okay hier die logs
FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-10-2013
Ran by Hele (administrator) on HELE-PC on 26-10-2013 01:05:45
Running from C:\Users\Hele\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2014\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe
(Cisco Systems, Inc.) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
() C:\Program Files\CDBurnerXP\NMSAccessU.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(RealNetworks, Inc.) C:\Program Files\Common Files\Real\Update_OB\realsched.exe
(Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIEFE.EXE
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Dropbox, Inc.) C:\Users\Hele\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
() C:\Program Files\Samsung\Samsung Update Plus\SLUTrayNotifier.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-10-26] (Synaptics, Inc.)
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6111232 2008-04-17] (Realtek Semiconductor)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [33648 2007-08-24] (Microsoft Corporation)
HKLM\...\Run: [TkBellExe] - C:\Program Files\Common Files\Real\Update_OB\realsched.exe [198160 2010-02-07] (RealNetworks, Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2011-07-05] (Apple Inc.)
HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [74752 2011-12-09] (Nullsoft, Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)
HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2014\avgui.exe [4908592 2013-10-07] (AVG Technologies CZ, s.r.o.)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [EPSON Stylus SX200 Series] - C:\Users\Hele\AppData\Local\Temp\E_SC3CB.tmp [122 2011-03-11] ()
HKCU\...\Run: [Google Update] - C:\Users\Hele\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-11-22] (Google Inc.)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20684656 2013-07-25] (Skype Technologies S.A.)
HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe [235936 2008-10-05] (Adobe Systems, Inc.)
MountPoints2: {7f836ef1-2d12-11e0-ae87-001377adcfdc} - SNOVE///pijes.exe
MountPoints2: {d847d1c9-e505-11de-a791-001377adcfdc} - wubi.exe --cdmenu
MountPoints2: {f655bdff-532b-11e0-b93d-001377adcfdc} - EDWARD\\\\stereolove.exe
MountPoints2: {fef87b99-e42f-11e0-bcf7-001377adcfdc} - F:\LaunchU3.exe -a
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
Startup: C:\Users\Hele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Hele\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Hele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Hele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
DPF: {1ED48504-8834-11D5-AC75-0008C73FD642} file:///C:/Program%20Files/proeWildfire%202.0/i486_nt/obj/pvx_install.exe
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Hele\AppData\Roaming\Mozilla\Firefox\Profiles\98odespk.default
FF Homepage: hxxp://fm4.orf.at/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.450 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.3.448 - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Hele\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Hele\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Users\Hele\AppData\Roaming\Mozilla\Firefox\Profiles\98odespk.default\searchplugins\icqplugin-11.xml
FF SearchPlugin: C:\Users\Hele\AppData\Roaming\Mozilla\Firefox\Profiles\98odespk.default\searchplugins\icqplugin-12.xml
FF SearchPlugin: C:\Users\Hele\AppData\Roaming\Mozilla\Firefox\Profiles\98odespk.default\searchplugins\icqplugin-13.xml
FF SearchPlugin: C:\Users\Hele\AppData\Roaming\Mozilla\Firefox\Profiles\98odespk.default\searchplugins\icqplugin-14.xml
FF SearchPlugin: C:\Users\Hele\AppData\Roaming\Mozilla\Firefox\Profiles\98odespk.default\searchplugins\icqplugin-15.xml
FF SearchPlugin: C:\Users\Hele\AppData\Roaming\Mozilla\Firefox\Profiles\98odespk.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Hele\AppData\Roaming\Mozilla\Firefox\Profiles\98odespk.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: sharemenot - C:\Users\Hele\AppData\Roaming\Mozilla\Firefox\Profiles\98odespk.default\Extensions\sharemenot@franziroesner.com.xpi
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Program Files\Real\RealPlayer\browserrecord\firefox\ext
FF Extension: RealPlayer Browser Record Plugin - C:\Program Files\Real\RealPlayer\browserrecord\firefox\ext
Chrome:
=======
CHR RestoreOnStartup: "hxxp://fm4.orf.at/"
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Hele\AppData\Local\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Hele\AppData\Local\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\Hele\AppData\Local\Google\Chrome\Application\30.0.1599.101\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Microsoft\\u00AE Windows Media Player Firefox Plugin) - C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (DivX Web Player) - C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll No File
CHR Plugin: (DivX Player Netscape Plugin) - C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll No File
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Winamp Application Detector) - C:\Program Files\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (BrowserPlus (from Yahoo!) v2.9.2) - C:\Users\Hele\AppData\Local\Yahoo!\BrowserPlus\2.9.2\Plugins\npybrowserplus_2.9.2.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (YouTube) - C:\Users\Hele\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Hele\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Skype Click to Call) - C:\Users\Hele\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0
CHR Extension: (Gmail) - C:\Users\Hele\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
========================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3538480 2013-10-03] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [301152 2013-09-25] (AVG Technologies CZ, s.r.o.)
R2 CVPND; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [1528608 2008-08-29] (Cisco Systems, Inc.)
