Okay, hier also der nächste File: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by Anwender on 23.11.2013 at 15:47:44,31
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2840710695-1092165201-1932038912-1001\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2840710695-1092165201-1932038912-1001\Software\web assistant
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\firstsearch
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9
~~~ Files
Successfully deleted: [File] C:\Windows\syswow64\sho4445.tmp
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\Users\Anwender\appdata\local\apn"
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{0BA73CC4-21C3-4FE6-AE24-4A506F5618E8}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{132FDCA8-DFAB-449C-9D1E-30A18B516322}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{14BF5ABE-5FE0-410B-BED6-9C84E8E75DAE}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{21DD9C5E-238F-4526-A889-3D90339291F1}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{3A65E127-2C7B-495A-BED1-2EF7D2AA805D}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{431EC2AD-0949-43D4-99F2-BE245821230E}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{469A55C7-9063-4EBD-B6AD-EAEAC131765B}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{48720BAD-6550-4447-9BB6-8FFC841E6DA9}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{499F118E-523A-41DF-AB0B-412FCA4F3659}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{4B68082F-A30A-4CB1-A62C-AE52690919DE}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{4EBE1C42-AFE3-4F82-B26B-92D8434C6E49}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{4EEF61D8-DD23-46E6-B646-0BCBBE3E8422}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{533C0683-5DAB-4DBE-A297-9EE98D198A6A}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{59A701D0-F60B-436D-B3D9-F9A90462431B}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{5F7058C2-5792-4463-964A-A3314C214EDE}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{647786A6-149D-4AEA-8DE5-AE1E3DF2D3A7}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{64E41AB9-1BEF-4569-81D8-2003065DBDB5}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{6817C959-5011-4044-9A24-10E222A953C1}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{694EB603-2876-43E3-929D-693068C335D1}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{69D8611E-7188-4A18-AAA6-60819437D529}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{81CE254D-B151-4CA2-8A48-855240340FCB}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{8327506F-C0B0-41B1-B202-23ADF3E71BBF}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{91A40026-3667-4CBD-8779-CE115BF38CD4}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{91B2AF3D-AE44-4C19-8215-F499345C13DB}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{93DE485F-EF85-44D5-ABA5-D52419716196}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{9A0D8E8D-291C-4224-AF64-82D99EEB9E2A}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{9FFBC634-430F-44FA-BC6B-3C0A9BF7C68A}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{AC808465-5EA4-4B3C-A96D-099BF63BBA81}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{ACB9A679-0481-4A4D-884B-EBACE7B14E80}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{AEF6A948-2745-491B-B40B-65E17C18AA09}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{AFF4AE21-986A-4830-8D2D-D798DD91C4DA}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{B49945F1-005D-46E3-8F17-D4478419685B}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{B8F2F3D1-71C9-4EA1-BC97-00E976DF6556}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{B9D5F80C-F228-4329-B2B3-AEA394254FC7}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{BA7A0326-395F-4A78-BBB0-8765078A3258}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{BC72E297-513C-41A6-A3CF-F3726413C565}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{BD895DB6-ED8E-4CF8-994B-9F4B418F25CA}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{BECE5F6D-D798-4C28-B4C7-0B0BC892DA6C}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{BFE850EA-9B41-4459-ACEC-5C0754A54007}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{C206585C-5603-461D-9BB3-CE98FC258421}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{C5FCD476-923B-4850-97BE-F74602101EC4}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{C6DB1425-8C50-40DC-BA7D-A9254632A7C7}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{CB7E35B0-22CA-4511-A162-F29317CCCB14}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{CE9EC319-184E-42E2-B612-562CA66FB953}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{D0E0B219-7DAD-40EE-9B31-1CAA77EF922C}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{DB471654-D7EC-42F7-8DEF-E843D3ACACA2}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{E50C123A-FB66-414B-B90B-71F76A27DEF2}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{EC05F39D-7BBC-460B-A5CE-27AEB9121106}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{ED10013F-4BFA-42E2-8467-7F231FFDEF00}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{EE06F5A2-E3E1-481D-ACFB-586931416BAE}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{F4DF8A8E-087F-46A5-B8B5-6D6C4F8BA4CB}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{FD7717DA-49FF-467F-A3D0-7D085CAAAF62}
