... die weiteren Logs: Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 01:28 on 03/03/2014 (Jan)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-03-2014 03
Ran by Jan (administrator) on JAN-PC on 03-03-2014 01:33:34
Running from C:\Users\Jan\Desktop\Virus März 2014
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
() C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Teruten) C:\Windows\system32\FsUsbExService.Exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Conexant Systems, Inc.) C:\Windows\system32\SAsrv.exe
() C:\Users\Jan\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
(Crawler.com) C:\Program Files\Spyware Terminator\st_rsser.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\ToolbarUpdater.exe
() C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\loggingserver.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2010-04-28] ()
HKLM\...\Run: [Ocs_SM] - C:\Users\Jan\AppData\Roaming\OCS\SM\SearchAnonymizer.exe [106496 2012-08-18] (OCS)
HKLM\...\Run: [vProt] - C:\Program Files\AVG Secure Search\vprot.exe [2539544 2014-03-03] ()
HKLM\...\Run: [FreePDF Assistant] - C:\Program Files\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [Smart File Advisor] - C:\Program Files\Smart File Advisor\sfa.exe [280824 2011-04-04] (Filefacts.net)
HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\update\realsched.exe [295512 2013-06-22] (RealNetworks, Inc.)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1758160 2014-02-13] (APN)
HKLM\...\Run: [NPSStartup] - [X]
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [SpywareTerminatorShield] - C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com)
HKLM\...\Run: [SpywareTerminatorUpdater] - C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com)
HKU\S-1-5-21-564274001-2427289716-4247934284-1000\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2010-04-28] ()
HKU\S-1-5-21-564274001-2427289716-4247934284-1000\...\Run: [Facebook Update] - C:\Users\Jan\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-02-07] (Facebook Inc.)
HKU\S-1-5-21-564274001-2427289716-4247934284-1000\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
HKU\S-1-5-21-564274001-2427289716-4247934284-1000\...\Run: [AutoStartNPSAgent] - C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [95576 2010-07-04] (Samsung Electronics Co., Ltd.)
HKU\S-1-5-21-564274001-2427289716-4247934284-1000\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://isearch.avg.com/?cid={37A4A90C-0782-4A07-AF7F-B60419365740}&mid=86f134904e5c47d0b04bd16f643ddd69-e308b1f7e7b3df9b85c090b2b6796e92d0fa2be3&lang=pl&ds=xn011&pr=sa&d=2013-01-06 22:09:56&v=13.3.0.17&sap=hp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7684CA621F42CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={37A4A90C-0782-4A07-AF7F-B60419365740}&mid=86f134904e5c47d0b04bd16f643ddd69-e308b1f7e7b3df9b85c090b2b6796e92d0fa2be3&lang=pl&ds=xn011&pr=sa&d=2013-01-06 22:09:56&v=15.4.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {DEFC088E-80ED-4615-ABEB-618C2F3E2265} URL = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=7cc62750-c5d4-4af1-ad19-6cf1ab7ff167&pid=freewarede&mode=bounce&k=0
SearchScopes: HKCU - {F01CFB10-6FC1-4756-A9DC-981242D80405} URL = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=7cc62750-c5d4-4af1-ad19-6cf1ab7ff167&pid=freewarede&mode=bounce&k=0
BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\18.0.0.248\AVG Secure Search_toolbar.dll (AVG Secure Search)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: DVDVideoSoft IE Extension - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
Toolbar: HKLM - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\18.0.0.248\AVG Secure Search_toolbar.dll (AVG Secure Search)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.0.0\ViProtocol.dll (AVG Secure Search)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL No File [ ]
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\yvl9e47t.default
FF Homepage: hxxp://isearch.avg.com/?cid={37A4A90C-0782-4A07-AF7F-B60419365740}&mid=86f134904e5c47d0b04bd16f643ddd69-e308b1f7e7b3df9b85c090b2b6796e92d0fa2be3&lang=pl&ds=xn011&pr=sa&d=&v=15.5.0.2&sap=hp
FF NetworkProxy: "no_proxies_on", "127.0.0.1"
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\18.0.0\\npsitesafety.dll (AVG Technologies)
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @mozilla.zeniko.ch/SumatraPDF_Browser_Plugin - C:\Program Files\SumatraPDF\npPdfViewer.dll (Simon Bünzli)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.2.32 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.2.32 - C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin HKCU: @mozilla.zeniko.ch/SumatraPDF_Browser_Plugin - C:\Program Files\SumatraPDF\npPdfViewer.dll (Simon Bünzli)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Jan\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Jan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF SearchPlugin: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\yvl9e47t.default\searchplugins\11-suche.xml
FF SearchPlugin: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\yvl9e47t.default\searchplugins\avg-secure-search.xml
FF SearchPlugin: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\yvl9e47t.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\yvl9e47t.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\yvl9e47t.default\searchplugins\google-ssl.xml
FF SearchPlugin: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\yvl9e47t.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\yvl9e47t.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Free Download Manager plugin - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\yvl9e47t.default\Extensions\fdm_ffext@freedownloadmanager.org [2012-12-12]
FF Extension: Forecastfox - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\yvl9e47t.default\Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2012-10-08]
FF Extension: FoxTrick - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\yvl9e47t.default\Extensions\{9d1f059c-cada-4111-9696-41a62d64e3ba} [2014-02-15]
FF Extension: WEB.DE MailCheck - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\yvl9e47t.default\Extensions\toolbar@web.de.xpi [2013-06-11]
FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\yvl9e47t.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi [2013-07-26]
FF Extension: Google Shortcuts - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\yvl9e47t.default\Extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}.xpi [2012-08-20]
FF Extension: Adblock Plus - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\yvl9e47t.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-06-05]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-11-18]
FF HKLM\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012-08-14]
FF HKLM\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG Secure Search\FireFoxExt\18.0.0.248
FF Extension: AVG Security Toolbar - C:\ProgramData\AVG Secure Search\FireFoxExt\18.0.0.248 [2014-03-03]
FF HKLM\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff\
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff\ []
FF HKLM\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-06-22]
========================== Services (Whitelisted) =================
R2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 AntiVirFirewallService; C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe [1012280 2013-12-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [896056 2013-12-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-12] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-17] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] (APN LLC.)
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
R2 SAService; C:\Windows\system32\SAsrv.exe [445496 2010-03-25] (Conexant Systems, Inc.)
