Nabend,
also folgendes:
Ich komme nach wie vor nicht ins netz mit dem Firefox und auch nicht Chrome. Allerdings komme ich nun mit dem IE rein, aber trzdm kann z.B Avira setup nicht ins Netz, komme per LAN und WLAN mit dem IE rein.
EDIT: Firefox schreibt kein hxxp:// vor die Seite, was denke ich das Problem ist, auch wenn ich es manuell eingebe schreibt Firefox zum Beispeil nur "www.google.de". AUch das Drucken über den WLAN Drucker geht, ich sehe alle Rechner im Netzwerk, also liegt das PRoblem wohl wahrscheinlich an Firefox und Chrome, aber leider auch eine Neuinstallation von Firefox ändert nichts. AVIRA Update kommt auch nicht rein, hm ich bin jetzt ehrlich gesgat überfragt.
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-06-2013
Ran by Nico (administrator) on 24-06-2013 15:20:03
Running from C:\Users\Nico\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
() C:\Windows\system32\services.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\ProgramData\Browser Manager\2.6.1339.144\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
() C:\ProgramData\Browser Manager\2.6.1339.144\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
() C:\Users\Nico\AppData\LocalLow\StumbleUpon\IE\StumbleUponUpdater.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
(Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11785832 2011-03-10] (Realtek Semiconductor)
HKLM\...\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [4526 2010-11-29] ()
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2280232 2010-07-29] (Synaptics Incorporated)
HKLM\...\Run: [Power Management] C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [1831528 2011-05-10] (Acer Incorporated)
HKLM\...\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [CD- und DVD-Sharing] "C:\Program Files\CD- und DVD-Sharing\ODSAgent.exe" [582256 2010-04-16] ()
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-06] (Adobe Systems Incorporated)
HKCU\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [x]
HKCU\...\Run: [AdobeBridge] [x]
HKCU\...\Run: [Google Update] "C:\Users\Nico\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-08-26] (Google Inc.)
HKCU\...\Run: [Facebook Update] "C:\Users\Nico\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2013-01-04] (Facebook Inc.)
MountPoints2: {ba655669-f6a7-11e1-8ea2-b870f487d6cf} - G:\Autorun.exe
HKLM-x32\...\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [336384 2011-05-24] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" [129648 2011-09-23] (VMware, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345312 2013-05-07] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Packard Bell\Screensaver\run_Packard Bell.exe /default [154144 2010-07-29] ()
AppInit_DLLs-x32: c:\progra~3\browse~1\261339~1.144\{16cdf~1\browse~1.dll [2521552 2013-06-03] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = google.de
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://packardbell.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://packardbell.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
URLSearchHook: (No Name) - {64ead72b-ffd4-4e01-aa3a-4c71665d73e4} - No File
URLSearchHook: (No Name) - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - No File
HKCU SearchScopes: DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=111304&tt=031012_ccp_4012_8&babsrc=SP_ss&mntrId=2cba4256000000000000d0df9a96774e
SearchScopes: HKCU - {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=rbox&toolbarid=adawaretb&u=23B62FAA28623C9359D0A45077CD7277&q={searchTerms}
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\PROGRA~2\IDM\QUICKF~1\PlugIns\IEHelp.dll (IDM)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM-x32 - DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog9 01 C:\Windows\System32\socketspy.dll File Not found ()
Winsock: Catalog9 02 C:\Windows\System32\socketspy.dll File Not found ()
Winsock: Catalog9 03 mswsock.dll File Not found ()
Winsock: Catalog9 04 mswsock.dll File Not found ()
Winsock: Catalog9 05 mswsock.dll File Not found ()
Winsock: Catalog9 06 mswsock.dll File Not found ()
Winsock: Catalog9 07 mswsock.dll File Not found ()
Winsock: Catalog9 08 mswsock.dll File Not found ()
Winsock: Catalog9 09 mswsock.dll File Not found ()
Winsock: Catalog9 10 mswsock.dll File Not found ()
Winsock: Catalog9 11 mswsock.dll File Not found ()
Winsock: Catalog9 12 mswsock.dll File Not found ()
Winsock: Catalog9 13 C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll [346736] (VMware, Inc.)