Successfully deleted: [Empty Folder] C:\Users\Anwender\appdata\local\{FE436D4A-2F8B-4C78-A2E5-FB2FC10DD014}
~~~ FireFox
Successfully deleted: [File] C:\user.js
Emptied folder: C:\Users\Anwender\AppData\Roaming\mozilla\firefox\profiles\2k68eo1d.default-1370682349470\minidumps [174 files]
~~~ Chrome
Successfully deleted: [Folder] C:\Users\Anwender\appdata\local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23.11.2013 at 15:54:26,67
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Hier der Rest:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-11-2013 03
Ran by Anwender (administrator) on ANWENDER-PC on 23-11-2013 18:04:20
Running from C:\Users\Anwender\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
(Jumping Bytes) C:\Program Files (x86)\PureSync\PureSyncTray.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
(Dropbox, Inc.) C:\Users\Anwender\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Farbar) C:\Users\Anwender\Downloads\FRST64(1).exe
==================== Registry (Whitelisted) ==================
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [SpybotSD TeaTimer] - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKCU\...\Run: [PureSync] - C:\Program Files (x86)\PureSync\PureSyncTray.exe [903712 2013-02-01] (Jumping Bytes)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20580000 2013-10-21] (Skype Technologies S.A.)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-19] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
Startup: C:\Users\Anwender\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Anwender\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs =
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP =
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2421} URL =
SearchScopes: HKLM-x32 - TopResultURLFallback hxxp://search.chatzum.com/?q={searchTerms}
SearchScopes: HKLM-x32 - URL hxxp://search.chatzum.com/?q={searchTerms}
BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: WEB.DE Toolbar BHO - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: SecureBrowsingBho Helper - {7632ABCA-B104-4fbc-9C70-419C4147061B} - C:\Program Files (x86)\Finjan Secure Browsing\bho.dll (Finjan LTD)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: WEB.DE Toolbar BHO - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Finjan Secure Browsing - {B99F805C-F0B1-48EA-8C8B-753BFCBED913} - C:\Program Files (x86)\Finjan Secure Browsing\bho.dll (Finjan LTD)
Toolbar: HKCU - No Name - {41525333-0076-A76A-76A7-7A786E7484D7} - No File
Toolbar: HKCU - No Name - {B99F805C-F0B1-48EA-8C8B-753BFCBED913} - No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler: webde - {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: webde - {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
Tcpip\Parameters: [DhcpNameServer] 78.42.43.62 82.212.62.62
Tcpip\..\Interfaces\{0FB6F404-2F14-4D12-9CCF-C49A52FB98DF}: [NameServer]8.26.56.26,156.154.70.22
FireFox:
========
FF ProfilePath: C:\Users\Anwender\AppData\Roaming\Mozilla\Firefox\Profiles\2k68eo1d.default-1370682349470
FF NetworkProxy: "http", "127.0.0.1"
FF NetworkProxy: "http_port", 8555
FF NetworkProxy: "type", 4
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.2 - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.10 - C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.0.0.1 - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.2 - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ftd - C:\Users\Anwender\AppData\Roaming\Mozilla\Firefox\Profiles\2k68eo1d.default-1370682349470\Extensions\ftd@ftd.com.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Hotspot Shield Helper (Please allow this installation) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afurladvisor@anchorfree.com
FF HKLM\...\Firefox\Extensions: [{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}] - C:\Program Files\V-bates\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}] - C:\Program Files\V-bates\Firefox
FF HKLM-x32\...\Firefox\Extensions: [OKitSpace@OKitSpace.es] - C:\Users\Anwender\AppData\Roaming\okitSpace\Firefox
FF HKCU\...\Firefox\Extensions: [{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}] - C:\Users\Anwender\AppData\Roaming\13001.027
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "urls_to_restore_on_startup": [
CHR Extension: (Skype Click to Call) - C:\Users\Anwender\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_1
CHR Extension: (Google Wallet) - C:\Users\Anwender\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_1
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151744 2013-11-21] (IObit)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.)
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-12-11] (Wacom Technology, Corp.)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [106904 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [46792 2013-06-21] (AnchorFree Inc.)
