Hallo Schrauber,
vielen Dank für Deine schnell Antwort. Wollte auch schon Ergebnisse liefern, aber ComboFix brauchte sehr lange und hat sich im Endeffekt aufgehängt. Ich werde es morgen nochmal versuchen und melde mich dann wieder.
Gruß Andreas!
Hallo Schrauber,
sorry - das mit den Adminrechten hatte ich vergessen. Allerdings wurden bis auf FRST sowie so alle anderen Programme mit der Admin-Aufforderungen gestartet. Deshalb habe ich heute nur FRST nochmal neu laufen lassen.
Hier die Ergebnisse: Additional.txt: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version:12-06-2014
Ran by internet at 2014-06-13 09:48:29
Running from D:\AntiVirus
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
AS: COMODO Antivirus (Disabled - Out of date) {0C2D2636-923D-EE52-2A83-E643204A8275}
FW: COMODO Firewall (Enabled) {8F7746F7-FE68-E084-3B6C-7404A51E8FB3}
==================== Installed Programs ======================
7-Zip 9.20 (HKLM\...\7-Zip) (Version: - )
Adobe Flash Player 13 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.0.150 - Adobe Systems, Inc.)
AMD Catalyst Control Center (Version: 2013.0604.1838.31590 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{FFEB98D2-E65A-3C8F-DC9E-7A0F6EEDDE33}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
AMD Fuel (Version: 2013.0604.1838.31590 - Advanced Micro Devices, Inc.) Hidden
Android Studio (HKLM\...\Android Studio) (Version: 1.0 - Google Inc.)
Apple Application Support (HKLM\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Auslogics DiskDefrag (HKLM\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 4.5.4.0 - Auslogics Labs Pty Ltd)
avast! Free Antivirus (HKLM\...\Avast) (Version: 9.0.2018 - Avast Software)
Avidemux 2.4 (HKLM\...\Avidemux 2.4) (Version: 2.4.4 - )
BillardGL 1.75 (HKLM\...\BillardGL 1.75) (Version: - )
Borland Turbo Delphi (HKLM\...\{7ED5371F-F4EA-48F9-B8F7-C8777AD9DF69}) (Version: 10.0.3 - Borland Software Corporation)
calibre (HKLM\...\{A696C2ED-7597-46AB-9676-898F9849576D}) (Version: 1.39.0 - Kovid Goyal)
CamStudio Lossless Codec v1.5 (HKLM\...\camcodec) (Version: 1.5 - CamStudio)
CamStudio version 2.7 (HKLM\...\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7 - CamStudio Open Source)
Canon CanoScan Toolbox 4.1 (HKLM\...\{BCE46757-7674-4416-BEDB-68205A60409E}) (Version: - )
Catalyst Control Center - Branding (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (Version: 2013.0604.1838.31590 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (Version: 2013.0604.1838.31590 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (Version: 2013.0604.1837.31590 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (Version: 2013.0604.1837.31590 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (Version: 2013.0604.1837.31590 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (Version: 2013.0604.1837.31590 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (Version: 2013.0604.1837.31590 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (Version: 2013.0604.1837.31590 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (Version: 2013.0604.1837.31590 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (Version: 2013.0604.1837.31590 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (Version: 2013.0604.1837.31590 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (Version: 2013.0604.1837.31590 - Advanced Micro Devices, Inc.) Hidden
ccc-utility (Version: 2013.0604.1838.31590 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.13 - Piriform)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.1.4003 - CDBurnerXP)
COMODO Internet Security (HKLM\...\{E62381A7-B1C1-4121-8262-84D38C77786C}) (Version: 5.12.55693.2551 - COMODO Security Solutions Inc.)
Corel Paint Shop Pro X (HKLM\...\{1A15507A-8551-4626-915D-3D5FA095CC1B}) (Version: 10.03 - Corel Inc)
Creative MediaSource 5 (HKLM\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.00 - )
CrystalDiskInfo 6.1.12 (HKLM\...\CrystalDiskInfo_is1) (Version: 6.1.12 - Crystal Dew World)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Display Manager (HKLM\...\{AC50C05D-9D57-40F5-B2EF-AC402F14312B}_is1) (Version: - EnTech Taiwan)
DIY DataRecovery MBRtool (HKLM\...\MBRtool_is1) (Version: 2.3.200 - DIY DataRecovery.nl)
EASEUS Partition Master 4.1.1 Professional (HKLM\...\EASEUS Partition Master Professional Edition_is1) (Version: - EASEUS)
Eraser 6.0.10.2620 (HKLM\...\{A45C5EC7-F13E-4414-99BE-47373935C0FE}) (Version: 6.0.2620 - The Eraser Project)
FBReader for Windows (HKLM\...\FBReader for Windows) (Version: - )
FileZilla Client 3.7.4.1 (HKLM\...\FileZilla Client) (Version: 3.7.4.1 - Tim Kosse)
Fotogalerie (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Foxit Cloud (HKLM\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 1.2.75.126 - Foxit Corporation)
Foxit Reader (HKLM\...\Foxit Reader_is1) (Version: 6.1.4.217 - Foxit Corporation)
Free Download Manager 3.9.3 (HKLM\...\Free Download Manager_is1) (Version: - FreeDownloadManager.ORG)
FreeDoko 0.7.12 (HKLM\...\FreeDoko) (Version: 0.7.12 - Borg Enders und Diether Knof)
Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.24.7 - Google Inc.) Hidden
Helium (HKLM\...\{9A781940-AC41-4D5E-8E1E-76A04B916FB9}) (Version: 1.0.0 - ClockworkMod)
ImageJ 1.47v (HKLM\...\ImageJ_is1) (Version: - NIH)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.37 - Irfan Skiljan)
Java 7 Update 60 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.600 - Oracle)
Java Auto Updater (Version: 2.1.60.19 - Oracle, Inc.) Hidden
Java SE Development Kit 7 Update 51 (HKLM\...\{32A3A4F4-B792-11D6-A78A-00B0D0170510}) (Version: 1.7.0.510 - Oracle)
JDownloader 0.9 (HKLM\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
Kyodai Mahjongg 2006 v1.42 (HKLM\...\Kyodai Mahjongg 2006_is1) (Version: - Rene-Gilles Deberdt)
LibreOffice 4.0 Help Pack (German) (HKLM\...\{FE231FC3-A6F1-45D4-AE1B-C591610EBC32}) (Version: 4.0.5.2 - The Document Foundation)
LibreOffice 4.1.5.3 (HKLM\...\{E77773E5-944A-453F-97F3-46767AE0A253}) (Version: 4.1.5.3 - The Document Foundation)
Macromedia Dreamweaver MX 2004 (HKLM\...\{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}) (Version: 7.0 - Macromedia)
Macromedia Extension Manager (HKLM\...\{A5BA14E0-7384-11D4-BAE7-00409631A2C8}) (Version: 1.5 - Macromedia)
McAfee SiteAdvisor (HKLM\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 3.6.115 - McAfee, Inc.)