Winsock: Catalog9 14 C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll [346736] (VMware, Inc.)
Winsock: Catalog9 15 C:\Windows\System32\socketspy.dll File Not found ()
Winsock: Catalog5-x64 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog9-x64 01 C:\Windows\System32\socketspy-64.dll [450048] (Ufasoft)
Winsock: Catalog9-x64 02 C:\Windows\System32\socketspy-64.dll [450048] (Ufasoft)
Winsock: Catalog9-x64 03 mswsock.dll File Not found ()
Winsock: Catalog9-x64 04 mswsock.dll File Not found ()
Winsock: Catalog9-x64 05 mswsock.dll File Not found ()
Winsock: Catalog9-x64 06 mswsock.dll File Not found ()
Winsock: Catalog9-x64 07 mswsock.dll File Not found ()
Winsock: Catalog9-x64 08 mswsock.dll File Not found ()
Winsock: Catalog9-x64 09 mswsock.dll File Not found ()
Winsock: Catalog9-x64 10 mswsock.dll File Not found ()
Winsock: Catalog9-x64 11 mswsock.dll File Not found ()
Winsock: Catalog9-x64 12 mswsock.dll File Not found ()
Winsock: Catalog9-x64 13 C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll [446576] (VMware, Inc.)
Winsock: Catalog9-x64 14 C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll [446576] (VMware, Inc.)
Winsock: Catalog9-x64 15 C:\Windows\System32\socketspy-64.dll [450048] (Ufasoft)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\uhmxne3e.Normales surfen
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.3 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pages.tvunetworks.com/WebPlayer - C:\Windows\system32\TVUAx\npTVUAx.dll No File
FF Plugin-x32: @protectdisc.com/NPMPDRM - C:\Program Files (x86)\Common Files\mpDRM\NPMPDRM.dll ( )
FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Lavasoft Search Plugin - C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\uhmxne3e.Normales surfen\Extensions\jid1-yZwVFzbsyfMrqQ@jetpack
FF Extension: DVDVideoSoftTB DE - C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\uhmxne3e.Normales surfen\Extensions\{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}
FF Extension: Yahoo! Toolbar - C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\uhmxne3e.Normales surfen\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF Extension: Adblock Plus - C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\uhmxne3e.Normales surfen\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF Extension: No Name - C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\uhmxne3e.Normales surfen\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
FF Extension: No Name - C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\uhmxne3e.Normales surfen\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
Chrome:
=======
CHR Extension: () - C:\Users\Nico\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhphemoobgnikcoofkgackkaimpfmenm\10.14.250.13_0
CHR Extension: () - C:\Users\Nico\AppData\Local\Google\Chrome\User Data\Default\Extensions\hempmfkijmahkaddljkmchcmjbojoedl\2.3.19.11_0
CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\Nico\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0
CHR Extension: (StumbleUpon) - C:\Users\Nico\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgifblbjgdjhcelbanblbhkhmbnnmhfg\3.97.1_0
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86752 2013-03-28] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110816 2013-03-28] (Avira Operations GmbH & Co. KG)
R2 Browser Manager; C:\ProgramData\Browser Manager\2.6.1339.144\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe [3085264 2013-06-03] ()
R2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [872552 2011-05-10] (Acer Incorporated)
R2 GREGService; C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe [39528 2011-01-18] (Acer Incorporated)
R2 Live Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [255376 2012-04-05] (Acer Incorporated)
R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2013-03-24] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.)