R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-04-30] ()
S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-04-30] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-24] (Anchorfree Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-23 18:04 - 2013-11-23 18:04 - 01958396 _____ (Farbar) C:\Users\Anwender\Downloads\FRST64(1).exe
2013-11-23 15:54 - 2013-11-23 15:54 - 00007537 _____ C:\Users\Anwender\Desktop\JRT.txt
2013-11-23 15:47 - 2013-11-23 15:47 - 01034531 _____ (Thisisu) C:\Users\Anwender\Downloads\JRT.exe
2013-11-23 15:47 - 2013-11-23 15:47 - 00000000 ____D C:\Windows\ERUNT
2013-11-23 15:38 - 2013-11-23 15:40 - 00000000 ____D C:\AdwCleaner
2013-11-23 15:37 - 2013-11-23 15:38 - 01085542 _____ C:\Users\Anwender\Downloads\adwcleaner.exe
2013-11-23 09:01 - 2013-11-23 09:14 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-11-23 09:01 - 2013-11-23 09:01 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2013-11-23 09:00 - 2013-11-23 09:14 - 00000000 ____D C:\Users\Anwender\Desktop\mbar
2013-11-23 09:00 - 2013-11-23 09:00 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Anwender\Downloads\mbar-1.07.0.1007.exe
2013-11-23 09:00 - 2013-11-23 09:00 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-11-22 17:22 - 2013-11-22 17:22 - 00051324 _____ C:\ComboFix.txt
2013-11-22 16:34 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2013-11-22 16:34 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2013-11-22 16:34 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-11-22 16:34 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-11-22 16:34 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-11-22 16:34 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2013-11-22 16:34 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2013-11-22 16:34 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2013-11-22 16:31 - 2013-11-22 17:23 - 00000000 ____D C:\Qoobox
2013-11-22 16:26 - 2013-11-22 16:26 - 00001222 _____ C:\Users\Anwender\Desktop\combofix [1].exe - Verknüpfung.lnk
2013-11-22 16:24 - 2013-11-22 17:18 - 00000000 ____D C:\Windows\erdnt
2013-11-22 16:23 - 2013-11-22 16:24 - 05147802 ____R (Swearware) C:\Users\Anwender\Downloads\combofix [1].exe
2013-11-22 16:22 - 2013-11-22 16:30 - 05147802 ____R (Swearware) C:\Users\Anwender\Downloads\ComboFix.exe
2013-11-21 22:11 - 2013-11-21 22:12 - 00025107 _____ C:\Users\Anwender\Downloads\Addition.txt
2013-11-21 22:09 - 2013-11-23 18:04 - 00016688 _____ C:\Users\Anwender\Downloads\FRST.txt
2013-11-21 22:09 - 2013-11-21 22:09 - 00000000 ____D C:\FRST
2013-11-21 22:08 - 2013-11-21 22:08 - 01957964 _____ (Farbar) C:\Users\Anwender\Downloads\FRST64.exe
2013-11-21 19:48 - 2013-11-21 19:48 - 10330944 _____ (IObit) C:\Users\Anwender\Downloads\iobituninstaller3-1.0.exe
2013-11-21 19:48 - 2013-11-21 19:48 - 00001247 _____ C:\Users\Anwender\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2013-11-21 19:48 - 2013-11-21 19:48 - 00001223 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2013-11-21 19:48 - 2013-11-21 19:48 - 00000000 ____D C:\Users\Anwender\AppData\Roaming\IObit
2013-11-21 19:48 - 2013-11-21 19:48 - 00000000 ____D C:\ProgramData\ProductData
2013-11-21 19:48 - 2013-11-21 19:48 - 00000000 ____D C:\ProgramData\IObit
2013-11-21 19:48 - 2013-11-21 19:48 - 00000000 ____D C:\Program Files (x86)\IObit
2013-11-21 11:26 - 2013-11-21 11:26 - 00001170 _____ C:\Users\Anwender\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2013-11-21 11:13 - 2013-11-21 11:14 - 00000000 ____D C:\Users\Anwender\AppData\Local\Mobogenie
2013-11-21 11:13 - 2013-11-21 11:13 - 00000000 ____D C:\Users\Anwender\Documents\Mobogenie
2013-11-21 11:13 - 2013-11-21 11:13 - 00000000 ____D C:\Users\Anwender\AppData\Local\cache
2013-11-21 11:13 - 2013-11-21 11:13 - 00000000 _____ C:\Users\Anwender\daemonprocess.txt
2013-11-21 11:12 - 2013-11-21 11:12 - 00000000 ____D C:\Users\Anwender\Documents\180467-532417-samsung-digimax-s500.zip
2013-11-20 10:52 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-11-20 10:52 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-11-20 10:52 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-11-20 10:52 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-11-20 10:52 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-11-20 10:52 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-11-20 10:52 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-11-20 09:46 - 2013-11-21 12:17 - 00000000 ____D C:\Users\Anwender\AppData\Local\Adobe