R2 SearchAnonymizer; C:\Users\Jan\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [40960 2012-08-18] ()
R2 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [587912 2013-04-03] (Crawler.com)
R2 VMCService; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [14336 2008-07-04] (Vodafone)
R2 vToolbarUpdater18.0.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\ToolbarUpdater.exe [1759768 2014-03-03] (AVG Secure Search)
==================== Drivers (Whitelisted) ====================
R3 ACPIVPC; C:\Windows\System32\DRIVERS\AcpiVpc.sys [23136 2010-01-20] (Lenovo Corporation)
R3 avfwim; C:\Windows\System32\DRIVERS\avfwim.sys [92448 2013-08-07] (Avira GmbH)
R1 avfwot; C:\Windows\System32\DRIVERS\avfwot.sys [113024 2013-08-07] (Avira GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-03-03] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-12] (Avira Operations GmbH & Co. KG)
R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [36608 2010-06-14] ()
R1 funfrm; C:\Windows\system32\Drivers\funfrm.sys [54800 2014-01-09] ()
R1 sp_rsdrv2; C:\Windows\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-07] (Avira GmbH)
R1 StarOpen; C:\Windows\system32\Drivers\StarOpen.sys [5632 2006-07-24] ()
R3 usbsmi; C:\Windows\System32\DRIVERS\SMIksdrv.sys [168704 2009-06-19] (SMI)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-03 01:32 - 2014-03-03 01:33 - 00000000 ____D () C:\FRST
2014-03-03 01:28 - 2014-03-03 01:28 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-03-03 01:21 - 2014-03-03 01:21 - 00050477 _____ () C:\Users\Jan\Downloads\Defogger(1).exe
2014-03-03 01:14 - 2014-03-03 01:14 - 00024594 _____ () C:\Users\Default\Desktop\AVSCAN-20140302-200340-B6294516.LOG
2014-03-03 01:14 - 2014-03-03 01:14 - 00024594 _____ () C:\Users\Default User\Desktop\AVSCAN-20140302-200340-B6294516.LOG
2014-03-03 01:10 - 2014-03-03 01:33 - 00000000 ____D () C:\Users\Jan\Desktop\Virus März 2014
2014-03-02 17:19 - 2014-03-02 17:19 - 00712264 _____ () C:\Windows\isRS-000.tmp
2014-03-02 17:19 - 2014-03-02 17:19 - 00001068 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-02 17:08 - 2014-03-02 17:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Jan\Downloads\mbam-setup-1.75.0.1300.exe
2014-03-02 17:04 - 2011-06-21 11:24 - 00032768 _____ () C:\Windows\system32\Drivers\sp_rsdrv2.sys
2014-03-02 17:03 - 2014-03-02 17:24 - 00000000 ____D () C:\ProgramData\Spyware Terminator
2014-03-02 17:03 - 2014-03-02 17:04 - 00000000 ____D () C:\Program Files\Spyware Terminator
2014-03-02 17:03 - 2014-03-02 17:03 - 05049344 _____ (Crawler.com ) C:\Users\Jan\Downloads\SpywareTerminatorSetup_3.0.0.82.exe
2014-03-02 17:03 - 2014-03-02 17:03 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Spyware Terminator
2014-03-02 16:28 - 2014-03-02 16:46 - 1093420651 _____ () C:\Users\Jan\Downloads\Rio_2014-02-02_1455_486536.mp4
2014-03-02 16:27 - 2014-03-02 16:41 - 1051695051 _____ () C:\Users\Jan\Downloads\Die_Legende_der_Waechter_Wiederholung_vom_31_1_2014-02-02_1200_486536.mp4
2014-03-02 16:27 - 2014-03-02 16:39 - 1051714713 _____ () C:\Users\Jan\Downloads\Die_Legende_der_Waechter_2014-01-31_2015_486536.mp4
2014-03-02 16:20 - 2014-03-02 16:26 - 1134854085 _____ () C:\Users\Jan\Downloads\Crusoe_2014-02-02_0730_486536.mp4
2014-03-02 16:12 - 2014-03-02 16:25 - 1047879063 _____ () C:\Users\Jan\Downloads\Caprona_Das_vergessene_Land_2014-02-02_0420_486536.mp4
2014-03-02 16:11 - 2014-03-02 16:22 - 1688482571 _____ () C:\Users\Jan\Downloads\Koenigreich_der_Himmel_2014-02-02_0330_486536.mp4
2014-03-02 16:04 - 2014-03-02 16:12 - 1274803714 _____ () C:\Users\Jan\Downloads\Inspector_Barnaby_Morden_wenn_die_Blaetter_fallen_2014-02-09_0120_486536.mp4
2014-03-02 16:03 - 2014-03-02 16:14 - 1277294372 _____ () C:\Users\Jan\Downloads\Inspector_Barnaby_Der_Tote_im_Kornkreis_2014-02-02_0255_486536.mp4
2014-03-02 16:03 - 2014-03-02 16:11 - 1275038539 _____ () C:\Users\Jan\Downloads\Inspector_Barnaby_Leichen_leben_laenger_2014-02-02_0115_486536.mp4
2014-02-27 20:05 - 2014-02-27 20:12 - 1426629690 _____ () C:\Users\Jan\Downloads\From_Hell_2014-02-01_0310_486536.mp4
2014-02-27 19:32 - 2014-02-27 19:44 - 1332701470 _____ () C:\Users\Jan\Downloads\Strangers_2014-02-01_0215_486536.mp4
2014-02-27 18:43 - 2014-02-27 18:54 - 1588876831 _____ () C:\Users\Jan\Downloads\Star_Wars_Episode_VI_Die_Rueckkehr_der_2014-01-31_2015_486536.mp4
2014-02-27 00:28 - 2014-02-27 00:28 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-02-23 22:09 - 2014-02-23 22:14 - 1150789942 _____ () C:\Users\Jan\Downloads\Inspektor_Jury_Der_Tote_im_Pub_2014-01-27_2015_486536.mp4
2014-02-19 21:01 - 2014-02-19 21:06 - 937948808 _____ () C:\Users\Jan\Downloads\Susi_und_Strolch_2014-01-24_2015_486536.mp4
2014-02-17 22:27 - 2014-02-17 22:32 - 1300009964 _____ () C:\Users\Jan\Downloads\District_9_2014-01-20_0250_486536.mp4
2014-02-17 21:29 - 2014-02-17 21:32 - 705795204 _____ () C:\Users\Jan\Downloads\Zaubertrank_Asterix_2014-01-19_1735_486536.mp4
2014-02-17 19:22 - 2014-02-17 19:23 - 00000000 ____D () C:\Users\Jan\Downloads\Die Tatortreiniger
2014-02-16 20:50 - 2014-02-16 21:03 - 00000000 ____D () C:\Users\Jan\Downloads\Audiobooks
2014-02-16 20:45 - 2014-02-16 20:46 - 129647568 _____ () C:\Users\Jan\Downloads\Pratchett Terry - Świat dysku 02 - Blask Fantastyczny.rar
2014-02-16 20:45 - 2014-02-16 20:46 - 124345425 _____ () C:\Users\Jan\Downloads\Pratchett Terry - Świat dysku 01 - Kolor Magii.rar
2014-02-16 20:42 - 2014-02-16 20:44 - 247438530 _____ () C:\Users\Jan\Downloads\Funke Cornelia - Atramentowe serce [czyta Jacek Kiss].rar
2014-02-16 20:41 - 2014-02-16 20:42 - 73001022 _____ () C:\Users\Jan\Downloads\Craig Shaw Gardner - Batman.rar
2014-02-16 20:39 - 2014-02-16 20:42 - 315349421 _____ () C:\Users\Jan\Downloads\Crichton Michael - Linia Czasu.rar
2014-02-15 15:28 - 2014-02-27 00:38 - 00000000 ____D () C:\Users\Jan\Desktop\Hochzeit
2014-02-13 22:19 - 2014-02-13 22:21 - 00000000 ____D () C:\Users\Jan\Downloads\Despicable me
2014-02-13 21:45 - 2014-02-13 22:02 - 00000000 ____D () C:\Users\Jan\Downloads\Schuh des Manitu