S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation)
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
R2 StumbleUponUpdater; C:\Users\Nico\AppData\LocalLow\StumbleUpon\IE\StumbleUponUpdater.exe [18432 2011-11-22] ()
S3 ufad-ws60; C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe [191024 2010-08-19] (VMware, Inc.)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-03-28] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-03-28] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-28] (Avira Operations GmbH & Co. KG)
R2 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [560184 2012-09-04] (Duplex Secure Ltd.)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [117040 2011-07-19] (Oracle Corporation)
R2 vstor2-ws60; C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys [32816 2010-08-19] (VMware, Inc.)
R2 vstor2-ws60; C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys [32816 2010-08-19] (VMware, Inc.)
S1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-24 14:20 - 2013-06-24 15:18 - 00000000 ____D C:\FRST
2013-06-24 14:19 - 2013-06-24 14:19 - 01931364 ____A (Farbar) C:\Users\Nico\Downloads\FRST64.exe
2013-06-23 13:01 - 2013-06-23 13:31 - 89977796 ____A C:\Users\Nico\Downloads\D.DX.12.13.part8.rar
2013-06-23 12:17 - 2013-06-24 15:17 - 93616457 ____A C:\Users\Nico\Downloads\D.DX.12.13.part7.rar.part
2013-06-23 11:21 - 2013-06-23 11:21 - 00000000 ____D C:\Users\Nico\AppData\Local\{1D2962E8-3E0C-42C5-A949-111D92C99983}
2013-06-22 17:29 - 2013-06-22 17:29 - 00262144 ____A C:\Windows\Minidump\062213-26738-01.dmp
2013-06-22 13:45 - 2013-06-22 17:29 - 580052725 ____A C:\Windows\MEMORY.DMP
2013-06-22 13:45 - 2013-06-22 17:29 - 00000000 ____D C:\Windows\Minidump
2013-06-22 13:45 - 2013-06-22 13:45 - 00262144 ____A C:\Windows\Minidump\062213-29936-01.dmp
2013-06-22 12:41 - 2013-06-22 12:41 - 00000392 ____A C:\Users\Nico\defogger_reenable
2013-06-22 12:29 - 2013-06-24 14:33 - 00000000 ____D C:\Users\Nico\Desktop\Gegen Virus
2013-06-22 12:21 - 2013-06-23 12:16 - 104857600 ____A C:\Users\Nico\Downloads\D.DX.12.13.part4.rar
2013-06-21 14:21 - 2013-06-21 14:21 - 00000000 ____D C:\Users\Nico\Downloads\SpybotPortable
2013-06-21 14:19 - 2013-06-21 14:20 - 57524944 ____A (PortableApps.com) C:\Users\Nico\Downloads\SpybotPortable_2.1.paf.exe
2013-06-21 14:14 - 2013-06-21 14:14 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Nico\Downloads\mbam-setup-1.75.0.1300.exe
2013-06-21 13:57 - 2013-06-24 15:17 - 00000672 ____A C:\Windows\setupact.log
2013-06-21 13:57 - 2013-06-21 13:57 - 00000000 ____A C:\Windows\setuperr.log
2013-06-21 13:56 - 2013-06-21 13:56 - 00000824 ____A C:\Windows\PFRO.log
2013-06-20 22:39 - 2013-06-20 22:39 - 00000019 ____A C:\Users\Nico\Desktop\in 1,5 aus.cmd
2013-06-20 22:28 - 2013-06-20 22:28 - 00000000 ____D C:\Windows\Profiles\Nico
2013-06-20 22:16 - 2013-06-20 22:30 - 00000000 ____D C:\Program Files (x86)\x264 Video Codec
2013-06-20 22:15 - 2013-06-22 11:30 - 00000000 ____D C:\Users\Nico\AppData\Roaming\vlc
2013-06-20 22:15 - 2013-06-20 22:15 - 00000000 ____D C:\Program Files\VideoLAN
2013-06-20 22:12 - 2013-06-20 22:12 - 23229256 ____A C:\Users\Nico\Downloads\vlc-2.0.7-win64.exe
2013-06-20 22:07 - 2013-06-20 22:42 - 104857600 ____A C:\Users\Nico\Downloads\D.DX.12.13.part3.rar
2013-06-20 20:02 - 2013-06-20 20:02 - 00000000 ____D C:\Users\Nico\AppData\Roaming\File Scout