2013-11-16 11:21 - 2013-11-16 11:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 09:45 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-14 09:45 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 09:45 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 09:45 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-14 09:45 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-14 09:45 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 09:45 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-14 09:45 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-14 09:45 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-14 09:45 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-14 09:45 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-14 09:45 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-14 09:45 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-14 09:45 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-14 09:45 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-14 09:45 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-14 09:45 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-14 09:45 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-14 09:45 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-14 09:45 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-14 09:45 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-14 09:45 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-14 09:45 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-14 09:45 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-14 09:45 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-14 09:45 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-14 09:45 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-14 09:45 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-14 09:45 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-14 09:45 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-11 20:31 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-11-11 20:27 - 2013-11-11 20:27 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-11 20:27 - 2013-11-11 20:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-11 20:27 - 2013-11-11 20:27 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-11 20:27 - 2013-11-11 20:27 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-11 20:27 - 2013-11-11 20:27 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-11 20:27 - 2013-11-11 20:27 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-11 20:27 - 2013-11-11 20:27 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-11 20:27 - 2013-11-11 20:27 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-11 20:27 - 2013-11-11 20:27 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-11 20:27 - 2013-11-11 20:27 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-11 20:27 - 2013-11-11 20:27 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-11 20:26 - 2013-11-11 20:31 - 00010242 _____ C:\Windows\IE11_main.log
2013-11-09 19:31 - 2013-11-09 19:31 - 00000000 ____D C:\Users\Anwender\AppData\Roaming\PamFax Office Integrations
2013-11-09 19:29 - 2013-11-09 19:29 - 00000000 ____D C:\Users\Anwender\AppData\Roaming\Softland
2013-11-09 19:28 - 2010-02-05 15:00 - 01700352 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2013-11-09 19:23 - 2013-11-09 19:23 - 00809688 _____ (Scendix Software GmbH ) C:\Users\Anwender\Downloads\PamFaxInstaller.exe
2013-11-04 10:09 - 2013-11-04 10:09 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-11-04 10:09 - 2013-11-04 10:09 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-11-04 10:09 - 2013-11-04 10:09 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-11-04 10:09 - 2013-11-04 10:09 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-11-04 10:09 - 2013-11-04 10:09 - 00000000 ____D C:\Program Files\Java
2013-11-04 10:08 - 2013-11-04 10:08 - 30694824 _____ (Oracle Corporation) C:\Users\Anwender\Downloads\jre-7u45-windows-x64.exe
2013-11-04 10:07 - 2013-11-04 10:09 - 00000000 ____D C:\ProgramData\Oracle
2013-11-04 10:07 - 2013-10-08 07:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-04 10:07 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-11-04 10:07 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-11-04 10:07 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-11-04 10:06 - 2013-11-04 10:07 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
==================== One Month Modified Files and Folders =======
2013-11-23 18:04 - 2013-11-23 18:04 - 01958396 _____ (Farbar) C:\Users\Anwender\Downloads\FRST64(1).exe
2013-11-23 18:04 - 2013-11-21 22:09 - 00016688 _____ C:\Users\Anwender\Downloads\FRST.txt
2013-11-23 18:03 - 2012-01-09 18:32 - 00000000 ____D C:\Users\Anwender\AppData\Roaming\Skype
2013-11-23 18:00 - 2012-01-11 15:45 - 00000000 ____D C:\Users\Anwender\Documents\Outlook Files