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - )
Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework SDK (English) 1.1 (HKLM\...\{EB9BD1D5-8DFB-48C4-927B-10BB47CA59B3}) (Version: 1.1.4322 - Microsoft)
Microsoft Application Compatibility Toolkit 5.6 (HKLM\...\{0F5AEBB0-43F3-4571-ACE7-A7942E8AA179}) (Version: 5.6.7324.0 - Microsoft Corporation)
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Baseline Security Analyzer 2.3 (HKLM\...\{C3013E88-B772-4446-A0AE-A7F37180B9F1}) (Version: 2.3.2208 - Microsoft Corporation)
Microsoft Expression Web 4 (HKLM\...\Web_4.0.1460.0) (Version: 4.0.1460.0 - Microsoft Corporation)
Microsoft Expression Web 4 (Version: 4.0.1460.0 - Microsoft Corporation) Hidden
Microsoft Office XP Professional mit FrontPage (HKLM\...\{90280407-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2701.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual J# .NET Redistributable Package 1.1 (HKLM\...\{1A655D51-1423-48A3-B748-8F5A0BE294C8}) (Version: 1.1.4322 - Microsoft)
Miro (HKLM\...\Miro) (Version: 6.0 - Participatory Culture Foundation)
Mobilizer (HKLM\...\com.springbox.mobilizer) (Version: 0.9.6 - UNKNOWN)
Mobilizer (Version: 0.9.6 - UNKNOWN) Hidden
Movie Maker (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 21.0 (x86 de) (HKLM\...\Mozilla Firefox 21.0 (x86 de)) (Version: 21.0 - Mozilla)
MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (Version: 16.4.1108.0727 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
MyPhoneExplorer (HKLM\...\MPE) (Version: 1.8.5 - F.J. Wechselberger)
Nitro Reader 3 (HKLM\...\{587BE1E5-418E-461F-B3F0-D7C07E38B481}) (Version: 3.5.5.2 - Nitro)
Photo Common (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Photo Gallery (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
PicPick (HKLM\...\PicPick) (Version: 3.3.2 - NTeWORKS)
QuickTime (HKLM\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
Realtek Ethernet Diagnostic Utility (HKLM\...\{DADC7AB0-E554-4705-9F6A-83EA82ED708E}) (Version: 1.006 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6767 - Realtek Semiconductor Corp.)
Roadkil's Disk Image Version 1.6 (HKLM\...\{2AE21A08-FF8E-44CF-84C7-F5571DBF7360}_is1) (Version: - Roadkil.Net)
Skype Click to Call (HKLM\...\{BB285C9F-C821-4770-8970-56C4AB52C87E}) (Version: 7.2.15747.10003 - Microsoft Corporation)
Skype™ 6.14 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
Sokoban YASC (HKLM\...\Sokoban YASC - Yet Another Sokoban Clone_is1) (Version: - )
Speccy (HKLM\...\Speccy) (Version: 1.25 - Piriform)
StreamTransport version: 1.1.4.0 (HKLM\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version: - )
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
UBCD4Win 3.60 (HKLM\...\UBCD4Win_is1) (Version: - UBCD4Win Team - Benjamin Burrows)
vavideo.app Version 1.0 (HKLM\...\vavideo.app_is1) (Version: 1.0 - vavideo)
VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN)
VSDC Free Video Editor Version 2.1.6.133 (HKLM\...\VSDC Free Video Editor_is1) (Version: 2.1.6.133 - Flash-Integro LLC)
WBInvoker (HKLM\...\{5319996b-e624-478f-881b-882508bd323f}.sdb) (Version: - )
Windows Live Communications Platform (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Live Essentials (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Photo Common (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
WinHTTrack Website Copier 3.47-21 (HKLM\...\WinHTTrack Website Copier_is1) (Version: 3.47.21 - HTTrack)
WinPcap 4.1.3 (HKLM\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
XQDC X-Setup Pro 9.2.100 (HKLM\...\xqdcXSP_is1) (Version: 9.2.100 - XQDC Ltd.)
==================== Restore Points =========================
11-06-2014 10:47:43 Windows Update
==================== Hosts content: ==========================
2009-07-14 10:04 - 2013-06-16 15:43 - 00000959 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 localhost
127.0.0.1 localhost
127.0.0.1 localhost
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {1291E9C6-050C-4A5C-AAC4-1187167AC714} - System32\Tasks\avast! Emergency Update => E:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-04-25] (AVAST Software)
Task: {15934C0F-D139-4309-BB90-8B9DC0AAFD47} - System32\Tasks\{4C59AC1C-202A-41AF-9123-6C665BB86827} => D:\moviemk.exe [2008-04-14] (Microsoft Corporation)
Task: {30472C5C-A170-4B37-B050-FD4C410044BB} - System32\Tasks\{3DC555EF-59C2-49B8-9AD8-19BA6896984B} => C:\Windows\system32\msiexec.exe [2010-11-20] (Microsoft Corporation)
Task: {40910F57-9D83-4E4C-AE87-37E69ECEA2AA} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => E:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-04-17] (COMODO)
Task: {9DADE6A6-88BE-4788-B6B3-E4B003CA2B44} - System32\Tasks\{05E7625E-6833-4F4D-9702-2CE80609AC7C} => E:\Games\Billard\Camron3D\carom.exe
Task: {A5E8E34F-F0D1-40DF-B5E1-F4C6EFD0DBC6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-16] (Adobe Systems Incorporated)
Task: {B8595D9F-4B67-4D11-AA20-D21E6BBA97E0} - System32\Tasks\{A2E15662-C697-4156-B16A-8DFE7B03CD9C} => E:\Games\Billard\Camron3D\carom.exe
Task: {BAE11546-192A-4978-A36B-DC6058CE6408} - System32\Tasks\{E830B81E-0E19-4E62-B82A-A17FC9115B4E} => D:\moviemk.exe [2008-04-14] (Microsoft Corporation)
Task: {C086CD84-47FD-46E8-A468-BF5A9747A7CD} - System32\Tasks\{0C075C35-C0B6-4DB9-83D0-B7B8811D81C1} => E:\Games\Billard\Camron3D\carom.exe
Task: {C280373C-E284-4901-860C-469C695D979A} - System32\Tasks\GoogleUpdateTaskMachineUA => E:\Program Files\Google\Update\GoogleUpdate.exe [2011-04-11] (Google Inc.)