R2 NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2009-11-12] ()
S2 Samsung Update Plus; C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe [77480 2008-05-13] ()
==================== Drivers (Whitelisted) ====================
S3 ADDMEM; C:\Users\Hele\AppData\Local\Temp\__Samsung_Update\ADDMEM.SYS [3205 2009-07-07] ()
R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [120632 2013-09-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [209208 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [145720 2013-09-02] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22840 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [176952 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [223032 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [102200 2013-08-20] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27448 2013-09-08] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [193848 2013-08-01] (AVG Technologies CZ, s.r.o.)
S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
R2 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306299 2008-08-29] (Cisco Systems, Inc.)
R3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [125328 2008-03-29] (Deterministic Networks, Inc.)
R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2009-07-07] (SAMSUNG ELECTRONICS CO., LTD.)
S3 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [7168 2009-11-12] ()
R3 VMC302; C:\Windows\System32\Drivers\VMC302.sys [242048 2008-06-05] (Vimicro Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-26 01:02 - 2013-10-26 01:02 - 01088465 _____ (Farbar) C:\Users\Hele\Desktop\FRST.exe
2013-10-25 20:13 - 2013-10-25 20:13 - 00000000 ____D C:\Users\Hele\AppData\Roaming\Malwarebytes
2013-10-25 20:13 - 2013-10-25 20:13 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-25 20:13 - 2013-10-25 20:13 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-25 20:13 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-25 20:12 - 2013-10-25 20:11 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Hele\Downloads\mbam-setup-1.75.0.1300.exe
2013-10-25 20:08 - 2013-10-25 20:08 - 00001356 _____ C:\Users\Hele\Desktop\JRT.txt
2013-10-25 20:03 - 2013-10-25 20:03 - 00000000 ____D C:\Windows\ERUNT
2013-10-25 20:01 - 2013-10-25 20:01 - 01033335 _____ (Thisisu) C:\Users\Hele\Desktop\JRT.exe
2013-10-25 19:51 - 2013-10-25 19:55 - 00000000 ____D C:\AdwCleaner
2013-10-25 19:50 - 2013-10-25 19:50 - 01060070 _____ C:\Users\Hele\Desktop\adwcleaner.exe
2013-10-25 16:55 - 2013-10-25 16:55 - 00000091 _____ C:\Users\Hele\AppData\Roaming\WB.CFG
2013-10-25 16:55 - 2013-10-25 16:55 - 00000006 _____ C:\Users\Hele\AppData\Roaming\WBPU-TTL.DAT
2013-10-25 16:51 - 2013-10-25 16:51 - 00138832 _____ C:\Windows\Minidump\Mini102513-01.dmp
2013-10-25 16:51 - 2013-10-25 16:51 - 00000000 ____D C:\Windows\Minidump
2013-10-25 16:50 - 2013-10-25 16:51 - 346901418 _____ C:\Windows\MEMORY.DMP
2013-10-25 16:40 - 2013-10-25 16:42 - 00012404 _____ C:\Users\Hele\Downloads\Addition.txt
2013-10-25 16:33 - 2013-10-25 16:33 - 00377856 _____ C:\Users\Hele\Desktop\5zp79ydu.exe
2013-10-25 16:26 - 2013-10-25 16:26 - 00000000 ____D C:\FRST
2013-10-25 16:10 - 2013-10-25 16:10 - 00000000 _____ C:\Users\Hele\defogger_reenable
2013-10-25 16:09 - 2013-10-25 16:09 - 00050477 _____ C:\Users\Hele\Desktop\Defogger.exe
2013-10-25 15:56 - 2013-10-25 20:56 - 00000284 _____ C:\Windows\Tasks\FoxTab.job
2013-10-25 15:56 - 2013-10-25 15:56 - 00000000 ____D C:\Users\Hele\AppData\Roaming\FoxTab
2013-10-15 15:38 - 2013-10-15 15:38 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-27 20:37 - 2013-09-27 20:37 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2013-09-27 20:37 - 2013-09-27 20:37 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
==================== One Month Modified Files and Folders =======
2013-10-26 01:02 - 2013-10-26 01:02 - 01088465 _____ (Farbar) C:\Users\Hele\Desktop\FRST.exe
2013-10-26 00:58 - 2009-09-17 17:06 - 00000000 ____D C:\Users\Hele\AppData\Roaming\Skype
2013-10-26 00:58 - 2008-01-21 03:35 - 01489753 _____ C:\Windows\WindowsUpdate.log
2013-10-26 00:58 - 2006-11-02 14:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-26 00:57 - 2006-11-02 14:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-25 20:56 - 2013-10-25 15:56 - 00000284 _____ C:\Windows\Tasks\FoxTab.job
2013-10-25 20:48 - 2012-05-12 23:49 - 00000000 ___RD C:\Users\Hele\Dropbox
2013-10-25 20:48 - 2012-05-12 23:41 - 00000000 ____D C:\Users\Hele\AppData\Roaming\Dropbox
2013-10-25 20:46 - 2011-08-07 01:47 - 00000306 _____ C:\Windows\Tasks\WinMaximizer-Hele-Startup.job
2013-10-25 20:46 - 2010-11-05 09:40 - 00001090 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-25 20:46 - 2009-07-07 12:17 - 00096640 _____ C:\ProgramData\nvModes.001
2013-10-25 20:46 - 2008-01-21 04:47 - 00048150 _____ C:\Windows\PFRO.log
2013-10-25 20:46 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-25 20:46 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Branding