2013-06-20 20:02 - 2013-05-28 15:05 - 00163328 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerUpdateService.exe
2013-06-20 19:41 - 2013-06-20 19:41 - 01125456 ____A (BitTorrent Inc.) C:\Users\Nico\Downloads\BitTorrent.exe
2013-06-20 19:21 - 2013-06-20 19:21 - 00000000 ____D C:\Users\Nico\AppData\Local\{F9859730-4A8B-4935-96F9-B5159219BD09}
2013-06-18 16:39 - 2013-06-18 16:39 - 00000000 ____D C:\Users\Nico\AppData\Local\{A3B9C5E6-D87F-4DB1-AA34-8258F0A6D317}
2013-06-18 15:22 - 2013-06-18 15:22 - 00000000 ____D C:\Users\Default\Documents\Visual Studio 2008
2013-06-18 15:22 - 2013-06-18 15:22 - 00000000 ____D C:\Users\Default User\Documents\Visual Studio 2008
2013-06-17 21:27 - 2013-06-17 21:27 - 00000000 ____D C:\ProgramData\VS
2013-06-17 21:25 - 2013-06-17 21:25 - 00000000 ____D C:\fbabd28d772111eec99e8982
2013-06-17 18:08 - 2013-06-17 18:08 - 00001795 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 18:07 - 2013-06-17 18:08 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-17 18:07 - 2013-06-17 18:08 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 18:07 - 2013-06-17 18:07 - 00000000 ____D C:\Program Files\iPod
2013-06-14 14:31 - 2013-06-12 21:15 - 00000101 ____A C:\Users\Nico\Downloads\ind-scary.nfo
2013-06-14 14:30 - 2013-06-14 14:30 - 00000466 ____A C:\Users\Nico\Desktop\DATA (D) - Verknüpfung.lnk
2013-06-13 17:22 - 2013-06-13 21:27 - 731594045 ____A C:\Users\Nico\Downloads\342fdsfssmo5.rar
2013-06-12 15:53 - 2013-05-17 06:05 - 17824768 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-12 15:53 - 2013-05-17 05:27 - 10926080 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-12 15:53 - 2013-05-17 05:09 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 15:53 - 2013-05-17 05:02 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 15:53 - 2013-05-17 05:02 - 01346560 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-12 15:53 - 2013-05-17 05:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-12 15:53 - 2013-05-17 05:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-12 15:53 - 2013-05-17 04:58 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-12 15:53 - 2013-05-17 04:56 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-12 15:53 - 2013-05-17 04:56 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-12 15:53 - 2013-05-17 04:55 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-12 15:53 - 2013-05-17 04:54 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 15:53 - 2013-05-17 04:53 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-12 15:53 - 2013-05-17 04:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-12 15:53 - 2013-05-17 04:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-12 15:53 - 2013-05-17 04:46 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-12 15:53 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-12 15:53 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-12 15:53 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 15:53 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 15:53 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-12 15:53 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-06-12 15:53 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-06-12 15:53 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-12 15:53 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 15:53 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-06-12 15:53 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-06-12 