2014-02-13 07:51 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-13 07:51 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-13 07:51 - 2014-02-06 11:19 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-13 07:51 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-13 07:51 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-13 07:51 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-13 07:51 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-13 07:51 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-13 07:51 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-13 07:51 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-13 07:51 - 2014-02-06 10:47 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-13 07:51 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-13 07:51 - 2014-02-06 10:34 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-13 07:51 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-13 07:51 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-13 07:51 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-13 07:51 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-13 07:51 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-13 07:51 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-13 07:51 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-13 07:51 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-13 07:44 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-13 07:21 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-13 07:21 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-13 07:21 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-13 07:21 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-13 07:21 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-13 07:20 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-13 07:20 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-13 07:20 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-13 07:20 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-13 07:20 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-13 07:20 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-13 07:20 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-13 07:20 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-13 07:20 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-12 07:30 - 2014-02-12 07:43 - 1198751009 _____ () C:\Users\Jan\Downloads\Wenn_Traeume_fliegen_lernen_2014-01-18_2015_486536.mp4
2014-02-11 22:55 - 2014-02-28 21:03 - 00000000 ____D () C:\Users\Jan\Downloads\Hancock
2014-02-11 17:53 - 2014-02-11 17:58 - 1603737081 _____ () C:\Users\Jan\Downloads\Die_neun_Pforten_2014-01-16_0110_486536.mp4
2014-02-11 17:51 - 2014-02-11 17:52 - 1154159585 _____ () C:\Users\Jan\Downloads\Riverworld_Teil_2_2014-01-14_2215_486536.mp4
2014-02-10 21:10 - 2014-02-13 07:24 - 00000000 ____D () C:\Users\Jan\Downloads\In & out
2014-02-10 19:39 - 2014-02-10 19:42 - 00000000 ____D () C:\Users\Jan\Desktop\Wohnung
2014-02-10 07:37 - 2014-02-10 07:56 - 1310433181 _____ () C:\Users\Jan\Downloads\Whiteout_2014-01-12_2225_486536.mp4
2014-02-10 07:36 - 2014-02-10 07:46 - 1145516531 _____ () C:\Users\Jan\Downloads\Invasion_2014-01-12_0155_486536.mp4
2014-02-09 23:12 - 2014-02-13 07:23 - 00000000 ____D () C:\Users\Jan\Downloads\Bärenbrüder
2014-02-09 17:16 - 2014-02-09 17:23 - 1235265416 _____ () C:\Users\Jan\Downloads\Die_Abenteuer_von_Tim_und_Struppi_2014-01-11_2015_486536.mp4
2014-02-08 19:53 - 2014-02-08 19:53 - 00000000 ____D () C:\Users\Jan\Downloads\Hoshi_o_ou_kodomo_2011_(NAPISY-120341).NS
2014-02-08 19:52 - 2011-12-28 14:50 - 00050130 ____N () C:\Users\Jan\Downloads\Children Who Chase Lost Voices From Deep Below.txt
2014-02-08 19:48 - 2014-02-08 19:48 - 00044131 _____ () C:\Users\Jan\Downloads\Hoshi o Ou Kodomo [Napisy PL] [2011].txt
2014-02-08 19:48 - 2014-02-08 19:48 - 00021283 _____ () C:\Users\Jan\Downloads\Hoshi_o_ou_kodomo_2011_(NAPISY-120341).NS.zip
2014-02-07 22:02 - 2005-10-28 18:36 - 00053396 ____N () C:\Users\Jan\Downloads\Madagascar.DVDRip.XviD-DoNE.txt
2014-02-07 21:58 - 2014-02-07 21:58 - 00025352 _____ () C:\Users\Jan\Downloads\Madagascar_(NAPISY-72765).NS.zip
2014-02-07 21:48 - 2014-02-07 21:48 - 00028150 _____ () C:\Users\Jan\Downloads\Brave_Story_Aragami_AnimeSubInfo_id16274.zip
2014-02-07 21:47 - 2014-02-07 21:47 - 00025001 _____ () C:\Users\Jan\Downloads\Brave_Story_Aragami_AnimeSubInfo_id17599.zip
2014-02-06 23:13 - 2014-02-06 23:14 - 00000000 ____D () C:\Users\Jan\Downloads\pan lodowego ogrodu
2014-02-05 21:35 - 2014-02-05 21:38 - 734138368 _____ () C:\Users\Jan\Downloads\Die Vergessenen.avi
2014-02-05 08:43 - 2014-02-05 08:45 - 00000000 ____D () C:\Users\Jan\Downloads\czarnoksieznik z archipelagu
2014-02-04 23:14 - 2014-02-05 21:14 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird
==================== One Month Modified Files and Folders =======
2014-03-03 01:33 - 2014-03-03 01:32 - 00000000 ____D () C:\FRST
2014-03-03 01:33 - 2014-03-03 01:10 - 00000000 ____D () C:\Users\Jan\Desktop\Virus März 2014
2014-03-03 01:33 - 2012-06-01 14:57 - 01866315 _____ () C:\Windows\WindowsUpdate.log
2014-03-03 01:28 - 2014-03-03 01:28 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-03-03 01:28 - 2013-08-11 00:54 - 00003730 _____ () C:\Program Files\Mozilla Firefoxavg-secure-search.xml
2014-03-03 01:28 - 2012-09-22 12:55 - 00001092 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-03 01:27 - 2013-01-06 22:09 - 00042784 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys
2014-03-03 01:27 - 2013-01-06 22:09 - 00000000 ____D () C:\Program Files\AVG Secure Search
2014-03-03 01:21 - 2014-03-03 01:21 - 00050477 _____ () C:\Users\Jan\Downloads\Defogger(1).exe
2014-03-03 01:21 - 2012-06-04 14:52 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-03 01:14 - 2014-03-03 01:14 - 00024594 _____ () C:\Users\Default\Desktop\AVSCAN-20140302-200340-B6294516.LOG
2014-03-03 01:14 - 2014-03-03 01:14 - 00024594 _____ () C:\Users\Default User\Desktop\AVSCAN-20140302-200340-B6294516.LOG