2013-10-25 20:45 - 2006-11-02 15:01 - 00032510 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-25 20:39 - 2009-07-27 12:12 - 00002631 _____ C:\Users\Hele\Desktop\Microsoft Office Word 2007.lnk
2013-10-25 20:38 - 2010-11-05 09:40 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-25 20:14 - 2011-11-22 14:25 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1475481164-914024980-864890415-1000UA.job
2013-10-25 20:13 - 2013-10-25 20:13 - 00000000 ____D C:\Users\Hele\AppData\Roaming\Malwarebytes
2013-10-25 20:13 - 2013-10-25 20:13 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-25 20:13 - 2013-10-25 20:13 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-25 20:11 - 2013-10-25 20:12 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Hele\Downloads\mbam-setup-1.75.0.1300.exe
2013-10-25 20:08 - 2013-10-25 20:08 - 00001356 _____ C:\Users\Hele\Desktop\JRT.txt
2013-10-25 20:03 - 2013-10-25 20:03 - 00000000 ____D C:\Windows\ERUNT
2013-10-25 20:01 - 2013-10-25 20:01 - 01033335 _____ (Thisisu) C:\Users\Hele\Desktop\JRT.exe
2013-10-25 19:55 - 2013-10-25 19:51 - 00000000 ____D C:\AdwCleaner
2013-10-25 19:55 - 2011-11-22 14:31 - 00001119 _____ C:\Users\Hele\Desktop\Google Chrome.lnk
2013-10-25 19:55 - 2011-11-22 14:31 - 00000000 ____D C:\Users\Hele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2013-10-25 19:55 - 2009-07-07 09:38 - 00000846 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-10-25 19:55 - 2009-07-07 09:34 - 00000973 _____ C:\Users\Hele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-10-25 19:52 - 2009-09-18 18:34 - 00000000 ____D C:\ProgramData\ICQ
2013-10-25 19:50 - 2013-10-25 19:50 - 01060070 _____ C:\Users\Hele\Desktop\adwcleaner.exe
2013-10-25 18:22 - 2013-09-23 12:18 - 00000000 ____D C:\ProgramData\MFAData
2013-10-25 16:55 - 2013-10-25 16:55 - 00000091 _____ C:\Users\Hele\AppData\Roaming\WB.CFG
2013-10-25 16:55 - 2013-10-25 16:55 - 00000006 _____ C:\Users\Hele\AppData\Roaming\WBPU-TTL.DAT
2013-10-25 16:51 - 2013-10-25 16:51 - 00138832 _____ C:\Windows\Minidump\Mini102513-01.dmp
2013-10-25 16:51 - 2013-10-25 16:51 - 00000000 ____D C:\Windows\Minidump
2013-10-25 16:51 - 2013-10-25 16:50 - 346901418 _____ C:\Windows\MEMORY.DMP
2013-10-25 16:42 - 2013-10-25 16:40 - 00012404 _____ C:\Users\Hele\Downloads\Addition.txt
2013-10-25 16:33 - 2013-10-25 16:33 - 00377856 _____ C:\Users\Hele\Desktop\5zp79ydu.exe
2013-10-25 16:32 - 2012-02-01 23:18 - 00000000 ____D C:\Users\Hele\Documents\notiz
2013-10-25 16:26 - 2013-10-25 16:26 - 00000000 ____D C:\FRST
2013-10-25 16:10 - 2013-10-25 16:10 - 00000000 _____ C:\Users\Hele\defogger_reenable
2013-10-25 16:10 - 2009-07-07 09:34 - 00000000 ____D C:\Users\Hele
2013-10-25 16:09 - 2013-10-25 16:09 - 00050477 _____ C:\Users\Hele\Desktop\Defogger.exe
2013-10-25 15:56 - 2013-10-25 15:56 - 00000000 ____D C:\Users\Hele\AppData\Roaming\FoxTab
2013-10-25 14:44 - 2009-09-21 22:42 - 00000000 ____D C:\Program Files\DivX
2013-10-25 14:25 - 2012-05-01 12:20 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-24 12:14 - 2011-11-22 14:25 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1475481164-914024980-864890415-1000Core.job
2013-10-22 12:11 - 2009-10-03 13:29 - 00000000 ____D C:\Users\Hele\Documents\Uni
2013-10-15 15:38 - 2013-10-15 15:38 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-10-06 14:57 - 2008-01-21 09:16 - 01418806 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-06 14:52 - 2009-09-17 17:06 - 00000000 ___RD C:\Program Files\Skype
2013-10-06 14:52 - 2009-09-17 17:06 - 00000000 ____D C:\ProgramData\Skype
2013-10-01 14:33 - 2006-11-02 14:52 - 00129266 _____ C:\Windows\setupact.log
2013-09-30 17:53 - 2013-03-04 11:48 - 00632656 _____ (Microsoft Corporation) C:\Windows\system32\msvcr80.dll
2013-09-30 17:53 - 2013-03-04 11:48 - 00554832 _____ (Microsoft Corporation) C:\Windows\system32\msvcp80.dll
2013-09-30 17:53 - 2013-03-04 11:48 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\msvcm80.dll
2013-09-30 17:53 - 2013-03-04 11:48 - 00001870 _____ C:\Windows\system32\Microsoft.VC80.CRT.manifest
2013-09-27 20:37 - 2013-09-27 20:37 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2013-09-27 20:37 - 2013-09-27 20:37 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
Files to move or delete:
====================
C:\Windows\Tasks\At1.job
Some content of TEMP:
====================
C:\Users\Hele\AppData\Local\Temp\02B673~1.exe
C:\Users\Hele\AppData\Local\Temp\66275uninstall.exe
C:\Users\Hele\AppData\Local\Temp\7z920.exe
C:\Users\Hele\AppData\Local\Temp\BackupSetup.exe
C:\Users\Hele\AppData\Local\Temp\bpuninstall.exe
C:\Users\Hele\AppData\Local\Temp\ConResGr.dll
C:\Users\Hele\AppData\Local\Temp\contentDATs.exe
C:\Users\Hele\AppData\Local\Temp\DelayInst.exe
C:\Users\Hele\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\Hele\AppData\Local\Temp\incredibar_installer.exe
C:\Users\Hele\AppData\Local\Temp\installservice.exe