15:53 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 15:53 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-12 15:53 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-06-12 15:53 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-12 15:53 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-12 14:50 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-12 14:50 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-12 14:50 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-12 14:50 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-12 14:50 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-12 14:50 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-12 14:50 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-12 14:50 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-12 14:50 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-12 14:50 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-12 14:50 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 14:50 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 14:50 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-12 14:50 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 14:50 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-11 13:55 - 2013-06-11 13:55 - 00000000 ____D C:\Users\Nico\AppData\Local\{4FC71047-D567-49F4-BF1A-EE9BEC968BA8}
2013-06-08 18:41 - 2013-06-08 18:41 - 00000000 ____D C:\Users\Nico\AppData\Local\{D8BDBDB0-6714-480D-91FC-2F101077576A}
2013-06-05 15:41 - 2013-06-05 15:41 - 00001036 ____A C:\Users\Nico\Desktop\ILS-SimV4.exe - Verknüpfung.lnk
==================== One Month Modified Files and Folders =======
2013-06-24 15:18 - 2013-06-24 14:20 - 00000000 ____D C:\FRST
2013-06-24 15:18 - 2012-01-13 17:01 - 00000000 ____D C:\ProgramData\VMware
2013-06-24 15:17 - 2013-06-23 12:17 - 93616457 ____A C:\Users\Nico\Downloads\D.DX.12.13.part7.rar.part
2013-06-24 15:17 - 2013-06-21 13:57 - 00000672 ____A C:\Windows\setupact.log
2013-06-24 15:17 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-24 15:15 - 2012-04-21 12:08 - 00000000 ____D C:\Users\Nico\AppData\Roaming\Skype
2013-06-24 14:33 - 2013-06-22 12:29 - 00000000 ____D C:\Users\Nico\Desktop\Gegen Virus
2013-06-24 14:30 - 2012-08-29 20:45 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-24 14:30 - 2012-08-26 15:03 - 00001116 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4147683108-3158561192-3553953681-1000UA.job
2013-06-24 14:24 - 2009-07-14 06:45 - 00016752 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-24 14:24 - 2009-07-14 06:45 - 00016752 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-24 14:20 - 2011-08-18 13:46 - 00765954 ____A C:\Windows\System32\perfh007.dat
2013-06-24 14:20 - 2011-08-18 13:46 - 00174834 ____A C:\Windows\System32\perfc007.dat
2013-06-24 14:20 - 2009-07-14 07:13 - 01808082 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-24 14:19 - 2013-06-24 14:19 - 01931364 ____A (Farbar) C:\Users\Nico\Downloads\FRST64.exe
2013-06-23 21:00 - 2012-08-26 15:03 - 00001064 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4147683108-3158561192-3553953681-1000Core.job
2013-06-23 20:51 - 2013-01-04 00:04 - 00000924 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4147683108-3158561192-3553953681-1000UA.job
2013-06-23 13:31 - 2013-06-23 13:01 - 89977796 ____A C:\Users\Nico\Downloads\D.DX.12.13.part8.rar