2013-11-23 17:43 - 2012-04-03 18:29 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-23 17:41 - 2012-03-02 18:50 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-23 15:54 - 2013-11-23 15:54 - 00007537 _____ C:\Users\Anwender\Desktop\JRT.txt
2013-11-23 15:50 - 2009-07-14 05:45 - 00021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-23 15:50 - 2009-07-14 05:45 - 00021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-23 15:47 - 2013-11-23 15:47 - 01034531 _____ (Thisisu) C:\Users\Anwender\Downloads\JRT.exe
2013-11-23 15:47 - 2013-11-23 15:47 - 00000000 ____D C:\Windows\ERUNT
2013-11-23 15:46 - 2013-02-13 18:36 - 01672441 _____ C:\Windows\WindowsUpdate.log
2013-11-23 15:45 - 2011-04-12 08:43 - 08042188 _____ C:\Windows\system32\perfh007.dat
2013-11-23 15:45 - 2011-04-12 08:43 - 02423550 _____ C:\Windows\system32\perfc007.dat
2013-11-23 15:45 - 2009-07-14 06:13 - 00005594 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-23 15:42 - 2012-03-02 18:50 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-23 15:42 - 2012-01-09 18:46 - 00000000 ___RD C:\Users\Anwender\Dropbox
2013-11-23 15:42 - 2012-01-09 18:44 - 00000000 ____D C:\Users\Anwender\AppData\Roaming\Dropbox
2013-11-23 15:41 - 2013-06-08 16:06 - 02006492 _____ C:\Windows\setupact.log
2013-11-23 15:41 - 2013-06-08 16:06 - 00160676 _____ C:\Windows\PFRO.log
2013-11-23 15:41 - 2012-09-14 17:06 - 00000000 _____ C:\Windows\system32\Drivers\lvuvc.hs
2013-11-23 15:41 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-23 15:40 - 2013-11-23 15:38 - 00000000 ____D C:\AdwCleaner
2013-11-23 15:38 - 2013-11-23 15:37 - 01085542 _____ C:\Users\Anwender\Downloads\adwcleaner.exe
2013-11-23 09:14 - 2013-11-23 09:01 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-11-23 09:14 - 2013-11-23 09:00 - 00000000 ____D C:\Users\Anwender\Desktop\mbar
2013-11-23 09:01 - 2013-11-23 09:01 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2013-11-23 09:00 - 2013-11-23 09:00 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Anwender\Downloads\mbar-1.07.0.1007.exe
2013-11-23 09:00 - 2013-11-23 09:00 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-11-22 17:23 - 2013-11-22 16:31 - 00000000 ____D C:\Qoobox
2013-11-22 17:23 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default
2013-11-22 17:22 - 2013-11-22 17:22 - 00051324 _____ C:\ComboFix.txt
2013-11-22 17:18 - 2013-11-22 16:24 - 00000000 ____D C:\Windows\erdnt
2013-11-22 17:11 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2013-11-22 16:30 - 2013-11-22 16:22 - 05147802 ____R (Swearware) C:\Users\Anwender\Downloads\ComboFix.exe
2013-11-22 16:26 - 2013-11-22 16:26 - 00001222 _____ C:\Users\Anwender\Desktop\combofix [1].exe - Verknüpfung.lnk
2013-11-22 16:24 - 2013-11-22 16:23 - 05147802 ____R (Swearware) C:\Users\Anwender\Downloads\combofix [1].exe
2013-11-22 16:09 - 2012-01-09 18:10 - 00000000 ____D C:\ProgramData\Adobe
2013-11-21 22:12 - 2013-11-21 22:11 - 00025107 _____ C:\Users\Anwender\Downloads\Addition.txt
2013-11-21 22:09 - 2013-11-21 22:09 - 00000000 ____D C:\FRST
2013-11-21 22:08 - 2013-11-21 22:08 - 01957964 _____ (Farbar) C:\Users\Anwender\Downloads\FRST64.exe
2013-11-21 20:14 - 2012-09-09 07:18 - 00001119 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-21 20:14 - 2012-09-09 07:18 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-21 19:48 - 2013-11-21 19:48 - 10330944 _____ (IObit) C:\Users\Anwender\Downloads\iobituninstaller3-1.0.exe
2013-11-21 19:48 - 2013-11-21 19:48 - 00001247 _____ C:\Users\Anwender\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2013-11-21 19:48 - 2013-11-21 19:48 - 00001223 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2013-11-21 19:48 - 2013-11-21 19:48 - 00000000 ____D C:\Users\Anwender\AppData\Roaming\IObit
2013-11-21 19:48 - 2013-11-21 19:48 - 00000000 ____D C:\ProgramData\ProductData
2013-11-21 19:48 - 2013-11-21 19:48 - 00000000 ____D C:\ProgramData\IObit
2013-11-21 19:48 - 2013-11-21 19:48 - 00000000 ____D C:\Program Files (x86)\IObit
2013-11-21 12:22 - 2013-09-17 18:59 - 00000000 ____D C:\Users\Anwender\AppData\Roaming\Adobe
2013-11-21 12:17 - 2013-11-20 09:46 - 00000000 ____D C:\Users\Anwender\AppData\Local\Adobe
2013-11-21 11:26 - 2013-11-21 11:26 - 00001170 _____ C:\Users\Anwender\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2013-11-21 11:15 - 2012-01-09 13:57 - 00000000 ___RD C:\Users\Anwender\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-21 11:14 - 2013-11-21 11:13 - 00000000 ____D C:\Users\Anwender\AppData\Local\Mobogenie
2013-11-21 11:13 - 2013-11-21 11:13 - 00000000 ____D C:\Users\Anwender\Documents\Mobogenie
2013-11-21 11:13 - 2013-11-21 11:13 - 00000000 ____D C:\Users\Anwender\AppData\Local\cache
2013-11-21 11:13 - 2013-11-21 11:13 - 00000000 _____ C:\Users\Anwender\daemonprocess.txt