C:\Users\Hele\AppData\Local\Temp\instmsi.exe
C:\Users\Hele\AppData\Local\Temp\instmsiw.exe
C:\Users\Hele\AppData\Local\Temp\ose00000.exe
C:\Users\Hele\AppData\Local\Temp\Quarantine.exe
C:\Users\Hele\AppData\Local\Temp\SecurityScan_Release.exe
C:\Users\Hele\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Hele\AppData\Local\Temp\Sqlite3.dll
C:\Users\Hele\AppData\Local\Temp\UpdateCheckerSetup.exe
C:\Users\Hele\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Hele\AppData\Local\Temp\vpnclient_setup.exe
C:\Users\Hele\AppData\Local\Temp\ydetect.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-25 21:02
==================== End Of Log ============================ --- --- ---
--- --- ---
Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 25-10-2013
Ran by Hele at 2013-10-26 01:06:45
Running from C:\Users\Hele\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}
==================== Installed Programs ======================
2007 Microsoft Office Suite Service Pack 1 (SP1)
7-Zip 9.20
Adobe Flash Player 10 ActiveX (Version: 10.0.12.36)
Adobe Flash Player 11 Plugin (Version: 11.5.502.135)
Adobe Reader XI (11.0.02) (Version: 11.0.02)
Apple Application Support (Version: 2.0.1)
Apple Software Update (Version: 2.1.3.127)
Atheros WLAN Client (Version: 1.00.000)
AVG 2014 (Version: 14.0.3615)
AVG 2014 (Version: 14.0.4158)
AVG 2014 (Version: 2014.0.4158)
CDBurnerXP (Version: 4.2.7.1875)
Chinese Simplified Fonts Support For Adobe Reader 9 (Version: 9.0.0)
Cisco Systems VPN Client 5.0.04.0300 (Version: 5.0.4)
Dropbox (HKCU Version: 2.0.22)
Druckerdeinstallation für EPSON Stylus SX200 Series
Easy Network Manager 3.0 (Version: 3.0.0.0)
EasyBits GO
EPSON Scan
GIMP 2.6.10 (Version: 2.6.10)
Google Chrome (HKCU Version: 30.0.1599.101)
Google Earth Plug-in (Version: 7.1.1.1888)
Google Update Helper (Version: 1.3.21.165)
ICQ7.2 (Version: 7.2)
Inkscape 0.48.4 (Version: 0.48.4)
Intel® Matrix Storage Manager
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300)
Microsoft – Speichern als PDF oder XPS – Add-In für 2007 Microsoft Office-Programme (Version: 12.0.4518.1014)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft Office Access MUI (German) 2007 (Version: 12.0.6215.1000)
Microsoft Office Enterprise 2007 (Version: 12.0.6215.1000)
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6215.1000)
Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6215.1000)
Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6215.1000)
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6215.1000)
Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6215.1000)
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6215.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6213.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6213.1000)
Microsoft Office Proof (German) 2007 (Version: 12.0.6213.1000)
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6213.1000)
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014)
Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6215.1000)
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6215.1000)
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6215.1000)
Microsoft SOAP Toolkit 2.0 SP2 (Version: 623.1)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Mozilla Firefox 24.0 (x86 de) (Version: 24.0)
Mozilla Maintenance Service (Version: 24.0)
NVIDIA Drivers
OpenOffice.org 3.1 (Version: 3.1.9420)
PDFCreator (Version: 1.5.1)
Pro/ENGINEER Release Wildfire 2.0 Datecode M270 (Version: Wildfire 2.0)
QuickTime (Version: 7.70.80.34)
RealPlayer
Realtek High Definition Audio Driver (Version: 6.0.1.5605)
Samsung Update Plus (Version: 1.3.0.11)
Skype Click to Call (Version: 5.9.9216)
Skype™ 6.7 (Version: 6.7.102)
Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0)
Synaptics Pointing Device Driver (Version: 10.1.2.0)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Zip Extractor
Update for Zip Opener
Vimicro UVC Camera (Version: 1.00.0000)
Visual Studio 2012 x86 Redistributables (Version: 14.0.0.1)
VMLoad
Winamp (Version: 5.623 )
Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1)
Windows Media Player Firefox Plugin (Version: 1.0.0.8)
WinZip 16.0 (Version: 16.0.9715)
Yahoo! Detect
==================== Restore Points =========================
23-09-2013 10:29:25 Removed Java(TM) 6 Update 10
24-09-2013 09:39:12 Geplanter Prüfpunkt
24-09-2013 09:50:48 Installed AVG 2014
24-09-2013 09:51:13 Installed AVG 2014
29-09-2013 17:07:18 Geplanter Prüfpunkt
01-10-2013 13:01:05 Geplanter Prüfpunkt
10-10-2013 18:32:52 Geplanter Prüfpunkt
11-10-2013 10:25:44 Geplanter Prüfpunkt
13-10-2013 09:11:04 Geplanter Prüfpunkt
15-10-2013 16:03:57 Geplanter Prüfpunkt
16-10-2013 11:51:29 Geplanter Prüfpunkt
18-10-2013 19:12:40 Geplanter Prüfpunkt
20-10-2013 17:38:54 Geplanter Prüfpunkt
21-10-2013 14:19:18 Geplanter Prüfpunkt
23-10-2013 16:11:06 Geplanter Prüfpunkt
25-10-2013 11:38:45 Geplanter Prüfpunkt
==================== Hosts content: ==========================