2014-03-02 22:48 - 2013-02-07 01:43 - 00000920 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-564274001-2427289716-4247934284-1000UA.job
2014-03-02 18:29 - 2012-06-05 21:28 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Skype
2014-03-02 17:37 - 2009-07-14 05:34 - 00014240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-02 17:37 - 2009-07-14 05:34 - 00014240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-02 17:28 - 2012-09-22 12:55 - 00001088 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-02 17:27 - 2013-01-06 01:00 - 00029556 _____ () C:\Windows\setupact.log
2014-03-02 17:27 - 2012-10-15 19:08 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-03-02 17:27 - 2012-06-04 15:03 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-03-02 17:27 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-02 17:24 - 2014-03-02 17:03 - 00000000 ____D () C:\ProgramData\Spyware Terminator
2014-03-02 17:19 - 2014-03-02 17:19 - 00712264 _____ () C:\Windows\isRS-000.tmp
2014-03-02 17:19 - 2014-03-02 17:19 - 00001068 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-02 17:08 - 2014-03-02 17:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Jan\Downloads\mbam-setup-1.75.0.1300.exe
2014-03-02 17:04 - 2014-03-02 17:03 - 00000000 ____D () C:\Program Files\Spyware Terminator
2014-03-02 17:03 - 2014-03-02 17:03 - 05049344 _____ (Crawler.com ) C:\Users\Jan\Downloads\SpywareTerminatorSetup_3.0.0.82.exe
2014-03-02 17:03 - 2014-03-02 17:03 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Spyware Terminator
2014-03-02 16:46 - 2014-03-02 16:28 - 1093420651 _____ () C:\Users\Jan\Downloads\Rio_2014-02-02_1455_486536.mp4
2014-03-02 16:41 - 2014-03-02 16:27 - 1051695051 _____ () C:\Users\Jan\Downloads\Die_Legende_der_Waechter_Wiederholung_vom_31_1_2014-02-02_1200_486536.mp4
2014-03-02 16:39 - 2014-03-02 16:27 - 1051714713 _____ () C:\Users\Jan\Downloads\Die_Legende_der_Waechter_2014-01-31_2015_486536.mp4
2014-03-02 16:26 - 2014-03-02 16:20 - 1134854085 _____ () C:\Users\Jan\Downloads\Crusoe_2014-02-02_0730_486536.mp4
2014-03-02 16:25 - 2014-03-02 16:12 - 1047879063 _____ () C:\Users\Jan\Downloads\Caprona_Das_vergessene_Land_2014-02-02_0420_486536.mp4
2014-03-02 16:22 - 2014-03-02 16:11 - 1688482571 _____ () C:\Users\Jan\Downloads\Koenigreich_der_Himmel_2014-02-02_0330_486536.mp4
2014-03-02 16:14 - 2014-03-02 16:03 - 1277294372 _____ () C:\Users\Jan\Downloads\Inspector_Barnaby_Der_Tote_im_Kornkreis_2014-02-02_0255_486536.mp4
2014-03-02 16:12 - 2014-03-02 16:04 - 1274803714 _____ () C:\Users\Jan\Downloads\Inspector_Barnaby_Morden_wenn_die_Blaetter_fallen_2014-02-09_0120_486536.mp4
2014-03-02 16:11 - 2014-03-02 16:03 - 1275038539 _____ () C:\Users\Jan\Downloads\Inspector_Barnaby_Leichen_leben_laenger_2014-02-02_0115_486536.mp4
2014-03-02 13:09 - 2014-01-25 03:02 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\vlc
2014-03-02 01:48 - 2013-02-07 01:43 - 00000898 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-564274001-2427289716-4247934284-1000Core.job
2014-03-01 20:14 - 2013-05-26 23:26 - 00000000 ____D () C:\Users\Jan\Documents\Marzenka
2014-02-28 21:03 - 2014-02-11 22:55 - 00000000 ____D () C:\Users\Jan\Downloads\Hancock
2014-02-28 21:02 - 2012-06-01 15:18 - 01649492 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-28 03:09 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-02-27 20:12 - 2014-02-27 20:05 - 1426629690 _____ () C:\Users\Jan\Downloads\From_Hell_2014-02-01_0310_486536.mp4
2014-02-27 19:44 - 2014-02-27 19:32 - 1332701470 _____ () C:\Users\Jan\Downloads\Strangers_2014-02-01_0215_486536.mp4
2014-02-27 18:54 - 2014-02-27 18:43 - 1588876831 _____ () C:\Users\Jan\Downloads\Star_Wars_Episode_VI_Die_Rueckkehr_der_2014-01-31_2015_486536.mp4
2014-02-27 17:29 - 2012-06-04 07:55 - 00073680 _____ () C:\Windows\PFRO.log
2014-02-27 00:38 - 2014-02-15 15:28 - 00000000 ____D () C:\Users\Jan\Desktop\Hochzeit
2014-02-27 00:29 - 2012-06-05 21:28 - 00000000 ____D () C:\ProgramData\Skype
2014-02-27 00:28 - 2014-02-27 00:28 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-02-27 00:28 - 2012-06-05 21:28 - 00000000 ___RD () C:\Program Files\Skype
2014-02-27 00:27 - 2012-07-30 21:29 - 00000000 ____D () C:\Users\Jan\.gimp-2.8
2014-02-23 22:14 - 2014-02-23 22:09 - 1150789942 _____ () C:\Users\Jan\Downloads\Inspektor_Jury_Der_Tote_im_Pub_2014-01-27_2015_486536.mp4
2014-02-21 02:21 - 2012-06-04 14:52 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-02-21 02:21 - 2012-06-04 14:52 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-02-19 21:06 - 2014-02-19 21:01 - 937948808 _____ () C:\Users\Jan\Downloads\Susi_und_Strolch_2014-01-24_2015_486536.mp4
2014-02-17 22:32 - 2014-02-17 22:27 - 1300009964 _____ () C:\Users\Jan\Downloads\District_9_2014-01-20_0250_486536.mp4
2014-02-17 21:32 - 2014-02-17 21:29 - 705795204 _____ () C:\Users\Jan\Downloads\Zaubertrank_Asterix_2014-01-19_1735_486536.mp4
2014-02-17 19:23 - 2014-02-17 19:22 - 00000000 ____D () C:\Users\Jan\Downloads\Die Tatortreiniger
2014-02-17 04:43 - 2012-06-05 19:17 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-16 21:03 - 2014-02-16 20:50 - 00000000 ____D () C:\Users\Jan\Downloads\Audiobooks
2014-02-16 20:46 - 2014-02-16 20:45 - 129647568 _____ () C:\Users\Jan\Downloads\Pratchett Terry - Świat dysku 02 - Blask Fantastyczny.rar
2014-02-16 20:46 - 2014-02-16 20:45 - 124345425 _____ () C:\Users\Jan\Downloads\Pratchett Terry - Świat dysku 01 - Kolor Magii.rar
2014-02-16 20:44 - 2014-02-16 20:42 - 247438530 _____ () C:\Users\Jan\Downloads\Funke Cornelia - Atramentowe serce [czyta Jacek Kiss].rar
2014-02-16 20:42 - 2014-02-16 20:41 - 73001022 _____ () C:\Users\Jan\Downloads\Craig Shaw Gardner - Batman.rar
2014-02-16 20:42 - 2014-02-16 20:39 - 315349421 _____ () C:\Users\Jan\Downloads\Crichton Michael - Linia Czasu.rar
2014-02-16 13:37 - 2013-11-18 00:14 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-14 22:36 - 2013-11-28 06:14 - 00000000 ____D () C:\Windows\rescache
2014-02-13 22:21 - 2014-02-13 22:19 - 00000000 ____D () C:\Users\Jan\Downloads\Despicable me
