05 11:46 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-12-10 16:29 - 2012-05-05 11:46 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-12-10 07:45 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-12-09 19:13 - 2012-06-07 10:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-12-07 11:47 - 2012-06-11 22:35 - 00000000 ____D () C:\Users\Michael\AppData\Local\Eclipse 2014-12-07 09:22 - 2009-07-14 05:45 - 00445816 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-12-06 18:31 - 2012-06-25 16:46 - 00115296 _____ () C:\Users\Michael\AppData\Local\GDIPFONTCACHEV1.DAT 2014-12-06 18:28 - 2012-04-22 13:29 - 00245221 _____ () C:\Windows\hpoins19.dat 2014-12-06 18:28 - 2012-04-22 12:11 - 00010288 _____ () C:\ProgramData\hpzinstall.log 2014-12-06 18:27 - 2012-04-22 13:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2014-12-06 18:26 - 2012-04-22 13:26 - 00000000 ____D () C:\ProgramData\HP 2014-12-06 18:25 - 2012-04-22 13:29 - 00000000 ____D () C:\Program Files (x86)\HP 2014-12-06 14:14 - 2012-04-02 22:48 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Adobe 2014-12-06 14:13 - 2013-12-18 13:17 - 00000000 ____D () C:\Users\Michael\AppData\Local\gtk-2.0 2014-12-06 13:49 - 2012-04-16 23:37 - 00000000 ____D () C:\Users\Michael\AppData\Local\Adobe 2014-12-06 13:24 - 2012-05-13 12:39 - 00000000 ____D () C:\SFIRM32_Datensicherungen 2014-12-06 11:52 - 2012-09-21 13:53 - 00000000 ____D () C:\Program Files (x86)\PDF Editor 3 2014-12-06 11:45 - 2012-07-20 12:37 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Free Download Manager 2014-12-02 09:32 - 2014-05-21 20:00 - 00000000 ____D () C:\Users\Michael\Desktop\Neuer Ordner (3) ZeroAccess: C:\Windows\Installer\{3a50d7d7-c3ee-f7ec-43e8-ec0552c84860} C:\Windows\Installer\{3a50d7d7-c3ee-f7ec-43e8-ec0552c84860}\@ C:\Windows\Installer\{3a50d7d7-c3ee-f7ec-43e8-ec0552c84860}\U\00000004.@ C:\Windows\Installer\{3a50d7d7-c3ee-f7ec-43e8-ec0552c84860}\U\00000008.@ C:\Windows\Installer\{3a50d7d7-c3ee-f7ec-43e8-ec0552c84860}\U\80000000.@ C:\Windows\Installer\{3a50d7d7-c3ee-f7ec-43e8-ec0552c84860}\U\80000064.@ Files to move or delete: ==================== C:\ProgramData\BB610C4B6B88mpsd43.dat C:\ProgramData\go_0molg.pad Some content of TEMP: ==================== C:\Users\Michael\AppData\Local\Temp\AcDeltree.exe C:\Users\Michael\AppData\Local\Temp\avgnt.exe C:\Users\Michael\AppData\Local\Temp\eon_uninst_101.exe C:\Users\Michael\AppData\Local\Temp\proxy_vole2951186448753120147.dll C:\Users\Michael\AppData\Local\Temp\Runner.exe C:\Users\Michael\AppData\Local\Temp\vmpremov.exe C:\Users\Michael\AppData\Local\Temp\_is4DE5.exe C:\Users\Michael\AppData\Local\Temp\_isF95F.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-15 04:21 ==================== End Of Log ============================ --- --- --- Addition.txt war zuviel, hab ich angehaengt. Hoffe aus dem Wust laesst sich was ablesen lg laserjet |
24.12.2014, 00:20 | #4 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Lösung: Windows 7 - Internet (im Browser) geht nicht, nslookup funktioniert ebenfalls nichtZitat:
Lesestoff: Rootkit-Warnung Dein Computer wurde mit einem besonderen Schädling infiziert, der sich vor herkömmlichen Virenscannern und dem Betriebssystem selbst verstecken kann. Zusätzlich hat so ein Schädling meist auch Backdoor-Funktionalität, reißt also ganz bewußt Löcher durch alle Schutzmaßnahmen, damit er weiteren Schadcode nachladen oder die Daten, die er so sammelt, an die "bösen Jungs" weiterleiten kann. Was heißt das jetzt für dich?
__________________ Logfiles bitte immer in CODE-Tags posten |
24.12.2014, 00:29 | #5 |
| Wie Windows 7 - Internet (im Browser) geht nicht, nslookup funktioniert ebenfalls nicht Hi oh das haette ich jetzt nicht erwartet, wie erkennt man denn an der Zahlen/Buchstaben Abfolge Schadsoftware? Da ich sowieso schon vor dem Schritt Neuinstallation stand, mache ich dies jetzt auch. Danke nochmals fuer die schnelle und kompetente Hilfe. Edit: Was meinst du eigentlich mit dem Punkt, dass sich die Daten "jeder" ansehen konnte. Gruss laserjet Geändert von laserjet (24.12.2014 um 00:43 Uhr) Grund: Nachfrage, im vorherigen Post vergessen |
24.12.2014, 00:44 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Wo Windows 7 - Internet (im Browser) geht nicht, nslookup funktioniert ebenfalls nicht Lösung! "Jeder" steht ja in Anführungszeichen. Damit wird jeder gemeint, der Kontrolle zB über ein Botnetz hat, in dem sich dein Rechner wer weiß wie lange schon befinden könnte.
__________________ --> Windows 7 - Internet (im Browser) geht nicht, nslookup funktioniert ebenfalls nicht |
24.12.2014, 00:50 | #7 |
| Windows 7 - Internet (im Browser) geht nicht, nslookup funktioniert ebenfalls nicht Ok, danke nochmals fuer die Hilfe |
Themen zu Windows 7 - Internet (im Browser) geht nicht, nslookup funktioniert ebenfalls nicht |
aufsetzen, beendet, browser, center, code, fehlermeldung, forum, fritzbox, funktioniert, handy, home, internet, langsam, netzwerk, nicht mehr, nslookup geht nicht, ping geht, problem, programme, rechner, router, spiele, starten, suche, windows, windows 7, wlan, zugriff |