2013-11-21 11:13 - 2013-02-13 17:50 - 00000000 ____D C:\Users\Anwender
2013-11-21 11:12 - 2013-11-21 11:12 - 00000000 ____D C:\Users\Anwender\Documents\180467-532417-samsung-digimax-s500.zip
2013-11-19 16:02 - 2013-05-07 13:55 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-11-19 16:02 - 2013-04-04 19:11 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-11-19 16:02 - 2013-04-04 19:11 - 00106904 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-11-19 16:02 - 2013-04-04 19:11 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-11-19 09:36 - 2013-10-22 08:14 - 00000000 ____D C:\Program Files\McAfee Security Scan
2013-11-19 09:36 - 2013-04-19 08:13 - 00001937 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2013-11-18 20:48 - 2012-04-03 18:29 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-11-18 20:48 - 2012-01-09 18:42 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-17 09:10 - 2013-06-08 10:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-16 11:21 - 2013-11-16 11:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-15 14:05 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-11-15 09:43 - 2012-03-02 18:50 - 00002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-14 14:39 - 2012-01-10 18:12 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-14 14:38 - 2013-08-14 10:51 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 14:37 - 2013-02-13 20:32 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-14 09:40 - 2012-01-09 18:32 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-11-14 09:40 - 2012-01-09 18:32 - 00000000 ____D C:\ProgramData\Skype
2013-11-12 08:57 - 2013-02-13 19:01 - 00001431 _____ C:\Users\Anwender\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-12 08:54 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-11-11 20:31 - 2013-11-11 20:26 - 00010242 _____ C:\Windows\IE11_main.log
2013-11-11 20:27 - 2013-11-11 20:27 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-11 20:27 - 2013-11-11 20:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-11 20:27 - 2013-11-11 20:27 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-11 20:27 - 2013-11-11 20:27 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-11 20:27 - 2013-11-11 20:27 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-11 20:27 - 2013-11-11 20:27 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-11 20:27 - 2013-11-11 20:27 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-11 20:27 - 2013-11-11 20:27 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-11 20:27 - 2013-11-11 20:27 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-11 20:27 - 2013-11-11 20:27 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-11 20:27 - 2013-11-11 20:27 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-11 20:27 - 2013-11-11 20:27 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-11 20:27 - 2013-11-11 20:27 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-11 05:50 - 2010-11-21 04:27 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-09 19:31 - 2013-11-09 19:31 - 00000000 ____D C:\Users\Anwender\AppData\Roaming\PamFax Office Integrations
2013-11-09 19:29 - 2013-11-09 19:29 - 00000000 ____D C:\Users\Anwender\AppData\Roaming\Softland
2013-11-09 19:23 - 2013-11-09 19:23 - 00809688 _____ (Scendix Software GmbH ) C:\Users\Anwender\Downloads\PamFaxInstaller.exe
2013-11-04 11:10 - 2012-01-09 17:53 - 00000000 ____D C:\Users\Anwender\AppData\Local\Nero
2013-11-04 10:09 - 2013-11-04 10:09 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-11-04 10:09 - 2013-11-04 10:09 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-11-04 10:09 - 2013-11-04 10:09 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-11-04 10:09 - 2013-11-04 10:09 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-11-04 10:09 - 2013-11-04 10:09 - 00000000 ____D C:\Program Files\Java
2013-11-04 10:09 - 2013-11-04 10:07 - 00000000 ____D C:\ProgramData\Oracle
2013-11-04 10:08 - 2013-11-04 10:08 - 30694824 _____ (Oracle Corporation) C:\Users\Anwender\Downloads\jre-7u45-windows-x64.exe
2013-11-04 10:07 - 2013-11-04 10:06 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-11-04 10:07 - 2012-01-09 19:00 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-24 07:41 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
Files to move or delete:
====================
C:\Users\Anwender\grub.exe
C:\Users\Anwender\rescue2usb.exe
C:\Users\Anwender\syslinux.exe
Some content of TEMP:
====================
C:\Users\Anwender\AppData\Local\Temp\avgnt.exe
C:\Users\Anwender\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-20 10:35
==================== End Of Log ============================ --- --- ---