2014-02-13 22:02 - 2014-02-13 21:45 - 00000000 ____D () C:\Users\Jan\Downloads\Schuh des Manitu
2014-02-13 07:48 - 2013-08-15 14:49 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-13 07:46 - 2012-06-04 08:28 - 85946576 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-13 07:43 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-02-13 07:24 - 2014-02-10 21:10 - 00000000 ____D () C:\Users\Jan\Downloads\In & out
2014-02-13 07:23 - 2014-02-09 23:12 - 00000000 ____D () C:\Users\Jan\Downloads\Bärenbrüder
2014-02-12 07:43 - 2014-02-12 07:30 - 1198751009 _____ () C:\Users\Jan\Downloads\Wenn_Traeume_fliegen_lernen_2014-01-18_2015_486536.mp4
2014-02-11 17:58 - 2014-02-11 17:53 - 1603737081 _____ () C:\Users\Jan\Downloads\Die_neun_Pforten_2014-01-16_0110_486536.mp4
2014-02-11 17:52 - 2014-02-11 17:51 - 1154159585 _____ () C:\Users\Jan\Downloads\Riverworld_Teil_2_2014-01-14_2215_486536.mp4
2014-02-10 19:42 - 2014-02-10 19:39 - 00000000 ____D () C:\Users\Jan\Desktop\Wohnung
2014-02-10 07:56 - 2014-02-10 07:37 - 1310433181 _____ () C:\Users\Jan\Downloads\Whiteout_2014-01-12_2225_486536.mp4
2014-02-10 07:46 - 2014-02-10 07:36 - 1145516531 _____ () C:\Users\Jan\Downloads\Invasion_2014-01-12_0155_486536.mp4
2014-02-09 17:23 - 2014-02-09 17:16 - 1235265416 _____ () C:\Users\Jan\Downloads\Die_Abenteuer_von_Tim_und_Struppi_2014-01-11_2015_486536.mp4
2014-02-08 19:53 - 2014-02-08 19:53 - 00000000 ____D () C:\Users\Jan\Downloads\Hoshi_o_ou_kodomo_2011_(NAPISY-120341).NS
2014-02-08 19:48 - 2014-02-08 19:48 - 00044131 _____ () C:\Users\Jan\Downloads\Hoshi o Ou Kodomo [Napisy PL] [2011].txt
2014-02-08 19:48 - 2014-02-08 19:48 - 00021283 _____ () C:\Users\Jan\Downloads\Hoshi_o_ou_kodomo_2011_(NAPISY-120341).NS.zip
2014-02-07 21:58 - 2014-02-07 21:58 - 00025352 _____ () C:\Users\Jan\Downloads\Madagascar_(NAPISY-72765).NS.zip
2014-02-07 21:48 - 2014-02-07 21:48 - 00028150 _____ () C:\Users\Jan\Downloads\Brave_Story_Aragami_AnimeSubInfo_id16274.zip
2014-02-07 21:47 - 2014-02-07 21:47 - 00025001 _____ () C:\Users\Jan\Downloads\Brave_Story_Aragami_AnimeSubInfo_id17599.zip
2014-02-06 23:14 - 2014-02-06 23:13 - 00000000 ____D () C:\Users\Jan\Downloads\pan lodowego ogrodu
2014-02-06 11:38 - 2014-02-13 07:51 - 17103872 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-06 11:20 - 2014-02-13 07:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-06 11:19 - 2014-02-13 07:51 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-06 11:01 - 2014-02-13 07:51 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-06 11:00 - 2014-02-13 07:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-06 10:57 - 2014-02-13 07:51 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-06 10:52 - 2014-02-13 07:51 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-06 10:52 - 2014-02-13 07:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-06 10:49 - 2014-02-13 07:51 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-06 10:47 - 2014-02-13 07:51 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-06 10:47 - 2014-02-13 07:51 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-06 10:46 - 2014-02-13 07:51 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-06 10:34 - 2014-02-13 07:51 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-06 10:25 - 2014-02-13 07:51 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-06 10:25 - 2014-02-13 07:51 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-06 10:13 - 2014-02-13 07:51 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-06 10:09 - 2014-02-13 07:51 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-06 10:03 - 2014-02-13 07:51 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-06 09:41 - 2014-02-13 07:51 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-06 09:36 - 2014-02-13 07:51 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-06 09:34 - 2014-02-13 07:51 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-05 21:38 - 2014-02-05 21:35 - 734138368 _____ () C:\Users\Jan\Downloads\Die Vergessenen.avi
2014-02-05 21:14 - 2014-02-04 23:14 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird
2014-02-05 08:45 - 2014-02-05 08:43 - 00000000 ____D () C:\Users\Jan\Downloads\czarnoksieznik z archipelagu
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-28 02:14
==================== End Of Log ============================ --- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 02-03-2014 03
Ran by Jan at 2014-03-03 01:34:12
Running from C:\Users\Jan\Desktop\Virus März 2014
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
µTorrent (HKCU\...\uTorrent) (Version: 3.3.2.30416 - BitTorrent Inc.)
7-Zip 9.20 (HKLM\...\7-Zip) (Version: - )
AAVUpdateManager (HKLM\...\{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}) (Version: 18.00.0000 - Wolters Kluwer Deutschland GmbH)
Adobe Flash Player 12 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 12.0.0.70 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated)
ALPS Touch Pad Driver (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: - )
Anatomy Trains (HKLM\...\Anatomy Trains) (Version: 1.00.000 - Primal Pictures)
Apple Application Support (HKLM\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{E14ADE0E-75F3-4A46-87E5-26692DD626EC}) (Version: 6.1.0.13 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AVG Security Toolbar (HKLM\...\AVG Secure Search) (Version: 18.0.0.248 - AVG Technologies)
Avira Internet Security (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.2.286 - Avira)
Avira SearchFree Toolbar (HKLM\...\{41564952-412D-5637-00A7-A758B70C0A03}) (Version: 12.10.3.4487 - APN, LLC)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Citavi (HKLM\...\{E12C6653-1FF0-4686-ADB8-589C13AE761F}) (Version: 3.2.0.0 - Swiss Academic Software)
Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.119.0.60 - Conexant)
Dziobas Rar Player 0.009.52 (HKLM\...\Dziobas Rar Player_is1) (Version: - Kamil Dzióbek)
EasyCapture (HKLM\...\EasyCapture4.0) (Version: V4.0.09.0731 - Lenovo)
Erie (HKLM\...\UDK-b8268cc7-ddbf-4616-9b3b-52866580cee0) (Version: - Epic Games, Inc.)
