steini83x | 26.07.2013 18:41 | So hier nochmal das gleiche wie vorhin, nur als Admin ausgeführt, hat sich meiner Meinung nach aber nicht viel geändert:
FIRST.txt:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-07-2013
Ran by admin (administrator) on 26-07-2013 19:31:12
Running from C:\Users\praxo_000\Downloads
Windows 8 Pro (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe
(Microsoft Corporation) C:\Windows\system32\dashost.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
() C:\Users\wfe\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
(Iminent) C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
() C:\Program Files\Synology\Assistant\UsbClientService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ManyCam LLC) C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe
() C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [Ocs_SM] - C:\Users\wfe\AppData\Roaming\OCS\SM\SearchAnonymizer.exe [106496 2013-03-11] (OCS)
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor)
HKLM\...\RunOnce: [*WerKernelReporting] - %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq [439392 2012-07-26] (Microsoft Corporation)
HKLM-x32\...\RunOnce: [SPUpdSentinel] - "C:\Program Files (x86)\Common Files\Umbrella\umbrella_bkp.exe" -SERVICEARGS=c [2723368 2013-06-29] (Iminent)
HKCU\...\Run: [ManyCam] - C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe [5399888 2013-01-24] (ManyCam LLC)
HKCU\...\Run: [AdobeBridge] - [x]
HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1635752 2013-05-04] (Valve Corporation)
HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [4270640 2013-03-23] ()
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
HKCU\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-04-05] (Apple Inc.)
HKCU\...\Run: [Browser Infrastructure Helper] - C:\Users\wfe\AppData\Local\Smartbar\Application\QuickShare.exe [20248 2013-05-12] (Smartbar)
HKCU\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHVE.EXE [241280 2012-07-12] (SEIKO EPSON CORPORATION)
HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_7_700_224_Plugin.exe -update plugin [814472 2013-06-16] (Adobe Systems Incorporated)
HKCU\...\Winlogon: [Shell] cmd.exe [404992 2012-07-26] (Microsoft Corporation) <==== ATTENTION
HKCU\...\Command Processor: "C:\Users\wfe\AppData\Local\Temp\b34btbztdb0vavaw.exe" <======= ATTENTION
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.)
HKLM-x32\...\Run: [ConnectionCenter] - C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [304568 2010-10-12] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Iminent] - C:\Program Files (x86)\Iminent\Iminent.exe [1074736 2013-01-25] (Iminent)
HKLM-x32\...\Run: [IminentMessenger] - C:\Program Files (x86)\Iminent\Iminent.Messengers.exe [884784 2013-01-25] (Iminent)
HKLM-x32\...\Run: [BambooCore] - C:\Program Files (x86)\Bamboo Dock\BambooCore.exe [646744 2012-10-16] ()
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641704 2012-11-16] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] - C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-02-20] (Apple Inc.)
HKLM-x32\...\Run: [TrayServer] - C:\Program Files (x86)\MAGIX\Movie_Edit_Pro_17_Download_Version\TrayServer.exe [90112 2008-11-13] (MAGIX AG)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-01] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
AppInit_DLLs-x32: c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll [2212304 2013-01-16] ()
Startup: C:\Users\wfe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\wfe\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\wfe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\praxo_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\wfe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\wfe\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\wfe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=DE&userid=f52d5790-8852-4fe3-92bf-e4dcb16e615a&searchtype=ds&q={searchTerms}&installDate=20/03/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=DE&userid=f52d5790-8852-4fe3-92bf-e4dcb16e615a&searchtype=hp&installDate=20/03/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.delta-search.com/?affID=119828&tt=070312_xn2&babsrc=HP_ss&mntrId=ecd9a27100000000000000e04c1a9b14
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=DE&userid=f52d5790-8852-4fe3-92bf-e4dcb16e615a&searchtype=ds&q={searchTerms}&installDate=20/03/2013
SearchScopes: HKLM - DefaultScope {71588120-FC17-4463-B07D-2C71FE6E057B} URL = hxxp://go.findrsearch.com/search/web?q={searchTerms}
SearchScopes: HKLM - {71588120-FC17-4463-B07D-2C71FE6E057B} URL = hxxp://go.findrsearch.com/search/web?q={searchTerms}