Task: {E662863F-F505-40F1-9088-2E344C400424} - System32\Tasks\CCleanerSkipUAC => E:\Program Files\CCleaner\CCleaner.exe [2014-04-18] (Piriform Ltd)
Task: {F65F46A1-B232-4315-B8F5-DC1F87922B8D} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => E:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-04-17] (COMODO)
Task: {F88D516A-F19F-4B46-A1E0-CAA9D0B8A3F4} - System32\Tasks\{8F355BAC-CBAB-41EE-ACEA-AAD36AA25841} => E:\Games\Billard\Camron3D\carom.exe
Task: {FDAAAC38-E336-414F-80E5-5E64E5095D40} - System32\Tasks\{775E29D0-B1C3-466D-AF4E-F234E71B1F21} => E:\Media\Video\Pinnacle VideoSpin\Programs\VideoSpin.exe
Task: {FE968CB4-AC69-4836-9634-2E0738F045D2} - System32\Tasks\GoogleUpdateTaskMachineCore => E:\Program Files\Google\Update\GoogleUpdate.exe [2011-04-11] (Google Inc.)
Task: {FE9E75C7-7343-4A11-86DE-D03FB359CCB9} - System32\Tasks\{2E281DFD-1809-4500-B68C-F0D04A417FD0} => E:\Media\Video\Pinnacle VideoSpin\Programs\VideoSpin.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => E:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => E:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-06-12 18:57 - 2014-06-12 18:57 - 02775040 _____ () E:\Program Files\AVAST Software\Avast\defs\14061200\algo.dll
2014-02-12 03:29 - 2014-02-12 03:29 - 00093696 _____ () E:\Internet\FTP\FileZilla 3.7.1\fzshellext.dll
2013-10-20 11:43 - 2013-10-20 11:43 - 19336120 _____ () E:\Program Files\AVAST Software\Avast\libcef.dll
2014-06-13 09:33 - 2014-06-13 09:33 - 00043008 _____ () C:\Users\internet_2\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplamcty.dll
2013-08-24 03:01 - 2013-08-24 03:01 - 25100288 _____ () C:\Users\internet_2\AppData\Roaming\Dropbox\bin\libcef.dll
2014-05-10 08:13 - 2014-05-10 08:13 - 03839088 _____ () E:\Internet\FireFox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== MSCONFIG/TASK MANAGER disabled items =========
MSCONFIG\Services: bthserv => 3
MSCONFIG\Services: Fax => 3
MSCONFIG\Services: Macromedia Licensing Service => 3
MSCONFIG\Services: McAfee SiteAdvisor Service => 2
MSCONFIG\Services: Wlansvc => 3
==================== Faulty Device Manager Devices =============
Name: SASDIFSV
Description: SASDIFSV
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: SASDIFSV
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: SASKUTIL
Description: SASKUTIL
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: SASKUTIL
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (06/13/2014 09:35:30 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program ComboFix.exe version 14.6.12.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 1370
Start Time: 01cf86a76bb894ea
Termination Time: 0
Application Path: D:\AntiVirus\ComboFix.exe
Report Id:
Error: (06/13/2014 09:29:52 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program ComboFix.exe version 14.6.12.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 1184
Start Time: 01cf86a0b158bc55
Termination Time: 10
Application Path: D:\AntiVirus\ComboFix.exe
Report Id:
Error: (06/13/2014 08:00:14 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program ComboFix.exe version 14.6.12.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 2ec
Start Time: 01cf86945174e134
Termination Time: 16
Application Path: D:\AntiVirus\ComboFix.exe
Report Id:
Error: (06/13/2014 07:49:18 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (06/12/2014 06:02:14 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (06/12/2014 02:53:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: updatewebget.exe, version: 0.0.0.0, time stamp: 0x5398819f
Faulting module name: KERNEL32.dll_unloaded, version: 0.0.0.0, time stamp: 0x531599f5
Exception code: 0xc0000005
Fault offset: 0x7778ed93
Faulting process id: 0x148c
Faulting application start time: 0xupdatewebget.exe0
Faulting application path: updatewebget.exe1
Faulting module path: updatewebget.exe2
Report Id: updatewebget.exe3
Error: (06/11/2014 06:47:43 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddCoreCsiFiles : RtlConvertNtFilePathToWin32Path() failed.
System Error:
0xC0000039 (unresolvable).
Error: (06/11/2014 06:47:42 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddCoreCsiFiles : RtlConvertNtFilePathToWin32Path() failed.
System Error:
0xC0000039 (unresolvable).
Error: (06/10/2014 06:37:17 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (06/10/2014 04:51:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program JBrowser.exe version 1.0.0.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 10bc
Start Time: 01cf8488eba61e71
Termination Time: 8
Application Path: O:\JBrowser.exe
Report Id: 4e8fe422-f07c-11e3-9dd7-6cf049ddb301
System errors:
=============
Error: (06/13/2014 07:09:59 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
SASDIFSV
SASKUTIL
Error: (06/13/2014 07:08:36 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Update webget service failed to start due to the following error:
%%2
Error: (06/12/2014 08:25:51 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk2\DR2.
Error: (06/12/2014 08:25:51 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk2\DR2.
Error: (06/12/2014 07:48:51 PM) (Source: cdrom) (EventID: 15) (User: )
Description: The device, \Device\CdRom1, is not ready for access yet.
Error: (06/12/2014 07:48:51 PM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort1.
Error: (06/12/2014 07:48:50 PM) (Source: cdrom) (EventID: 15) (User: )
Description: The device, \Device\CdRom1, is not ready for access yet.
Error: (06/12/2014 07:48:49 PM) (Source: cdrom) (EventID: 15) (User: )
Description: The device, \Device\CdRom1, is not ready for access yet.
Error: (06/12/2014 07:48:48 PM) (Source: cdrom) (EventID: 15) (User: )
Description: The device, \Device\CdRom1, is not ready for access yet.
Error: (06/12/2014 07:48:47 PM) (Source: cdrom) (EventID: 15) (User: )
Description: The device, \Device\CdRom1, is not ready for access yet.
Microsoft Office Sessions:
=========================
Error: (06/13/2014 09:35:30 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: ComboFix.exe14.6.12.1137001cf86a76bb894ea0D:\AntiVirus\ComboFix.exe
Error: (06/13/2014 09:29:52 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: ComboFix.exe14.6.12.1118401cf86a0b158bc5510D:\AntiVirus\ComboFix.exe
Error: (06/13/2014 08:00:14 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: ComboFix.exe14.6.12.12ec01cf86945174e13416D:\AntiVirus\ComboFix.exe
Error: (06/13/2014 07:49:18 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"f:\programming\Android\android studio\bin\studio64.exe.Manifest
Error: (06/12/2014 06:02:14 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"f:\programming\Android\android studio\bin\studio64.exe.Manifest
Error: (06/12/2014 02:53:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: updatewebget.exe0.0.0.05398819fKERNEL32.dll_unloaded0.0.0.0531599f5c00000057778ed93148c01cf860af8c1ae69E:\Program Files\webget\updatewebget.exeKERNEL32.dll37c5ec38-f1fe-11e3-a48a-6cf049ddb301
Error: (06/11/2014 06:47:43 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddCoreCsiFiles : RtlConvertNtFilePathToWin32Path() failed.