Facebook Video Calling 2.0.0.447 (HKLM\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited)
Foldit (HKLM\...\Foldit) (Version: - )
Free Download Manager 3.9.2 (HKLM\...\Free Download Manager_is1) (Version: - FreeDownloadManager.ORG)
Free YouTube to MP3 Converter version 3.12.14.1022 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.14.1022 - DVDVideoSoft Ltd.)
FreePDF (Remove only) (HKLM\...\FreePDF_XP) (Version: - )
GIMP 2.8.0 (HKLM\...\GIMP-2_is1) (Version: 2.8.0 - The GIMP Team)
Google Earth (HKLM\...\{3E8A20E1-223F-11E2-9116-B8AC6F98CCE3}) (Version: 7.0.1.8244 - Google)
Google Update Helper (Version: 1.3.22.5 - Google Inc.) Hidden
GPL Ghostscript (HKLM\...\GPL Ghostscript 9.04) (Version: 9.04 - Artifex Software Inc.)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.32 - Irfan Skiljan)
IsoBuster 3.1 (HKLM\...\IsoBuster_is1) (Version: 3.1 - Smart Projects)
iTunes (HKLM\...\{91FD46D2-4FB7-4A51-8637-556E1BE1DB7C}) (Version: 11.0.4.4 - Apple Inc.)
Java 7 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.450 - Oracle)
Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
JavaFX 2.1.1 (HKLM\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 1.1 (HKLM\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM\...\{90850407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 27.0.1 (x86 de) (HKLM\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla)
Mozilla Thunderbird 24.3.0 (x86 de) (HKLM\...\Mozilla Thunderbird 24.3.0 (x86 de)) (Version: 24.3.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NVIDIA 3D Vision Treiber 314.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 314.22 - NVIDIA Corporation)
NVIDIA Grafiktreiber 314.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 314.22 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.23.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.23.1 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.115.743 - NVIDIA Corporation) Hidden
NVIDIA PhysX (Version: 9.12.1031 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.12.1031 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.1031 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.1422 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 314.22 (Version: 314.22 - NVIDIA Corporation) Hidden
NVIDIA Update 1.12.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.12.12 - NVIDIA Corporation)
NVIDIA Update Components (Version: 1.12.12 - NVIDIA Corporation) Hidden
OpenOffice.org 3.4 (HKLM\...\{4C552FD3-2CCD-4E00-AC64-0681DBB3F8B5}) (Version: 3.4.9590 - OpenOffice.org)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.4.0 - Frank Heindörfer, Philip Chinery)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.209.0 - Tracker Software Products Ltd)
PlanetSide 2 (HKCU\...\soe-PlanetSide 2 PSG) (Version: 1.0.3.183 - Sony Online Entertainment)
QuickTime (HKLM\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
RealDownloader (Version: 1.3.2 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM\...\RealPlayer 16.0) (Version: 16.0.2 - RealNetworks)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: - )
roomeon 3D-Planer (HKLM\...\{EDEE71DB-99FD-4672-8E6A-B314865D0D4C}) (Version: 1.4.2 - roomeon GmbH)
Samsung Mobile phone USB driver Drive Software (HKLM\...\Samsung Mobile phone USB driver Drive) (Version: - )
Samsung New PC Studio (HKLM\...\InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.)
Samsung New PC Studio (Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.650.0 - SAMSUNG Electronics Co., Ltd.)
Scribus 1.4.2 (HKLM\...\Scribus 1.4.2) (Version: 1.4.2 - The Scribus Team)
SearchAnonymizer (HKLM\...\SearchAnonymizer) (Version: 1.0.1 (de) - )
Sid Meier's Pirates! (HKLM\...\InstallShield_{1632FD86-1BA4-4FC4-8B25-A8C655D63F68}) (Version: 2.00.0000 - Ihr Firmenname)
Sid Meier's Pirates! (Version: 2.00.0000 - Ihr Firmenname) Hidden
Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.10.9560 - Skype Technologies S.A.)
Skype™ 6.14 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
SleepTimer Ultimate 1.2 (HKLM\...\{0EE56463-49B2-45E1-B74F-3E0139DBC986}_is1) (Version: - Christian Handorf)
Smart File Advisor 1.1.1 (HKLM\...\Smart File Advisor_is1) (Version: 1.1.1 - Filefacts.net)
Spyware Terminator 2012 (HKLM\...\{56736259-613E-4A3B-B428-6235F2E76F44}_is1) (Version: 3.0.0.82 - Crawler.com)
Steuer-Software 2012 (HKLM\...\{F19178B7-F232-4E97-8511-E4D37A339E9C}) (Version: 17.11 - Wolters Kluwer Deutschland GmbH)
Steuer-Software 2013 (HKLM\...\{3193DDB1-8F15-43DA-85D5-4796BF645914}) (Version: 18.09 - Wolters Kluwer Deutschland GmbH)
StreamTransport version: 1.0.2.2171 (HKLM\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version: - )
SubEdit-Player (HKLM\...\SubEdit-Player_is1) (Version: 4072 - Artur Sikora)
SumatraPDF (HKLM\...\SumatraPDF) (Version: 2.1.1 - Krzysztof Kowalczyk)
Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS)
VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN)
Vodafone Mobile Connect Lite (HKLM\...\{C656142F-EFE1-44CD-BFAD-6CBC6DCB9860}) (Version: 9.3.3.10523 - Vodafone)
XMedia Recode Version 3.1.3.6 (HKLM\...\{DDA3C325-47B2-4730-9672-BF3771C08799}_is1) (Version: 3.1.3.6 - XMedia Recode)
Zoom Player (remove only) (HKLM\...\ZoomPlayer) (Version: - )
==================== Restore Points =========================
==================== Hosts content: ==========================
2009-07-14 03:04 - 2012-10-22 18:14 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {04C5B5E3-9412-49A3-97BF-ABA6F9E3EFB4} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {06AAD2D1-935C-4755-A74A-4BE8D7338404} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {0A770AC7-5385-4EA2-88D9-15DD554D8787} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {0D9B5D92-3A22-486D-A887-3AA21597CF27} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started <==== ATTENTION
Task: {0E3531A7-718D-451E-82E2-04406731E286} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {127DAC02-3498-4FB8-BBDE-8A919D3396D7} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {1DDAA103-DE8E-49BB-A448-B95CA41A2010} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline => C:\Windows\system32\schtasks.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {2375F586-1009-41FB-B54E-30D8AF2B781D} - System32\Tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary => C:\Program Files\Windows Media Player\wmpnscfg.exe [2009-07-14] (Microsoft Corporation) <==== ATTENTION
Task: {2B51307A-D9A0-40D8-BA87-7D72BB38ACBC} - System32\Tasks\{C35DEC40-B67A-4CA2-BB76-4BC345BE6C82} => C:\Windows\system32\pcalua.exe [2009-07-14] (Microsoft Corporation) <==== ATTENTION
Task: {2C59ECAF-3A27-4640-9F4B-519B05BDD70F} - System32\Tasks\Microsoft\Windows\MUI\LPRemove => C:\Windows\system32\lpremove.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {2C6740F4-5D9D-4034-A525-774D336738F9} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {345C6656-D662-41FD-8EF9-3CDC6373D644} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {3EB99184-EA25-467A-8927-80BB03BBDB3E} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {3FFA3948-8DEA-44BC-AAAB-5479BB100245} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {547E4689-F607-443C-A7CA-008A10788FFD} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {5B184694-64C3-4633-94C5-945B3FA561D6} - System32\Tasks\Microsoft\Windows\WindowsBackup\ConfigNotification => C:\Windows\System32\sdclt.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {60158C7A-6808-42CD-95EE-AFD9A57925DB} - System32\Tasks\Microsoft\Windows\AppID\PolicyConverter => C:\Windows\system32\appidpolicyconverter.exe [2009-07-14] (Microsoft Corporation) <==== ATTENTION