2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {250373CC-A849-4A3F-8751-878293A1C2BE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1475481164-914024980-864890415-1000UA => C:\Users\Hele\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-22] (Google Inc.)
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {3D5FCC10-6F8C-44DA-8FFB-22EE5A88E87E} - System32\Tasks\FoxTab => C:\Users\Hele\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {88569C84-941F-4C60-A151-4EE520758DFC} - System32\Tasks\WinMaximizer-Hele-Startup => C:\Program Files\WinMaximizer\WinMaximizer.exe
Task: {92AFBD8A-8331-4AF7-A595-7D6FDBF1BF87} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-11-05] (Google Inc.)
Task: {A16E5CCF-F2B7-4F1C-9F86-B324A50FB799} - System32\Tasks\{1F5742FE-2DBB-4595-B042-F06C5DF4C601} => C:\Program Files\Skype\Phone\Skype.exe [2013-07-25] (Skype Technologies S.A.)
Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => C:\Windows\system32\pla.dll [2008-01-21] (Microsoft Corporation)
Task: {AF2C3325-B9B7-4B60-964C-70B89C8A1830} - System32\Tasks\{A6AF78F1-75FF-4EBB-B4FD-FAF75CE0B460} => C:\Program Files\Skype\\Phone\Skype.exe [2013-07-25] (Skype Technologies S.A.)
Task: {CE379565-D83A-4C9F-804F-124766D90CFE} - System32\Tasks\At1 => C:\Users\Hele\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE
Task: {E43B0508-DAAE-4E2F-9E28-AE000FCE4DBB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1475481164-914024980-864890415-1000Core => C:\Users\Hele\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-22] (Google Inc.)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {FA8BC14A-41D8-4E76-9137-E4C66449D31A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-11-05] (Google Inc.)
Task: C:\Windows\Tasks\At1.job => C:\Users\Hele\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE
Task: C:\Windows\Tasks\FoxTab.job => C:\Users\Hele\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1475481164-914024980-864890415-1000Core.job => C:\Users\Hele\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1475481164-914024980-864890415-1000UA.job => C:\Users\Hele\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\WinMaximizer-Hele-Startup.job => C:\Program Files\WinMaximizer\WinMaximizer.exe
==================== Loaded Modules (whitelisted) =============
2013-03-13 22:48 - 2013-03-13 22:48 - 24978944 _____ () C:\Users\Hele\AppData\Roaming\Dropbox\bin\libcef.dll
2009-08-18 16:54 - 2009-08-18 16:54 - 00970752 _____ () C:\Program Files\OpenOffice.org 3\program\libxml2.dll
2013-10-15 15:38 - 2013-10-15 15:38 - 03279768 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Users\Hele\Downloads\The_Age_Of_Stupid_eng.avi:TOC.WMV
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Tun-Miniportadapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunmp
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: Cisco Systems VPN Adapter
Description: Cisco Systems VPN Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: CVirtA
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (10/25/2013 08:47:55 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (10/25/2013 08:47:55 PM) (Source: Service Control Manager) (User: )
Description: Parallel port driver%%1058
Error: (10/25/2013 08:46:33 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT)
Description: C:\Windows\system32\athihvs.dll126
Error: (10/25/2013 08:46:33 PM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2013-10-26 01:06:08.013
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-26 01:06:07.926
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-26 01:06:07.837
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-26 01:06:07.750
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-26 01:06:07.656
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-26 01:06:07.569
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-26 01:06:07.481
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-26 01:06:07.394
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-26 01:06:05.388
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-26 01:06:05.300
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 52%
Total physical RAM: 3065.84 MB
Available physical RAM: 1457.1 MB
Total Pagefile: 6340.08 MB
Available Pagefile: 4785.48 MB
Total Virtual: 2047.88 MB
Available Virtual: 1911.66 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:283.09 GB) (Free:113.4 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Volume) (Fixed) (Total:15 GB) (Free:14.9 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298 GB) (Disk ID: B079B6F4)
Partition 1: (Not Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=283 GB) - (Type=07 NTFS)
==================== End Of Log ============================
SystemLook Code:
SystemLook 30.07.11 by jpshortstuff
Log created at 01:09 on 26/10/2013 by Hele
Administrator - Elevation successful
========== filefind ==========
Searching for "*IBUpdater*"
No files found.