System Error:
0xC0000039 (unresolvable)
Error: (06/11/2014 06:47:42 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddCoreCsiFiles : RtlConvertNtFilePathToWin32Path() failed.
System Error:
0xC0000039 (unresolvable)
Error: (06/10/2014 06:37:17 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"f:\programming\Android\android studio\bin\studio64.exe.Manifest
Error: (06/10/2014 04:51:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: JBrowser.exe1.0.0.110bc01cf8488eba61e718O:\JBrowser.exe4e8fe422-f07c-11e3-9dd7-6cf049ddb301
==================== Memory info ===========================
Percentage of memory in use: 66%
Total physical RAM: 3325.55 MB
Available physical RAM: 1110.74 MB
Total Pagefile: 4323.84 MB
Available Pagefile: 2515.64 MB
Total Virtual: 2047.88 MB
Available Virtual: 1895.13 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:23.49 GB) (Free:4.36 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (System) (Fixed) (Total:10.72 GB) (Free:4.13 GB) NTFS
Drive e: (Programme) (Fixed) (Total:22.36 GB) (Free:3.94 GB) NTFS
Drive f: (Daten) (Fixed) (Total:23.39 GB) (Free:2.25 GB) NTFS
Drive g: (MP3) (Fixed) (Total:102.53 GB) (Free:54.7 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive h: (Bilder) (Fixed) (Total:107.42 GB) (Free:54.22 GB) NTFS
Drive i: (Eigene) (Fixed) (Total:30.25 GB) (Free:13.02 GB) NTFS
Drive k: (SundayBackups) (Fixed) (Total:28.96 GB) (Free:10.44 GB) NTFS
Drive l: (Backups) (Fixed) (Total:9.82 GB) (Free:5.54 GB) NTFS
Drive m: (Videos) (Fixed) (Total:88.13 GB) (Free:29.25 GB) NTFS
Drive p: () (Fixed) (Total:74.51 GB) (Free:14.48 GB) FAT32
Drive z: (FREE) (Fixed) (Total:0.05 GB) (Free:0.04 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 298 GB) (Disk ID: 69ECF574)
Partition 1: (Active) - (Size=103 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=107 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=88 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: EE4EEE4E)
Partition 1: (Active) - (Size=23 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=47 MB) - (Type=0C)
Partition 3: (Not Active) - (Size=126 GB) - (Type=OF Extended)
========================================================
Disk: 2 (Size: 75 GB) (Disk ID: E5B69024)
Partition 1: (Not Active) - (Size=75 GB) - (Type=0C)
==================== End Of Log ============================ FRST Scan Result:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:12-06-2014
Ran by internet (administrator) on DESKTOP-PC on 13-06-2014 09:47:09
Running from D:\AntiVirus
Platform: Microsoft Windows 7 Home Basic Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(COMODO) E:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe
(AVAST Software) E:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) E:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) E:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) E:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Foxit Corporation) E:\Program Files\Foxit Reader\Foxit Cloud\FCUpdateService.exe
(Nitro PDF Software) E:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(COMODO) E:\Program Files\Comodo\COMODO Internet Security\cavwp.exe
(The Eraser Project) E:\Program Files\Eraser\Eraser.exe
(AVAST Software) E:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Realtek Semiconductor) E:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(NTeWORKS) E:\Image Processing\PicPick\picpick.exe
(Skype Technologies S.A.) E:\Program Files\Skype\Phone\Skype.exe
(Microsoft Corporation) E:\Program Files\Windows Sidebar\sidebar.exe
(Dropbox, Inc.) C:\Users\internet_2\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Oracle Corporation) E:\Program Files\Java\jre7\bin\javaw.exe
(Microsoft Corporation) E:\MS\Office10\MSOFFICE.EXE
(Microsoft Corporation) E:\Program Files\windows media player\wmpnetwk.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Mozilla Corporation) E:\Internet\FireFox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [COMODO Internet Security] => E:\Program Files\Comodo\COMODO Internet Security\cistray.exe [1225944 2014-03-26] (COMODO)
HKLM\...\Run: [NetFxUpdate_v1.1.4322] => C:\Windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe [106496 2004-08-10] (Microsoft)
HKLM\...\Run: [Eraser] => E:\Program Files\Eraser\Eraser.exe [980920 2012-05-22] (The Eraser Project)
HKLM\...\Run: [StartCCC] => E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [676608 2013-06-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] => E:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [AvastUI.exe] => E:\Program Files\AVAST Software\Avast\AvastUI.exe [3890208 2014-06-06] (AVAST Software)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKLM\...\Run: [RtHDVCpl] => E:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [11680400 2012-10-26] (Realtek Semiconductor)
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [280576 2013-06-18] (Microsoft Corporation)
HKU\S-1-5-21-2546741769-1852086618-152487652-1000\...\Run: [Skype] => E:\Program Files\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-2546741769-1852086618-152487652-1000\...\Run: [PicPick Start] => E:\Image Processing\PicPick\picpick.exe [13165400 2014-03-12] (NTeWORKS)
HKU\S-1-5-21-2546741769-1852086618-152487652-1000\...\MountPoints2: {e9c92f2f-d4c2-11e2-85eb-806e6f6e6963} - N:\CDBROWSE.EXE
HKU\S-1-5-21-2546741769-1852086618-152487652-1000\...\MountPoints2: {e9c92f30-d4c2-11e2-85eb-806e6f6e6963} - O:\Run.exe
HKU\S-1-5-21-2546741769-1852086618-152487652-1002\...\Run: [PicPick Start] => E:\Image Processing\PicPick\picpick.exe [13165400 2014-03-12] (NTeWORKS)
HKU\S-1-5-21-2546741769-1852086618-152487652-1002\...\Run: [Skype] => E:\Program Files\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-2546741769-1852086618-152487652-1002\...\Run: [Messenger (Yahoo!)] => "E:\PROGRA~3\Yahoo!\Messenger\YahooMessenger.exe" -quiet
HKU\S-1-5-21-2546741769-1852086618-152487652-1002\...\MountPoints2: {e9c92f2f-d4c2-11e2-85eb-806e6f6e6963} - notepad readme.txt
HKU\S-1-5-21-2546741769-1852086618-152487652-1002\...\MountPoints2: {e9c92f30-d4c2-11e2-85eb-806e6f6e6963} - O:\Run.exe
Startup: C:\Users\internet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI (RC3).lnk
ShortcutTarget: Secunia PSI (RC3).lnk -> D:\Programme\Personal Software Inspector\psi.exe (Secunia)
Startup: C:\Users\internet_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\internet\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
Startup: C:\Users\internet_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JDownloaderPortable.lnk
ShortcutTarget: JDownloaderPortable.lnk -> E:\Media\Video\JDownloader\JDownloaderPortable.exe (AppWork GmbH)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fil-PH
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://ph.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x13A26660C36CCE01