--- --- ---
Additional: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-11-2013 03
Ran by Anwender at 2013-11-23 18:11:25
Running from C:\Users\Anwender\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
7-Zip 9.20 (x32)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.152)
Adobe Photoshop Elements 8.0 (x32 Version: 8.0)
Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05)
Apple Application Support (x32 Version: 2.3.4)
Apple Software Update (x32 Version: 2.1.3.127)
Avira Free Antivirus (x32 Version: 14.0.1.719)
Bamboo Explore (x32 Version: 1.2010.1105.1650)
Bamboo Scribe LanguagePack de_DE 3.2 (x32 Version: 3.2.63.144)
Bamboo Scribe Wacom 3.2 (x32 Version: 3.2.63.144)
Canon MP540 series MP Drivers
CCleaner (Version: 3.22)
CDBurnerXP (x32 Version: 4.5.0.3717)
CutePDF Writer 3.0 (Version: 3.0)
D3DX10 (x32 Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32)
Digimax Master (x32 Version: 1.0.10)
Dropbox (HKCU Version: 2.0.22)
ElsterFormular (x32 Version: 14.3.20130522)
Finjan Secure Browsing (x32)
Free Easy Burner V 5.1 (x32 Version: 5.1.0.0)
Google Chrome (x32 Version: 31.0.1650.57)
Google Update Helper (x32 Version: 1.3.21.165)
High-Definition Video Playback (x32 Version: 7.1.13900.47.0)
Internet-TV für Windows Media Center (x32 Version: 4.2.2.0)
IObit Uninstaller (x32 Version: 3.0.4.922)
IrfanView (remove only) (x32 Version: 4.32)
Java 7 Update 45 (64-bit) (Version: 7.0.450)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
JDownloader 0.9 (x32 Version: 0.9)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
Logitech Vid HD (x32 Version: 7.2 (7259))
Logitech Webcam Software (Version: 12.00.1280)
Logitech Webcam Software-Treiberpaket (Version: 12.0.1278)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
McAfee Security Scan Plus (Version: 3.8.130.10)
Mesh Runtime (x32 Version: 15.4.5722.2)
Messenger Companion (x32 Version: 15.4.3502.0922)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Access MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Access Setup Metadata MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Excel MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Groove MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office InfoPath MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000)
Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000)
Microsoft Office OneNote MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Outlook MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office PowerPoint MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proof (Spanish) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Proofing (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Publisher MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000)
Microsoft Office Word MUI (English) 2010 (x32 Version: 14.0.7015.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft VC9 runtime libraries (x32 Version: 2.0.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 25.0.1 (x86 de) (x32 Version: 25.0.1)
Mozilla Maintenance Service (x32 Version: 25.0.1)
Mozilla Thunderbird 9.0.1 (x86 de) (x32 Version: 9.0.1)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
Nero 10 Movie ThemePack 1 (x32 Version: 10.2.10000.11.0)
Nero 10 Movie ThemePack Basic (x32 Version: 10.2.10000.0.0)
Nero BurnRights 10 (x32 Version: 4.2.10500.1.102)
Nero BurnRights 10 Help (CHM) (x32 Version: 10.5.10000)
Nero Control Center 10 (x32 Version: 10.2.11900.1.9)
Nero ControlCenter 10 Help (CHM) (x32 Version: 10.5.10000)
Nero Core Components 10 (x32 Version: 2.0.18400.9.0)
Nero CoverDesigner 10 (x32 Version: 5.2.11400.11.100)
Nero CoverDesigner 10 Help (CHM) (x32 Version: 10.5.10000)
Nero DiscSpeed 10 (x32 Version: 6.2.10500.2.100)
Nero DiscSpeed 10 Help (CHM) (x32 Version: 10.5.10000)
Nero Express 10 (x32 Version: 10.2.11900.20.100)
Nero Express 10 Help (CHM) (x32 Version: 10.5.10300)
Nero InfoTool 10 (x32 Version: 7.2.10400.5.100)
Nero InfoTool 10 Help (CHM) (x32 Version: 10.5.10000)
Nero MediaHub 10 (x32 Version: 1.2.13200.33.100)
Nero MediaHub 10 Help (CHM) (x32 Version: 10.5.10000)
Nero Multimedia Suite 10 Essentials (x32 Version: 10.5.10400)
Nero RescueAgent 10 (x32 Version: 3.2.10800.9.100)
Nero RescueAgent 10 Help (CHM) (x32 Version: 10.5.10000)
Nero StartSmart 10 (x32 Version: 10.2.11600.14.100)
Nero StartSmart 10 Help (CHM) (x32 Version: 10.5.10000)
Nero Update (x32 Version: 1.0.0018)
PureSync (x32 Version: 3.7.2)
PureSync 3.7.2 (x32 Version: 3.7.2)
QuickTime (x32 Version: 7.74.80.86)
S500/S600 USB Driver (x32)
Security Task Manager 1.8d (x32 Version: 1.8d)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32)
Skype Click to Call (x32 Version: 5.9.9216)
Skype™ 6.10 (x32 Version: 6.10.104)