Searching for "*MyPC Backup*"
No files found.
Searching for "*DSite*"
C:\Program Files\Common Files\Real\Plugins\vidsite.dll --a---- 380928 bytes [13:15 07/02/2010] [13:15 07/02/2010] 1D47049EBF11FECBE34922E4A0545A53
C:\Users\Hele\AppData\Local\Temp\ish3214993\DAT\DSiteU.dat --a---- 95233 bytes [14:42 23/05/2013] [14:42 23/05/2013] 35B6D8F495CE656F6BA683192858CB36
Searching for "*digitalsite*"
C:\AdwCleaner\Quarantine\C\Windows\system32\Tasks\digitalsite.vir --a---- 3224 bytes [13:55 25/10/2013] [13:56 25/10/2013] 3FC9B264AEC0604034379209C4274881
C:\AdwCleaner\Quarantine\C\Windows\Tasks\digitalsite.job.vir --a---- 288 bytes [13:55 25/10/2013] [17:55 25/10/2013] 45C1AB9CEBC05B804AC0D29E66690278
Searching for "*qvo6*"
C:\AdwCleaner\Quarantine\C\Program Files\Mozilla Firefox\searchplugins\qvo6.xml.vir --a---- 827 bytes [13:38 15/10/2013] [13:33 04/09/2013] B509B23B4AC59B715CE33B7C2E3AA75F
Searching for "*Softonic*"
C:\Users\Hele\AppData\Roaming\Microsoft\Windows\Cookies\hele@gimp.softonic[2].txt --a---- 366 bytes [17:59 27/01/2011] [18:00 27/01/2011] C9F9603DB3AF4D5654C8806233B09BF6
C:\Users\Hele\AppData\Roaming\Microsoft\Windows\Cookies\hele@sd.softonic[2].txt --a---- 250 bytes [10:52 13/05/2012] [10:52 13/05/2012] 005607393CB7CAC0D3512E8DC1AE39C6
C:\Users\Hele\AppData\Roaming\Microsoft\Windows\Cookies\hele@softonic[1].txt --a---- 444 bytes [10:52 13/05/2012] [10:53 13/05/2012] 1C5297E4C3A85B065F108AC6FB5BB859
C:\Users\Hele\AppData\Roaming\Microsoft\Windows\Cookies\hele@softonic[2].txt --a---- 364 bytes [10:52 13/05/2012] [10:52 13/05/2012] 972C0AD65824F5D8907B4C6F082E7157
C:\Users\Hele\AppData\Roaming\Microsoft\Windows\Cookies\hele@winzip.sd.softonic[2].txt --a---- 420 bytes [10:53 13/05/2012] [11:01 13/05/2012] 217D2D0998508276F2ACEF2E04F0F18D
C:\Users\Hele\Downloads\SoftonicDownloader_fuer_gimp.exe --a---- 304928 bytes [17:58 27/01/2011] [17:58 27/01/2011] 57F336F40BF87DE86B87272F460204BC
Searching for "*Web Assistant*"
No files found.
========== folderfind ==========
Searching for "*IBUpdater*"
No folders found.
Searching for "*MyPC Backup*"
No folders found.
Searching for "*DSite*"
C:\AdwCleaner\Quarantine\C\Users\Hele\AppData\Roaming\DSite d------ [17:54 25/10/2013]
Searching for "*digitalsite*"
C:\AdwCleaner\Quarantine\C\Users\Hele\AppData\Roaming\digitalsite d------ [17:54 25/10/2013]
Searching for "*qvo6*"
No folders found.
Searching for "*Softonic*"
No folders found.
Searching for "*Web Assistant*"
No folders found.
========== regfind ==========
Searching for "IBUpdater"
No data found.
Searching for "MyPC Backup"
No data found.