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - E:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - E:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - E:\Program Files\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - E:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - E:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - E:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - E:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{65379DEE-2D36-4695-8857-4DC4D45113C2}: [NameServer]192.168.0.1
FireFox:
========
FF ProfilePath: I:\Eigene Dateien\Internet\FireFox\Profile\@dele
FF Homepage: hxxp://www.gmx.net
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - E:\Program Files\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - E:\Program Files\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @Google.com/GoogleEarthPlugin - E:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.60.2 - E:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.60.2 - E:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 - E:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @nitropdf.com/NitroPDF - E:\Program Files\Nitro\Reader 3\npnitromozilla.dll (Nitro PDF)
FF Plugin: @tools.google.com/Google Update;version=3 - E:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - E:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 - E:\Media\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 - E:\Media\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 - E:\Media\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 - E:\Media\VLC\npvlc.dll (VideoLAN)
FF user.js: detected! => C:\Users\internet\AppData\Roaming\Mozilla\Firefox\Profiles\y4m0hhnp.default\user.js
FF Extension: McAfee SiteAdvisor - E:\Program Files\McAfee\SiteAdvisor [2011-12-25]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - E:\Program Files\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - E:\Program Files\McAfee\SiteAdvisor [2011-12-25]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - E:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - E:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-20]
FF StartMenuInternet: FIREFOX.EXE - E:\Internet\FireFox\firefox.exe
========================== Services (Whitelisted) =================
R2 AMD FUEL Service; E:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [291840 2013-06-04] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; E:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-25] (AVAST Software)
R2 c2cautoupdatesvc; E:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; E:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
R2 cmdAgent; E:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5306504 2014-04-17] (COMODO)
S3 cmdvirth; E:\Program Files\Comodo\COMODO Internet Security\cmdvirth.exe [1663192 2014-03-26] (COMODO)
R2 FoxitCloudUpdateService; E:\Program Files\Foxit Reader\Foxit Cloud\FCUpdateService.exe [239680 2014-02-19] (Foxit Corporation)
S2 gupdate; E:\Program Files\Google\Update\GoogleUpdate.exe [136176 2011-04-11] (Google Inc.)
S3 gupdatem; E:\Program Files\Google\Update\GoogleUpdate.exe [136176 2011-04-11] (Google Inc.)
S3 Macromedia Licensing Service; C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [68096 2013-06-20] () [File not signed]
S4 McAfee SiteAdvisor Service; E:\Program Files\McAfee\SiteAdvisor\McSACore.exe [104880 2014-01-07] (McAfee, Inc.)
S3 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [335872 2003-03-19] (Microsoft Corporation) [File not signed]
R2 NitroReaderDriverReadSpool3; E:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe [196624 2013-03-26] (Nitro PDF Software)
S2 SkypeUpdate; E:\Program Files\Skype\Updater\Updater.exe [172192 2013-10-23] (Skype Technologies)
S3 wampapache; P:\wamp\bin\apache\apache2.2.22\bin\httpd.exe [18432 2012-05-13] (Apache Software Foundation) [File not signed]
S3 wampmysqld; P:\wamp\bin\mysql\mysql5.5.24\bin\mysqld.exe [8177664 2012-04-19] () [File not signed]
S3 WinDefend; E:\Program Files\Windows Defender\mpsvc.dll [680960 2013-07-12] (Microsoft Corporation)
R3 WMPNetworkSvc; E:\Program Files\Windows Media Player\wmpnetwk.exe [1121792 2013-08-18] (Microsoft Corporation)
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X]
S2 Update webget; "E:\Program Files\webget\updatewebget.exe" [X]
==================== Drivers (Whitelisted) ====================
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-04-25] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-04-25] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81768 2014-04-25] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-04-25] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [777488 2014-05-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [411680 2014-05-15] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [68312 2014-05-15] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180632 2014-04-25] ()
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20072 2014-04-17] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [607168 2014-04-17] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [43728 2014-04-17] (COMODO)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [14216 2009-08-26] () [File not signed]
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [8456 2009-09-16] () [File not signed]
S3 gdrv; C:\Windows\gdrv.sys [17488 2014-06-10] (Windows (R) 2000 DDK provider)
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [92656 2014-04-17] (COMODO)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R2 RtNdPt60; C:\Windows\System32\DRIVERS\RtNdPt60.sys [22120 2011-06-15] (Realtek )
S3 RTTEAMPT; C:\Windows\System32\DRIVERS\RtTeam60.sys [49768 2011-06-15] (Realtek Corporation)
S3 RTVLANPT; C:\Windows\System32\DRIVERS\RtVlan60.sys [27752 2011-09-16] (Realtek Corporation)
S3 SIVDriver; C:\Windows\system32\Drivers\SIVX32.sys [90648 2011-06-14] (Ray Hinchliffe)
S3 TEAM; C:\Windows\System32\DRIVERS\RtTeam60.sys [49768 2011-06-15] (Realtek Corporation)
R1 {55685567-4840-4a91-962b-49a412e9485a}w; C:\Windows\System32\drivers\{55685567-4840-4a91-962b-49a412e9485a}w.sys [52920 2014-05-26] (StdLib)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S1 SASDIFSV; \??\I:\Temp\SAS_SelfExtract\SASDIFSV.SYS [X]
S1 SASKUTIL; \??\I:\Temp\SAS_SelfExtract\SASKUTIL.SYS [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-13 09:47 - 2014-06-13 09:47 - 00000000 ____D () C:\FRST
2014-06-12 17:24 - 2014-06-13 09:33 - 00000000 ___SD () C:\32788R22FWJFW
2014-06-12 09:20 - 2014-06-12 09:20 - 00000000 ____D () C:\Users\internet\AppData\Roaming\SUPERAntiSpyware.com