SPSS Data Access Pack 2.5 (x32 Version: 2.5)
Spybot - Search & Destroy (x32 Version: 1.6.2)
TeamViewer 8 (x32 Version: 8.0.22298)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2494150) (x32)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32)
Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition (x32)
Wacom (Version: 5.3.2-1)
WEB.DE Softwareaktualisierung (x32 Version: 2.0.4.1)
WEB.DE Toolbar für Mozilla Firefox (x32 Version: 1.7.0.0)
WEB.DE Toolbar MSVC100 CRT x64 (Version: 1.0.0)
WEB.DE Toolbar MSVC100 CRT x86 (x32 Version: 1.0.0)
WebTablet FB Plugin 32 bit (x32 Version: 2.1.0.2)
WebTablet FB Plugin 64 bit (Version: 2.1.0.2)
WebTablet IE Plugin (x32 Version: 1.1.0.12)
WebTablet Netscape Plugin (x32 Version: 1.1.0.10)
Winamp (x32 Version: 5.63 )
Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3538.0513)
Windows Live Family Safety (Version: 15.4.3538.0513)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3538.0513)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3538.0513)
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live Sync (x32 Version: 14.0.8117.416)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
Windows Media Center Add-in for Silverlight (x32 Version: 4.7.3.0)
Zattoo4 4.0.5 (x32 Version: 4.0.5)
==================== Restore Points =========================
29-10-2013 07:42:28 Windows Update
03-11-2013 18:52:16 Windows Update
04-11-2013 09:06:20 Installed Java 7 Update 45
04-11-2013 09:08:55 Installed Java 7 Update 45 (64-bit)
08-11-2013 08:21:26 Windows Update
11-11-2013 19:26:05 Windows Update
14-11-2013 13:35:51 Windows Update
17-11-2013 18:00:22 Windows-Sicherung
19-11-2013 08:27:08 Windows Update
20-11-2013 09:52:35 Windows Update
22-11-2013 15:34:14 ComboFix created restore point
==================== Hosts content: ==========================
2009-07-14 03:34 - 2013-11-22 17:10 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {03DD1734-5935-4918-8C22-73CC7FF617EC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-18] (Adobe Systems Incorporated)
Task: {3D0F265D-641D-4F98-A662-41F59EBF2821} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation)
Task: {5CD1D107-CC60-44BC-AA1E-D05D59696C82} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {6B5B2CEA-6680-4A85-951B-939BBB885622} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-02] (Google Inc.)
Task: {7BA39AB3-2698-42D1-AA38-F6D7A7379A61} - \Scheduled Update for Ask Toolbar No Task File
Task: {81C2FD50-5CB8-4027-8BA2-383D3B1EE7EC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-02] (Google Inc.)
Task: {8B0749A9-1982-4E7A-9915-87AC7C9802AD} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {96D6F6EE-4186-49D5-A936-08FD73E60CAA} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {DAC03BD6-C9BD-4A0B-B9E9-D4B3DC44B3CF} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {F2BADF04-EB10-4CEE-BA54-955834969E9B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-02-28 10:25 - 2012-10-04 18:49 - 00087152 _____ () C:\Windows\System32\cpwmon64.dll
2012-01-10 12:38 - 2012-12-11 13:07 - 01184640 _____ () C:\Program Files\Tablet\Pen\libxml2.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:23 - 2010-10-20 15:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2012-11-15 09:58 - 2012-09-19 18:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:45 - 2010-10-20 15:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2013-03-13 21:48 - 2013-03-13 21:48 - 24978944 _____ () C:\Users\Anwender\AppData\Roaming\Dropbox\bin\libcef.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2013-02-14 14:46 - 2013-02-14 14:46 - 01044048 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
2013-11-16 11:21 - 2013-11-16 11:21 - 03363952 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2013-11-22 17:05:44.337
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-11-22 17:05:44.287
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 45%
Total physical RAM: 4013.3 MB
Available physical RAM: 2191.56 MB
Total Pagefile: 8024.77 MB
Available Pagefile: 5860.27 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB
==================== Drives ================================
Drive c: (System) (Fixed) (Total:197.66 GB) (Free:77.68 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATEN) (Fixed) (Total:268.1 GB) (Free:189.6 GB) NTFS
Drive e: (Amitabha Praxis) (CDROM) (Total:0.37 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 97ECEDB4)
Partition 1: (Active) - (Size=198 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=268 GB) - (Type=07 NTFS)
Attempted reading MBR returned 0 bytes.
Could not read MBR for disk 1.
==================== End Of Log ============================ Ist's jetzt fertig?
Grüsse, Buddhi |