Searching for "DSite"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DSite]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\DSite]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\DSite]
"DisplayIcon"="C:\Users\Hele\AppData\Roaming\DSite\UpdateProc\UpdateTask.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\DSite]
"UninstallString"="C:\Users\Hele\AppData\Roaming\DSite\UpdateProc\UpdateTask.exe /Uninstall"
[HKEY_CURRENT_USER\Software\RealNetworks\RealMediaSDK\6.0\Preferences\PluginHandlerData\FileInfo0]
@="{3gppttrenderer.dll,0994F8E33C7BFACDF55B4F81B43ED7A1,0,29184,1}{aacff.dll,3BC5BCB1E730B56AC5FD0AE10CEC63C6,0,77824,1}{amrff.dll,C938F79CBD67003E2607FAE9E8D17952,0,36864,1}{audplin.dll,6FEB30C8EFD1AFEAE36C46E8C3CEDD8B,1,135168,7}{authmgr.dll,46CEBCBCD9FE17F8ECABF09B0BB4D655,0,45056,1}{cdda3260.dll,A4C754A05CAF1C4CCE92BA8C238CE772,1,17408,2}{clbascauth.dll,EB4E533AA5439424788268A75F8BB3FB,0,25088,1}{clntxres.dll,147F01DEABA12BCE062E7638645C335C,0,44032,1}{cont3260.dll,144CC8B58FC1471F1B9930615FB43170,0,73728,1}{flvff.dll,F8A8204C1950FA6A5332549A021EC890,0,61440,1}{flvrender.dll,DEDEDA3FF1F7098E5E3D9E3DA04697D8,0,307200,1}{h263render.dll,DDBE83E60102976425783FC27F9008CA,0,126976,1}{httpfsys.dll,61F649711837001C1C145CD0C3EC9A57,1,204800,2}{hxsdp.dll,4F81FAFB1D24DB2A112138D15E8F928A,0,49152,1}{hxxml.dll,E0431B11F31590993CB4F6974B62592B,0,90112,1}{imaprender.dll,2F75F01A2068D171FCCEEEAD47FF1E86,0,53248,1}{imgrende
[HKEY_CURRENT_USER\Software\RealNetworks\RealMediaSDK\6.0\Preferences\PluginHandlerData\GUIDInfo0]
@="{309f2d21-cc0a-11d2-8a53-100ff0000000,imgrender.dll,8,imgrender.dll,10,imgrender.dll,12,pxcb3210.dll,0}{00000000-0901-11d1-8b06-00a024406d59,authmgr.dll,0,hxxml.dll,0,vidsite.dll,0}{10552e61-c6f1-11d2-8a4f-28909a000000,imgrender.dll,9,imgrender.dll,11,imgrender.dll,13,pxcb3210.dll,1}{00000a00-b4c8-11d0-9995-00a0248da5f0,clntxres.dll,0}337"
[HKEY_CURRENT_USER\Software\RealNetworks\RealMediaSDK\6.0\Preferences\PluginHandlerData\PluginInfo4]
@="right~SContains Macromedia(R) Flash Player technology by Macromedia, Inc.
Copyright (c) 1995-2000 Macromedia, Inc. All rights reserved.
Copyright (c) 1995-2004 RealNetworks, Inc. All rights reserved.~Description~SRealNetworks Renderer Plugin for Macromedia Flash 4~PlgCopy~Shxxp://www.real.com~PluginFilename~Sswfrender.dll~PluginType~SPLUGIN_RENDERER~RendererMime~Sapplication/x-shockwave-flash|application/x-shockwave-flash2}{IndexNumber~N0~LoadMultiple~N1~Version~N268452285~Copyright~S(c) 1995-2002 RealNetworks, Inc. All rights reserved.~Description~SRealNetworks Local TFile System~FileProtocol~Stfile~FileShort~Stfile-local~PlgCopy~Shxxp://www.real.com~PluginFilename~Stfilesys.dll~PluginType~SPLUGIN_FILE_SYSTEM}{IndexNumber~N0~LoadMultiple~N1~Renderer_Granularity~N20~Version~N-1610612736~Copyright~SCopyright(c) RealNetworks, Inc. 1995-2009. All rights reserved. Source code for this program is available un
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}]
@="IE Shell Rebar BandSite"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ECD4FC4D-521C-11D0-B792-00A0C90312E1}]
@="Shell Rebar BandSite"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4CF504B0-DE96-11D0-8B3F-00A0C911E8E5}]
@="IBandSite"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SOFTWARE\RealNetworks\Update\6.0\Preferences\Components\RMACore:6.0\File17]
@="C:\Program Files\Common Files\Real\Plugins\vidsite.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\UnattendBackup\SuggestedSitesEnabled]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}"="IE Shell Rebar BandSite"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
[HKEY_USERS\S-1-5-21-1475481164-914024980-864890415-1000\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DSite]
[HKEY_USERS\S-1-5-21-1475481164-914024980-864890415-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\DSite]
[HKEY_USERS\S-1-5-21-1475481164-914024980-864890415-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\DSite]
"DisplayIcon"="C:\Users\Hele\AppData\Roaming\DSite\UpdateProc\UpdateTask.exe"
[HKEY_USERS\S-1-5-21-1475481164-914024980-864890415-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\DSite]
"UninstallString"="C:\Users\Hele\AppData\Roaming\DSite\UpdateProc\UpdateTask.exe /Uninstall"