2014-06-11 18:47 - 2014-05-30 17:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-11 18:47 - 2014-05-30 17:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-11 18:47 - 2014-05-30 17:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-11 18:47 - 2014-05-30 16:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-11 18:47 - 2014-05-30 16:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-11 18:47 - 2014-05-30 16:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-11 18:47 - 2014-05-30 16:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-11 18:47 - 2014-05-30 16:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-11 18:47 - 2014-05-30 16:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-11 18:47 - 2014-05-30 16:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-11 18:47 - 2014-05-30 16:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-11 18:47 - 2014-05-30 16:28 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-11 18:47 - 2014-05-30 16:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-11 18:47 - 2014-05-30 16:21 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-11 18:47 - 2014-05-30 16:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-11 18:47 - 2014-05-30 16:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-11 18:47 - 2014-05-30 16:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-11 18:47 - 2014-05-30 16:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-11 18:47 - 2014-05-30 16:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-11 18:47 - 2014-05-30 15:57 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-11 18:47 - 2014-05-30 15:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-11 18:47 - 2014-05-30 15:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-11 18:47 - 2014-05-30 15:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-11 18:47 - 2014-05-30 15:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-11 18:47 - 2014-05-30 15:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-11 18:47 - 2014-05-30 15:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-11 18:47 - 2014-05-30 15:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-11 18:47 - 2014-05-30 15:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-11 16:54 - 2014-06-08 16:48 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-11 16:54 - 2014-04-05 10:25 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-11 16:54 - 2014-04-05 10:24 - 00187840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-11 16:53 - 2014-06-08 16:43 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-11 16:53 - 2014-04-25 10:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-11 16:53 - 2014-03-26 22:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-11 16:53 - 2014-03-26 22:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-11 16:53 - 2014-03-26 22:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-11 16:53 - 2014-03-26 22:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-10 17:23 - 2014-06-10 17:23 - 00000000 ____D () C:\Windows\system32\RTCOM
2014-06-10 17:22 - 2012-10-30 17:59 - 03340880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHDA.sys
2014-06-10 17:22 - 2012-10-30 16:43 - 00369117 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT
2014-06-10 17:22 - 2012-10-29 16:34 - 02357344 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO.dll
2014-06-10 17:22 - 2012-10-25 14:45 - 00097424 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoInstII.dll
2014-06-10 17:22 - 2012-10-23 11:30 - 03219600 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO.dll
2014-06-10 17:22 - 2012-09-20 00:59 - 00742264 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell.dll
2014-06-10 17:22 - 2012-09-12 09:51 - 02486416 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkPgExt.dll
2014-06-10 17:22 - 2012-09-09 14:33 - 01929080 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll
2014-06-10 17:22 - 2012-08-21 14:51 - 00658064 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApoApi.dll
2014-06-10 17:22 - 2012-08-13 18:06 - 01501840 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSndMgr.cpl
2014-06-10 17:22 - 2012-08-03 18:18 - 01706640 _____ (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll
2014-06-10 17:22 - 2012-06-20 17:26 - 00090624 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2014-06-10 17:22 - 2012-06-08 16:23 - 00071808 _____ (Creative Technology Ltd.) C:\Windows\system32\MBWrp32.dll
2014-06-10 17:22 - 2012-06-08 16:21 - 00753280 _____ (Creative Technology Ltd.) C:\Windows\system32\MBAPO32.dll
2014-06-10 17:22 - 2012-03-08 11:47 - 00176736 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTACap.dll
2014-06-10 17:22 - 2012-03-08 11:47 - 00095840 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTARen.dll
2014-06-10 17:22 - 2011-12-16 14:57 - 00054360 _____ (Creative Technology Ltd.) C:\Windows\system32\MBppld32.dll
2014-06-10 17:22 - 2011-11-22 16:28 - 00013416 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR.dll
2014-06-10 17:22 - 2010-11-08 07:31 - 00359768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP32A.dll
2014-06-10 17:22 - 2010-11-08 07:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT32.dll
2014-06-10 17:22 - 2010-11-08 07:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA32.dll
2014-06-10 17:22 - 2010-11-08 07:31 - 00170840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED32A.dll
2014-06-10 17:22 - 2010-11-08 07:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL32A.dll
2014-06-10 17:22 - 2010-11-08 07:31 - 00064856 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG32A.dll
2014-06-10 17:22 - 2010-09-27 09:34 - 00232792 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2014-06-10 17:22 - 2009-12-04 15:43 - 00132368 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO.dll
2014-06-10 17:22 - 2009-11-24 09:55 - 00345328 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSXT.dll
2014-06-10 17:22 - 2009-11-24 09:55 - 00185584 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSHD.dll
2014-06-10 17:22 - 2009-11-24 09:55 - 00173296 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP360.dll
2014-06-10 17:22 - 2009-11-24 09:55 - 00140528 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW.dll
2014-06-10 17:22 - 2009-11-18 18:42 - 01783056 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesLib.dll
2014-06-10 17:22 - 2009-11-18 07:13 - 00050776 _____ (Creative Technology Ltd.) C:\Windows\system32\MBPPCn32.dll
2014-06-10 16:49 - 2014-06-10 16:49 - 00017488 _____ (Windows (R) 2000 DDK provider) C:\Windows\gdrv.sys
2014-06-09 11:05 - 2014-06-09 13:27 - 00000000 ____D () E:\Program Files\Calibre Portable
2014-06-05 16:03 - 2014-06-05 19:05 - 00000368 _____ () C:\Users\internet_2\Desktop\cover.txt
2014-06-03 22:11 - 2014-06-03 22:11 - 00147667 ____N () C:\Windows\Minidump\060314-22495-01.dmp
2014-05-31 10:32 - 2014-05-31 10:32 - 00000849 _____ () C:\Users\Public\Desktop\StreamTransport.lnk
2014-05-30 09:00 - 2014-05-30 09:00 - 00000084 _____ () C:\Users\internet\Downloads\nano vom 28. Mai 2014.info
2014-05-30 08:40 - 2014-05-30 09:00 - 102334358 _____ () C:\Users\internet\Downloads\nano vom 28. Mai 2014@HIGH.mp4
2014-05-30 08:19 - 2014-05-30 08:19 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-05-30 08:18 - 2014-05-07 15:02 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-05-30 08:18 - 2014-05-07 14:59 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-05-30 08:18 - 2014-05-07 14:59 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-05-30 08:18 - 2014-05-07 14:58 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-05-30 08:17 - 2014-05-30 08:18 - 00003993 _____ () C:\Windows\system32\jupdate-1.7.0_60-b19.log