Task: {62454169-C882-4D29-B5A6-CEDFDCA2A5A8} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-564274001-2427289716-4247934284-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) <==== ATTENTION
Task: {6962E6DE-6E80-49B5-B32B-681C95A4148A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-09-22] (Google Inc.) <==== ATTENTION
Task: {6AEF0C98-2CB4-4B67-8C70-4C977C7355CC} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => Sc.exe start sppsvc <==== ATTENTION
Task: {6B7AC694-8D6D-481B-9DD8-2A3A741ADA6D} - System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem => C:\Windows\System32\powercfg.exe [2009-07-14] (Microsoft Corporation) <==== ATTENTION
Task: {6E8FB9F0-DD13-48E8-B830-2E039E434944} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {6FBC31AF-357D-4104-ABDE-C8E450906AF0} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {731E9C62-95B5-4C8C-AB64-4CC591C9FF5B} - System32\Tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask => C:\Windows\system32\RAServer.exe [2009-07-14] (Microsoft Corporation) <==== ATTENTION
Task: {7D3C7871-A917-4EF0-82E8-5F0A96423051} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => C:\Windows\system32\BthUdTask.exe [2009-07-14] (Microsoft Corporation) <==== ATTENTION
Task: {80DB6C5D-1FDA-4D8B-A01F-405FD047AB21} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {84C36FC8-9D6C-4964-ABA0-67FBC123E962} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {907EC567-71EC-45CB-A024-759DE949375A} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {91A5E8CE-29B9-477A-9938-87429EF69D0C} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-564274001-2427289716-4247934284-1000Core => C:\Users\Jan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-07] (Facebook Inc.) <==== ATTENTION
Task: {953C2A11-2E36-4AAD-AE98-4FBE6FE01DF9} - System32\Tasks\{E353273D-6CE7-42B4-8784-831B38A64A73} => C:\Windows\system32\pcalua.exe [2009-07-14] (Microsoft Corporation) <==== ATTENTION
Task: {9BDEEC21-D7AB-4B53-9201-013B90588033} - System32\Tasks\{84E1AFC6-562C-4649-80FC-8B70AD55C73D} => C:\Windows\system32\pcalua.exe [2009-07-14] (Microsoft Corporation) <==== ATTENTION
Task: {A6394592-54CE-4E93-8D64-1A068F462632} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator => C:\Windows\System32\wsqmcons.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {A63D4C6F-EEE4-420C-AE88-60C44816D629} - System32\Tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver => C:\Windows\system32\DFDWiz.exe [2009-07-14] (Microsoft Corporation) <==== ATTENTION
Task: {A7297587-3C7D-4FF5-8F35-0802185873B9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-09-22] (Google Inc.) <==== ATTENTION
Task: {A982CCB9-228D-4762-9F6C-8B6A55235F73} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-564274001-2427289716-4247934284-1000UA => C:\Users\Jan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-07] (Facebook Inc.) <==== ATTENTION
Task: {AD76C7E9-2BE4-426D-ABEC-72C6EF24545B} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {AEB94145-02D7-4F62-8E5C-1260AB6B26E2} - System32\Tasks\{E92EE4C8-A1A4-4F2C-865E-0FD6E660E886} => C:\Windows\system32\pcalua.exe [2009-07-14] (Microsoft Corporation) <==== ATTENTION
Task: {B9BEE219-C29E-4310-819C-147A5A0E045E} - System32\Tasks\Microsoft\Windows\Defrag\ScheduledDefrag => C:\Windows\system32\defrag.exe [2009-07-14] (Microsoft Corp.) <==== ATTENTION
Task: {C90440A0-6D8F-423F-8F42-83EEF05CE708} - System32\Tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck => C:\Windows\system32\appidcertstorecheck.exe [2009-07-14] (Microsoft Corporation) <==== ATTENTION
Task: {D21F6024-191F-4454-BBBC-09A650DA2549} - System32\Tasks\Microsoft\Windows\Application Experience\AitAgent => C:\Windows\system32\aitagent.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {D622195C-D680-4FEA-9C56-59660C7C9E94} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => Sc.exe config upnphost start= auto <==== ATTENTION
Task: {D7947F82-89CC-466F-947E-97C35C3FBAB9} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {DA839948-AFC8-4723-A822-F1DF5A8A945C} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {DAC3429C-242B-4D38-9D24-47C82D2CA6D3} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2012-12-10] (Microsoft Corporation) <==== ATTENTION
Task: {DE8699D2-8A05-42F7-8A85-5162AF47D26A} - System32\Tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting => C:\Windows\system32\wermgr.exe [2009-07-14] (Microsoft Corporation) <==== ATTENTION
Task: {E2C97803-5C7B-4FB5-9027-8AF5FCE37DF9} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-564274001-2427289716-4247934284-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) <==== ATTENTION
Task: {E8164C0D-216C-4B6B-9EB8-31BF958B8014} - System32\Tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo => C:\Windows\system32\gatherNetworkInfo.vbs [2009-06-10] () <==== ATTENTION
Task: {EAC01733-7E2C-47C7-8817-B08F4102ECD6} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {EF08ED29-C47B-43E3-A611-74DD8198CB19} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: {EF4048A0-9D9F-4EA6-9597-AC0385E059AC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-21] (Adobe Systems Incorporated) <==== ATTENTION
Task: {F93C7104-998A-4A38-B935-775A3138B3C3} - System32\Tasks\Microsoft\Windows\Location\Notifications => C:\Windows\System32\LocationNotifications.exe [2009-07-14] (Microsoft Corporation) <==== ATTENTION
Task: {FC20D953-95BF-4EC7-8E72-EB604C1DE16F} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe [2010-11-20] (Microsoft Corporation) <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-564274001-2427289716-4247934284-1000Core.job => C:\Users\Jan\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-564274001-2427289716-4247934284-1000UA.job => C:\Users\Jan\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-05-09 15:32 - 2013-03-15 03:59 - 00078624 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2013-08-09 17:16 - 2013-04-15 10:49 - 00176128 _____ () C:\Windows\System32\HP1006LM.DLL
2013-01-24 19:53 - 2010-06-17 21:56 - 00116224 _____ () C:\Windows\System32\redmonnt.dll
2013-08-09 17:16 - 2013-04-15 10:49 - 00059904 _____ () C:\Windows\system32\spool\PRTPROCS\W32X86\HP1006PP.dll
2013-08-07 12:22 - 2013-08-07 10:00 - 00394824 _____ () C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
2008-10-24 15:35 - 2008-10-24 15:35 - 00128296 _____ () C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
2013-01-28 12:08 - 2013-01-28 12:08 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2013-01-28 12:08 - 2013-01-28 12:08 - 01242512 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-04-16 02:07 - 2013-04-16 02:07 - 00039056 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