[HKEY_USERS\S-1-5-21-1475481164-914024980-864890415-1000\Software\RealNetworks\RealMediaSDK\6.0\Preferences\PluginHandlerData\FileInfo0]
@="{3gppttrenderer.dll,0994F8E33C7BFACDF55B4F81B43ED7A1,0,29184,1}{aacff.dll,3BC5BCB1E730B56AC5FD0AE10CEC63C6,0,77824,1}{amrff.dll,C938F79CBD67003E2607FAE9E8D17952,0,36864,1}{audplin.dll,6FEB30C8EFD1AFEAE36C46E8C3CEDD8B,1,135168,7}{authmgr.dll,46CEBCBCD9FE17F8ECABF09B0BB4D655,0,45056,1}{cdda3260.dll,A4C754A05CAF1C4CCE92BA8C238CE772,1,17408,2}{clbascauth.dll,EB4E533AA5439424788268A75F8BB3FB,0,25088,1}{clntxres.dll,147F01DEABA12BCE062E7638645C335C,0,44032,1}{cont3260.dll,144CC8B58FC1471F1B9930615FB43170,0,73728,1}{flvff.dll,F8A8204C1950FA6A5332549A021EC890,0,61440,1}{flvrender.dll,DEDEDA3FF1F7098E5E3D9E3DA04697D8,0,307200,1}{h263render.dll,DDBE83E60102976425783FC27F9008CA,0,126976,1}{httpfsys.dll,61F649711837001C1C145CD0C3EC9A57,1,204800,2}{hxsdp.dll,4F81FAFB1D24DB2A112138D15E8F928A,0,49152,1}{hxxml.dll,E0431B11F31590993CB4F6974B62592B,0,90112,1}{imaprender.dll,2F75F01A2068D1
[HKEY_USERS\S-1-5-21-1475481164-914024980-864890415-1000\Software\RealNetworks\RealMediaSDK\6.0\Preferences\PluginHandlerData\GUIDInfo0]
@="{309f2d21-cc0a-11d2-8a53-100ff0000000,imgrender.dll,8,imgrender.dll,10,imgrender.dll,12,pxcb3210.dll,0}{00000000-0901-11d1-8b06-00a024406d59,authmgr.dll,0,hxxml.dll,0,vidsite.dll,0}{10552e61-c6f1-11d2-8a4f-28909a000000,imgrender.dll,9,imgrender.dll,11,imgrender.dll,13,pxcb3210.dll,1}{00000a00-b4c8-11d0-9995-00a0248da5f0,clntxres.dll,0}337"
[HKEY_USERS\S-1-5-21-1475481164-914024980-864890415-1000\Software\RealNetworks\RealMediaSDK\6.0\Preferences\PluginHandlerData\PluginInfo4]
@="right~SContains Macromedia(R) Flash Player technology by Macromedia, Inc.
Copyright (c) 1995-2000 Macromedia, Inc. All rights reserved.
Copyright (c) 1995-2004 RealNetworks, Inc. All rights reserved.~Description~SRealNetworks Renderer Plugin for Macromedia Flash 4~PlgCopy~Shxxp://www.real.com~PluginFilename~Sswfrender.dll~PluginType~SPLUGIN_RENDERER~RendererMime~Sapplication/x-shockwave-flash|application/x-shockwave-flash2}{IndexNumber~N0~LoadMultiple~N1~Version~N268452285~Copyright~S(c) 1995-2002 RealNetworks, Inc. All rights reserved.~Description~SRealNetworks Local TFile System~FileProtocol~Stfile~FileShort~Stfile-local~PlgCopy~Shxxp://www.real.com~PluginFilename~Stfilesys.dll~PluginType~SPLUGIN_FILE_SYSTEM}{IndexNumber~N0~LoadMultiple~N1~Renderer_Granularity~N20~Version~N-1610612736~Copyright~SCopyright(c) RealNetworks, Inc. 1995-2009. All rights reserved. Source
Searching for "digitalsite"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DigitalSite]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\DigitalSite]
[HKEY_USERS\S-1-5-21-1475481164-914024980-864890415-1000\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DigitalSite]
[HKEY_USERS\S-1-5-21-1475481164-914024980-864890415-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\DigitalSite]
Searching for "qvo6"
No data found.
Searching for "Softonic"
No data found.
Searching for "Web Assistant"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd]
"path"="C:\Program Files\Web Assistant\source.crx"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Mozilla\Firefox\Extensions]
"{336D0C35-8A85-403a-B9D2-65C292C39087}"="C:\Program Files\Web Assistant\Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Mozilla\Firefox\Extensions]
"{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}"="C:\Program Files\Web Assistant\Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Mozilla\Firefox\Extensions]
"{8E9E3331-D360-4f87-8803-52DE43566502}"="C:\Program Files\Web Assistant\Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Web Assistant]
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Web Assistant]
"product_name"="Web Assistant"
[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-18\Software\Web Assistant]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-18\Software\Web Assistant]
-= EOF =- und zur Beantwortung der Fragen:
Mit Malware scheine ich keine Probleme mehr zu haben.
Soweit ich das beurteilen kann läuft der PC auch gut. Mit firefox hatte ich längerer Zeit auch immer Probleme, dass der Browser beim Öffnen sehr lange geladen hat und zwischenzeitlich "keine Rückmeldung" angezeigt wurde. Das ist nun auch nicht mehr der Fall.
Grüße hirbee |