2014-05-30 07:52 - 2014-05-26 20:57 - 00052920 _____ (StdLib) C:\Windows\system32\Drivers\{55685567-4840-4a91-962b-49a412e9485a}w.sys
2014-05-28 08:33 - 2014-06-12 14:54 - 00000000 ____D () E:\Program Files\webget
2014-05-25 14:32 - 2014-05-30 16:53 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\FreeDoko
2014-05-25 14:07 - 2014-05-25 14:07 - 00000756 _____ () C:\Users\internet\Desktop\FreeDoko.lnk
2014-05-25 14:07 - 2014-05-25 14:07 - 00000000 ____D () C:\Users\internet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeDoko
2014-05-25 14:05 - 2014-05-25 14:05 - 00000000 ____D () C:\Users\internet\FreeDoko
2014-05-24 13:48 - 2014-05-24 14:03 - 00001002 _____ () C:\Users\internet_2\Desktop\DBV_Klaerung.txt
2014-05-21 15:36 - 2014-05-29 15:36 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\Mp3tag
2014-05-17 15:06 - 2014-04-12 10:15 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-17 15:06 - 2014-04-12 10:15 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-17 15:06 - 2014-04-12 10:12 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-17 15:06 - 2014-04-12 10:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-17 15:06 - 2014-04-12 10:12 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-17 15:06 - 2014-04-12 10:11 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-17 15:06 - 2014-04-12 10:11 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-17 15:06 - 2014-03-04 17:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2014-05-17 15:06 - 2014-03-04 17:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-17 15:06 - 2014-03-04 17:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-17 15:06 - 2014-03-04 17:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-17 15:06 - 2014-03-04 17:17 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-17 15:06 - 2014-03-04 17:17 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-17 15:06 - 2014-03-04 17:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-17 15:06 - 2014-03-04 17:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-17 15:06 - 2014-03-04 17:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-17 15:06 - 2014-03-04 17:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-17 15:06 - 2014-03-04 17:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-17 15:06 - 2014-03-04 17:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-17 15:06 - 2014-03-04 17:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-17 15:06 - 2014-03-04 17:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-17 15:06 - 2014-03-04 17:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-17 15:06 - 2014-03-04 17:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-17 15:06 - 2014-03-04 17:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-17 14:58 - 2014-03-25 10:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
==================== One Month Modified Files and Folders =======
2014-06-13 09:47 - 2014-06-13 09:47 - 00000000 ____D () C:\FRST
2014-06-13 09:33 - 2014-06-12 17:24 - 00000000 ___SD () C:\32788R22FWJFW
2014-06-13 09:33 - 2014-03-03 09:13 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\DropboxMaster
2014-06-13 09:33 - 2013-09-22 13:46 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\Dropbox
2014-06-13 09:33 - 2013-06-22 19:49 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\Skype
2014-06-13 09:32 - 2014-01-01 10:16 - 00001060 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-13 09:00 - 2014-01-01 10:16 - 00001064 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-13 08:49 - 2013-07-14 07:30 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-13 08:21 - 2013-09-10 17:39 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\vlc
2014-06-13 08:04 - 2013-06-14 15:33 - 00795754 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-13 07:18 - 2009-07-14 12:34 - 00014912 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-13 07:18 - 2009-07-14 12:34 - 00014912 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-13 07:16 - 2013-06-14 15:23 - 01972928 _____ () C:\Windows\WindowsUpdate.log
2014-06-13 07:07 - 2014-03-22 07:07 - 00021972 _____ () C:\Windows\setupact.log
2014-06-13 07:07 - 2009-07-14 12:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-12 21:18 - 2013-10-20 13:10 - 00000000 ____D () C:\Users\internet\AppData\Roaming\vlc
2014-06-12 18:00 - 2013-11-13 08:06 - 00000000 ____D () C:\Windows\rescache
2014-06-12 16:46 - 2013-06-21 08:43 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\Nitro PDF
2014-06-12 14:54 - 2014-05-28 08:33 - 00000000 ____D () E:\Program Files\webget
2014-06-12 14:54 - 2013-06-15 07:45 - 00401084 _____ () C:\Windows\PFRO.log
2014-06-12 14:30 - 2009-07-14 10:04 - 00000505 _____ () C:\Windows\win.ini
2014-06-12 09:20 - 2014-06-12 09:20 - 00000000 ____D () C:\Users\internet\AppData\Roaming\SUPERAntiSpyware.com
2014-06-11 20:35 - 2014-04-25 11:58 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-11 20:35 - 2011-02-08 14:44 - 00000000 ____D () E:\Program Files\internet explorer
2014-06-11 18:51 - 2013-07-27 08:55 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-11 18:48 - 2013-06-17 13:26 - 92708840 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-11 16:52 - 2014-02-04 16:57 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\Free Download Manager
2014-06-10 17:24 - 2013-09-13 10:24 - 00000000 ___HD () E:\Program Files\Temp
2014-06-10 17:23 - 2014-06-10 17:23 - 00000000 ____D () C:\Windows\system32\RTCOM
2014-06-10 17:22 - 2011-02-08 16:04 - 00000000 ____D () E:\Program Files\Realtek
2014-06-10 16:49 - 2014-06-10 16:49 - 00017488 _____ (Windows (R) 2000 DDK provider) C:\Windows\gdrv.sys
2014-06-10 16:49 - 2013-06-14 15:35 - 00000010 _____ () C:\Windows\GSetup.ini
2014-06-10 16:05 - 2013-09-04 12:00 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\Orbit
2014-06-10 16:04 - 2013-10-14 10:09 - 00000000 ____D () E:\Program Files\Calibre2
2014-06-09 13:27 - 2014-06-09 11:05 - 00000000 ____D () E:\Program Files\Calibre Portable
2014-06-09 10:10 - 2013-10-14 10:15 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\calibre
2014-06-08 16:48 - 2014-06-11 16:54 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 16:43 - 2014-06-11 16:53 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-05 19:05 - 2014-06-05 16:03 - 00000368 _____ () C:\Users\internet_2\Desktop\cover.txt
2014-06-03 22:11 - 2014-06-03 22:11 - 00147667 ____N () C:\Windows\Minidump\060314-22495-01.dmp
2014-06-03 22:11 - 2013-09-30 16:09 - 00000000 ____D () C:\Windows\Minidump
2014-06-02 12:10 - 2013-06-25 13:16 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\FileZilla
2014-05-31 11:41 - 2013-07-17 12:01 - 00000000 ____D () C:\Users\internet_2\.mediathek3
2014-05-31 10:32 - 2014-05-31 10:32 - 00000849 _____ () C:\Users\Public\Desktop\StreamTransport.lnk