2012-08-18 22:18 - 2012-08-18 22:18 - 00040960 _____ () C:\Users\Jan\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
2013-08-07 12:22 - 2012-01-31 07:42 - 00447848 _____ () C:\Program Files\Avira\AntiVir Desktop\libxml2.dll
2013-08-07 12:22 - 2012-01-31 07:42 - 00060264 _____ () C:\Program Files\Avira\AntiVir Desktop\cares.dll
2013-11-18 00:14 - 2014-02-16 13:37 - 03578992 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2014-03-03 01:28 - 2014-03-03 01:27 - 00159768 _____ () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\loggingserver.exe
2014-03-03 01:28 - 2014-03-03 01:27 - 00519704 _____ () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\log4cplusU.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== Disabled items from MSCONFIG ==============
MSCONFIG\startupreg: MobileConnect => %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
MSCONFIG\startupreg: NvCplDaemon => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SmartAudio => C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (03/02/2014 05:27:30 PM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
Error: (03/02/2014 06:12:34 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4992
Error: (03/02/2014 06:12:34 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 4992
Error: (03/02/2014 06:12:34 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (03/02/2014 01:13:13 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (03/01/2014 08:35:44 PM) (Source: Application Hang) (User: )
Description: Programm firefox.exe, Version 27.0.1.5156 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: d58
Startzeit: 01cf357e43af74b7
Endzeit: 271
Anwendungspfad: C:\Program Files\Mozilla Firefox\firefox.exe
Berichts-ID: 9edcbd59-a178-11e3-bd5b-002622d9349a
Error: (03/01/2014 07:40:45 PM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
Error: (03/01/2014 04:07:15 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5070
Error: (03/01/2014 04:07:15 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5070
Error: (03/01/2014 04:07:15 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
System errors:
=============
Error: (03/02/2014 05:31:18 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80004005
Error: (03/02/2014 05:31:01 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
Error: (03/02/2014 04:40:15 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht vergrößert werden kann.
Error: (03/01/2014 07:44:03 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
Error: (02/28/2014 09:00:15 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst LanmanServer erreicht.
Error: (02/27/2014 05:32:10 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80004005
Error: (02/26/2014 06:21:11 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80004005
Error: (02/22/2014 08:34:20 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst LanmanServer erreicht.
Error: (02/21/2014 04:31:57 PM) (Source: DCOM) (User: )
Description: 1053WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error: (02/21/2014 04:31:57 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Microsoft Office Sessions:
=========================
Error: (03/02/2014 05:27:30 PM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
Error: (03/02/2014 06:12:34 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4992
Error: (03/02/2014 06:12:34 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 4992
Error: (03/02/2014 06:12:34 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (03/02/2014 01:13:13 AM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe
Error: (03/01/2014 08:35:44 PM) (Source: Application Hang)(User: )
Description: firefox.exe27.0.1.5156d5801cf357e43af74b7271C:\Program Files\Mozilla Firefox\firefox.exe9edcbd59-a178-11e3-bd5b-002622d9349a
Error: (03/01/2014 07:40:45 PM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
Error: (03/01/2014 04:07:15 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5070
Error: (03/01/2014 04:07:15 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5070
Error: (03/01/2014 04:07:15 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
==================== Memory info ===========================
Percentage of memory in use: 49%
Total physical RAM: 3036.6 MB
Available physical RAM: 1545.15 MB
Total Pagefile: 7130.89 MB
Available Pagefile: 5376.58 MB
Total Virtual: 2047.88 MB
Available Virtual: 1878.94 MB
==================== Drives ================================
Drive c: ( ) (Fixed) (Total:465.76 GB) (Free:30.48 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 0FDCB09E)
Partition: GPT Partition Type.
==================== End Of Log ============================ Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-03-03 02:14:50
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD5000BPVT-22HXZT3 rev.01.01A01 465,76GB
Running: Gmer-19357.exe; Driver: C:\Temp\pwldypow.sys
---- System - GMER 2.1 ----
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwClose [0x90602444]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwCreateFile [0x90601C8A]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwCreateKey [0x90601958]
SSDT 963D02A6 ZwCreateSection
SSDT 963D027E ZwCreateSymbolicLinkObject
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwDeleteKey [0x90601A68]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey [0x90601B5A]
SSDT 963D0283 ZwLoadDriver
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwOpenFile [0x90601F9C]
SSDT 963D0279 ZwOpenSection
SSDT 963D02B0 ZwRequestWaitReplyPort
SSDT 963D02AB ZwSetContextThread
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwSetInformationFile [0x906020D2]
SSDT 963D02B5 ZwSetSecurityObject
SSDT 963D0288 ZwSetSystemInformation
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwSetValueKey [0x9060177E]
SSDT 963D02BA ZwSystemDebugControl
SSDT 963D0247 ZwTerminateProcess
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwWriteFile [0x906022BC]
SSDT 963D0242 ZwWriteVirtualMemory
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 142D 8305BA15 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 83095212 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 116F 8309C504 4 Bytes [44, 24, 60, 90] {INC ESP; AND AL, 0x60; NOP }
.text ntkrnlpa.exe!KeRemoveQueueEx + 11AF 8309C544 4 Bytes [8A, 1C, 60, 90] {MOV BL, [EAX]; NOP }
.text ntkrnlpa.exe!KeRemoveQueueEx + 11BF 8309C554 4 Bytes [58, 19, 60, 90] {POP EAX; SBB [EAX-0x70], ESP}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11F7 8309C58C 4 Bytes [A6, 02, 3D, 96]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11FF 8309C594 4 Bytes [7E, 02, 3D, 96]
.text ...
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Real\RealPlayer\Update\realsched.exe[364] kernel32.dll!SetUnhandledExceptionFilter 7693F4EB 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
---- Devices - GMER 2.1 ----
AttachedDevice \Driver\tdx \Device\Tcp avfwot.sys
AttachedDevice \Driver\tdx \Device\Udp avfwot.sys
AttachedDevice \Driver\tdx \Device\RawIp avfwot.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Catalogs\SystemIndex@{535BB2D1-ABF1-11E1-9299-806E6F6E6963} 3966439200
---- EOF - GMER 2.1 ---- |