2013-06-23 13:24 - 2012-06-06 21:16 - 00000000 ____D C:\Users\Nico\AppData\Roaming\Spotify
2013-06-23 12:16 - 2013-06-22 12:21 - 104857600 ____A C:\Users\Nico\Downloads\D.DX.12.13.part4.rar
2013-06-23 11:48 - 2011-12-19 17:33 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-06-23 11:21 - 2013-06-23 11:21 - 00000000 ____D C:\Users\Nico\AppData\Local\{1D2962E8-3E0C-42C5-A949-111D92C99983}
2013-06-22 17:29 - 2013-06-22 17:29 - 00262144 ____A C:\Windows\Minidump\062213-26738-01.dmp
2013-06-22 17:29 - 2013-06-22 13:45 - 580052725 ____A C:\Windows\MEMORY.DMP
2013-06-22 17:29 - 2013-06-22 13:45 - 00000000 ____D C:\Windows\Minidump
2013-06-22 13:45 - 2013-06-22 13:45 - 00262144 ____A C:\Windows\Minidump\062213-29936-01.dmp
2013-06-22 13:33 - 2011-12-14 09:59 - 00000000 ____D C:\Users\Nico\AppData\Local\CrashDumps
2013-06-22 12:41 - 2013-06-22 12:41 - 00000392 ____A C:\Users\Nico\defogger_reenable
2013-06-22 12:41 - 2011-12-08 15:43 - 00000000 ____D C:\users\Nico
2013-06-22 11:30 - 2013-06-20 22:15 - 00000000 ____D C:\Users\Nico\AppData\Roaming\vlc
2013-06-22 11:18 - 2013-03-19 22:58 - 00629248 __ASH C:\Users\Nico\Desktop\Thumbs.db
2013-06-21 23:08 - 2013-01-04 00:03 - 00000902 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4147683108-3158561192-3553953681-1000Core.job
2013-06-21 14:21 - 2013-06-21 14:21 - 00000000 ____D C:\Users\Nico\Downloads\SpybotPortable
2013-06-21 14:20 - 2013-06-21 14:19 - 57524944 ____A (PortableApps.com) C:\Users\Nico\Downloads\SpybotPortable_2.1.paf.exe
2013-06-21 14:14 - 2013-06-21 14:14 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Nico\Downloads\mbam-setup-1.75.0.1300.exe
2013-06-21 13:57 - 2013-06-21 13:57 - 00000000 ____A C:\Windows\setuperr.log
2013-06-21 13:56 - 2013-06-21 13:56 - 00000824 ____A C:\Windows\PFRO.log
2013-06-20 22:42 - 2013-06-20 22:07 - 104857600 ____A C:\Users\Nico\Downloads\D.DX.12.13.part3.rar
2013-06-20 22:39 - 2013-06-20 22:39 - 00000019 ____A C:\Users\Nico\Desktop\in 1,5 aus.cmd
2013-06-20 22:30 - 2013-06-20 22:16 - 00000000 ____D C:\Program Files (x86)\x264 Video Codec
2013-06-20 22:28 - 2013-06-20 22:28 - 00000000 ____D C:\Windows\Profiles\Nico
2013-06-20 22:15 - 2013-06-20 22:15 - 00000000 ____D C:\Program Files\VideoLAN
2013-06-20 22:12 - 2013-06-20 22:12 - 23229256 ____A C:\Users\Nico\Downloads\vlc-2.0.7-win64.exe
2013-06-20 22:08 - 2012-01-12 19:08 - 00000000 ____D C:\Users\Nico\AppData\Roaming\BitTorrent
2013-06-20 20:02 - 2013-06-20 20:02 - 00000000 ____D C:\Users\Nico\AppData\Roaming\File Scout
2013-06-20 19:44 - 2012-01-12 19:09 - 00000000 ____D C:\Program Files (x86)\BitTorrent
2013-06-20 19:41 - 2013-06-20 19:41 - 01125456 ____A (BitTorrent Inc.) C:\Users\Nico\Downloads\BitTorrent.exe
2013-06-20 19:21 - 2013-06-20 19:21 - 00000000 ____D C:\Users\Nico\AppData\Local\{F9859730-4A8B-4935-96F9-B5159219BD09}
2013-06-19 18:38 - 2012-06-06 21:17 - 00000000 ____D C:\Users\Nico\AppData\Local\Spotify
2013-06-19 15:31 - 2012-08-26 15:05 - 00002374 ____A C:\Users\Nico\Desktop\Google Chrome.lnk
2013-06-18 16:39 - 2013-06-18 16:39 - 00000000 ____D C:\Users\Nico\AppData\Local\{A3B9C5E6-D87F-4DB1-AA34-8258F0A6D317}
2013-06-18 15:50 - 2011-12-09 15:06 - 01786150 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2013-06-18 15:32 - 2012-03-26 20:45 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 10.0
2013-06-18 15:32 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\MSBuild