2014-05-30 17:18 - 2014-06-11 18:47 - 17271296 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-30 17:02 - 2014-06-11 18:47 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-30 17:02 - 2014-06-11 18:47 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-30 16:53 - 2014-05-25 14:32 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\FreeDoko
2014-05-30 16:44 - 2014-06-11 18:47 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-30 16:43 - 2014-06-11 18:47 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-30 16:42 - 2014-06-11 18:47 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-30 16:38 - 2014-06-11 18:47 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-30 16:34 - 2014-06-11 18:47 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-30 16:33 - 2014-06-11 18:47 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-30 16:30 - 2014-06-11 18:47 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-30 16:28 - 2014-06-11 18:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-30 16:28 - 2014-06-11 18:47 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-30 16:27 - 2014-06-11 18:47 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-30 16:21 - 2014-06-11 18:47 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-30 16:16 - 2014-06-11 18:47 - 00368128 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-30 16:10 - 2014-06-11 18:47 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 16:06 - 2014-06-11 18:47 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-30 16:04 - 2014-06-11 18:47 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-30 16:02 - 2014-06-11 18:47 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-30 15:57 - 2014-06-11 18:47 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-30 15:56 - 2014-06-11 18:47 - 04244992 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-30 15:54 - 2014-06-11 18:47 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-30 15:50 - 2014-06-11 18:47 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-05-30 15:49 - 2014-06-11 18:47 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-30 15:40 - 2014-06-11 18:47 - 11725312 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-30 15:21 - 2014-06-11 18:47 - 01790976 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-30 15:15 - 2014-06-11 18:47 - 01143296 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-30 15:13 - 2014-06-11 18:47 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-30 09:00 - 2014-05-30 09:00 - 00000084 _____ () C:\Users\internet\Downloads\nano vom 28. Mai 2014.info
2014-05-30 09:00 - 2014-05-30 08:40 - 102334358 _____ () C:\Users\internet\Downloads\nano vom 28. Mai 2014@HIGH.mp4
2014-05-30 08:19 - 2014-05-30 08:19 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-05-30 08:18 - 2014-05-30 08:17 - 00003993 _____ () C:\Windows\system32\jupdate-1.7.0_60-b19.log
2014-05-30 08:18 - 2011-02-15 11:34 - 00000000 ____D () E:\Program Files\Java
2014-05-29 16:12 - 2014-04-29 08:22 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\MyPhoneExplorer
2014-05-29 15:36 - 2014-05-21 15:36 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\Mp3tag
2014-05-29 13:24 - 2013-06-19 16:54 - 00000000 ___HD () C:\Users\internet\.opdveza-an
2014-05-29 13:24 - 2013-06-19 16:54 - 00000000 ____D () C:\Users\internet\.borland
2014-05-28 13:09 - 2013-06-15 12:56 - 00000600 _____ () C:\Users\internet_2\AppData\Roaming\winscp.rnd
2014-05-27 09:55 - 2009-07-14 10:37 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-05-26 20:57 - 2014-05-30 07:52 - 00052920 _____ (StdLib) C:\Windows\system32\Drivers\{55685567-4840-4a91-962b-49a412e9485a}w.sys
2014-05-25 14:07 - 2014-05-25 14:07 - 00000756 _____ () C:\Users\internet\Desktop\FreeDoko.lnk
2014-05-25 14:07 - 2014-05-25 14:07 - 00000000 ____D () C:\Users\internet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeDoko
2014-05-25 14:05 - 2014-05-25 14:05 - 00000000 ____D () C:\Users\internet\FreeDoko
2014-05-25 14:05 - 2013-06-14 15:31 - 00000000 ____D () C:\Users\internet
2014-05-25 07:10 - 2014-03-03 09:12 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-24 14:03 - 2014-05-24 13:48 - 00001002 _____ () C:\Users\internet_2\Desktop\DBV_Klaerung.txt
2014-05-19 16:09 - 2013-09-13 09:30 - 00000000 ____D () C:\Users\internet_2\AppData\Roaming\Notepad++
2014-05-19 07:02 - 2009-07-14 12:53 - 00032592 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-05-18 12:11 - 2009-07-14 10:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-05-17 17:53 - 2013-06-23 07:54 - 00000000 ____D () C:\Users\internet\AppData\Roaming\Skype
2014-05-16 10:11 - 2013-06-14 16:41 - 00000000 ____D () C:\Users\internet_2
2014-05-16 09:51 - 2013-06-15 10:30 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-05-16 09:51 - 2013-06-15 10:30 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-05-15 19:13 - 2013-12-27 21:07 - 00068312 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-05-15 19:13 - 2013-10-20 11:43 - 00777488 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-05-15 19:13 - 2013-10-20 11:43 - 00411680 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
Files to move or delete:
====================
C:\Users\internet\AppData\Roaming\CamLayout.ini
C:\Users\internet\AppData\Roaming\CamShapes.ini
C:\Users\internet_2\AppData\Roaming\Camdata.ini
C:\Users\internet_2\AppData\Roaming\CamLayout.ini
C:\Users\internet_2\AppData\Roaming\CamShapes.ini
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-08 17:50
==================== End Of Log ============================ --- --- ---
--- --- ---
Anmerkung zur Gmer_zip Datei:
Natürlich habe ich die Anleitung zum Posten gelesen und auch versucht, alle Protokolle direkt einzu binden. Mitnichten will ich Dir unnötige Arbeit machen. Ich kann sehr wohl einschätzen, wie viel Mühe es eh schon macht, mir und all den Leuten hier zu helfen.
Aber als ich mir den Post in der Vorschau angesehen habe, da wurde mir mitgeteilt, das zuviele Zeichen vorhanden sind. Daher habe ich - übrigens wie in der Anleitung nachzulesen - das log von GMER als zip-Datei angehängt.
Leider war es mir gestern und heute nicht möglich Combofix zum laufen zu bekommen. Das Programm habe ich sowohl mit Adminrechten im eingeschränkten Account als auch direkt im Admin laufen lassen und es ist nie weiter gekommen, als bis zu der Meldung "Outputfolder: C:\3278...".
Im FRST kann man dazu ja finden
"Error: (06/13/2014 09:35:30 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: ComboFix.exe14.6.12.1137001cf86a76bb894ea0D:\AntiVirus\ComboFix.exe"
Aber das hilft mir nicht weiter. Ich hoffe, Du kannst damit was anfangen.
Ich hätte Dir gerne einen ScreenShot davon mit gepostet, aber leider werden meine Links aus der Dropbox ja nicht angezeigt.
Den Outputfolder unter C:\ konnte ich nicht finden, dafür aber einen neuen, mir unbekannten Ordner "32788R22FWJFW" mit folgendem Hint unter der Maus: "Shows the disk drives and hardware connected to this computer". Kann ich mir nicht erklären - hat aber vielleicht ja gar nichts mit Combofix zu tun.
Sorry dass ich Dir keine besseren Nachrichten bieten konnte - aber heute ist ja auch Freitag der 13. !
Gruß Andreas |