2013-06-18 15:22 - 2013-06-18 15:22 - 00000000 ____D C:\Users\Default\Documents\Visual Studio 2008
2013-06-18 15:22 - 2013-06-18 15:22 - 00000000 ____D C:\Users\Default User\Documents\Visual Studio 2008
2013-06-17 21:28 - 2012-03-26 20:42 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs
2013-06-17 21:27 - 2013-06-17 21:27 - 00000000 ____D C:\ProgramData\VS
2013-06-17 21:25 - 2013-06-17 21:25 - 00000000 ____D C:\fbabd28d772111eec99e8982
2013-06-17 18:08 - 2013-06-17 18:08 - 00001795 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 18:08 - 2013-06-17 18:07 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-17 18:08 - 2013-06-17 18:07 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 18:08 - 2012-10-13 14:19 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-17 18:07 - 2013-06-17 18:07 - 00000000 ____D C:\Program Files\iPod
2013-06-14 22:20 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-06-14 14:30 - 2013-06-14 14:30 - 00000466 ____A C:\Users\Nico\Desktop\DATA (D) - Verknüpfung.lnk
2013-06-13 21:27 - 2013-06-13 17:22 - 731594045 ____A C:\Users\Nico\Downloads\342fdsfssmo5.rar
2013-06-12 21:15 - 2013-06-14 14:31 - 00000101 ____A C:\Users\Nico\Downloads\ind-scary.nfo
2013-06-12 21:15 - 2013-02-06 22:32 - 00000341 ____A C:\Users\Nico\Downloads\www.goldesel.to - www.charts.to .txt
2013-06-12 21:15 - 2013-02-06 22:32 - 00000291 ____A C:\Users\Nico\Downloads\Charts.to - Die ultimative Seite fuer Charts als Direkt-Download.url
2013-06-12 21:15 - 2013-02-06 22:32 - 00000220 ____A C:\Users\Nico\Downloads\Goldesel.to - Die Seite fuer Direkt-Downloads aller Art.url
2013-06-12 18:30 - 2012-04-14 15:21 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-12 18:30 - 2011-07-25 12:15 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-12 15:51 - 2011-12-17 14:27 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-12 15:07 - 2013-01-24 18:29 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-06-12 15:07 - 2011-07-25 11:54 - 00000000 ____D C:\ProgramData\Skype
2013-06-11 13:55 - 2013-06-11 13:55 - 00000000 ____D C:\Users\Nico\AppData\Local\{4FC71047-D567-49F4-BF1A-EE9BEC968BA8}
2013-06-10 16:40 - 2009-07-14 07:08 - 00032632 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-08 18:41 - 2013-06-08 18:41 - 00000000 ____D C:\Users\Nico\AppData\Local\{D8BDBDB0-6714-480D-91FC-2F101077576A}
2013-06-08 17:43 - 2011-12-15 23:13 - 00000616 ____A C:\Users\Nico\Documents\ax_files.xml
2013-06-07 13:44 - 2012-11-05 18:14 - 00000000 ____D C:\Users\Nico\AppData\Local\Origin
2013-06-07 13:44 - 2012-11-05 18:07 - 00000000 ____D C:\Program Files (x86)\Origin
2013-06-05 15:46 - 2013-04-13 19:06 - 00000000 __SHD C:\Users\Nico\wc
2013-06-05 15:41 - 2013-06-05 15:41 - 00001036 ____A C:\Users\Nico\Desktop\ILS-SimV4.exe - Verknüpfung.lnk
2013-06-05 09:21 - 2012-10-06 16:46 - 00000000 ____D C:\ProgramData\Browser Manager
2013-06-03 17:21 - 2013-04-07 11:47 - 01130496 ____A C:\Users\Nico\Desktop\Schuppenat_Noel_09A (2).lpo
2013-05-28 15:05 - 2013-06-20 20:02 - 00163328 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerUpdateService.exe
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-14 01:19] - [2009-07-14 03:39] - 0329216 ____N () D41D8CD98F00B204E9800998ECF8427E
C:\Windows\System32\services.exe IS INFECTED. <===== ATTENTION!
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-06-14 22:11
==================== End Of Log ============================ --- --- ---
--- --- --- |