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=DE&userid=f52d5790-8852-4fe3-92bf-e4dcb16e615a&searchtype=ds&q={searchTerms}&installDate=20/03/2013
SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=DE&userid=f52d5790-8852-4fe3-92bf-e4dcb16e615a&searchtype=ds&q={searchTerms}&installDate=20/03/2013
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com.anonymize-me.de/?anonymto=687474703A2F2F7777772E62696E672E636F6D2F7365617263683F713D7B7365617263685465726D737D267372633D49452D536561726368426F7826464F524D3D494531305352&st={searchTerms}&clid=4a6b96bb-d8b1-4c86-aad3-67f687815e96&pid=proxtubede&k=0
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&affID=119828&tt=070312_xn2&babsrc=SP_ss&mntrId=ecd9a27100000000000000e04c1a9b14
BHO: QuickShare WidgetEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MIF5BA~1\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~1\MIF5BA~1\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: QuickShare WidgetEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: IMinent WebBooster (BHO) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files (x86)\Iminent\Iminent.WebBooster.InternetExplorer.dll (Iminent)
BHO-x32: LyricsTube - {B399EDE8-1525-458C-8DD9-31EADF632D06} - C:\Program Files (x86)\LyricsTube\lrcstube.dll (Hansen & Destar Apps)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MIF5BA~1\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Webtestaufzeichnung 10.0-Hilfsprogramm - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - c:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
Toolbar: HKLM - QuickShare Widget - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com)
Toolbar: HKLM-x32 - QuickShare Widget - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Hosts: Hosts file not detected in the default directory
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\wfe\AppData\Roaming\Mozilla\Firefox\Profiles\jhb3q8jg.default
FF user.js: detected! => C:\Users\wfe\AppData\Roaming\Mozilla\Firefox\Profiles\jhb3q8jg.default\user.js
FF NewTab: hxxp://www.delta-search.com/?affID=119370&babsrc=NT_ss&mntrId=ecd9a27100000000000000e04c1a9b14
FF SelectedSearchEngine: Delta Search
FF Homepage: hxxp://www.delta-search.com/?affID=119370&babsrc=HP_ss&mntrId=ecd9a27100000000000000e04c1a9b14
FF NetworkProxy: "autoconfig_url", "data:application/x-ns-proxy-autoconfig;base64,ZnVuY3Rpb24gRmluZFByb3h5Rm9yVVJMKHVybCwgaG9zdCkgewogIGlmICgoaG9zdCA9PSAnd3d3LnlvdXR1YmUuY29tJyAmJiB1cmwuaW5kZXhPZigneW91dHViZS5jb20vd2F0Y2g/dj1RSzhtSkpKdmFlcyZweHRyeT0yJykgIT0gLTEpIHx8IChob3N0LmluZGV4T2YoJ2MueW91dHViZS5jb20nKSAhPSAtMSAmJiB1cmwuaW5kZXhPZignYy55b3V0dWJlLmNvbS92aWRlb3BsYXliYWNrJykgIT0gLTEgJiYgdXJsLmluZGV4T2YoJ2djcj11cycpICE9IC0xKSkKICAgIHJldHVybiAnUFJPWFkgMjA5LjIzOS4xMjAuMTA3OjMxMzEnOwogIHJldHVybiAnRElSRUNUJzsKfQ=="
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.2 - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MIF5BA~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @protectdisc.com/NPMPDRM - C:\Program Files (x86)\Common Files\mpDRM\Binaries\NPMPDRM.dll ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.2 - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\wfe\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF SearchPlugin: C:\Users\wfe\AppData\Roaming\Mozilla\Firefox\Profiles\jhb3q8jg.default\searchplugins\Web Search.xml
FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\wfe\AppData\Roaming\Mozilla\Firefox\Profiles\jhb3q8jg.default\Extensions\ich@maltegoetz.de
FF Extension: No Name - C:\Users\wfe\AppData\Roaming\Mozilla\Firefox\Profiles\jhb3q8jg.default\Extensions\{f52d5790-8852-4fe3-92bf-e4dcb16e615a}
FF Extension: webbooster - C:\Users\wfe\AppData\Roaming\Mozilla\Firefox\Profiles\jhb3q8jg.default\Extensions\webbooster@iminent.com.xpi
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [downloader@finalvideotools.com] C:\Program Files (x86)\FinalVideoDownloader\Firefox
FF Extension: FinalVideoDownloader plugin for Mozilla Firefox - C:\Program Files (x86)\FinalVideoDownloader\Firefox
FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\
FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\
FF HKCU\...\Firefox\Extensions: [{58bd07eb-0ee0-4df0-8121-dc9b693373df}] C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension
FF Extension: BrowserProtect - C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension
FF HKCU\...\Firefox\Extensions: [lrcsTube@hansanddeta.com] C:\Program Files (x86)\LyricsTube\FF\
FF Extension: No Name - C:\Program Files (x86)\LyricsTube\FF\
Chrome:
=======
CHR DefaultSearchURL: (Web) - hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=DE&userid=f52d5790-8852-4fe3-92bf-e4dcb16e615a&searchtype=ds&q={searchTerms}&installDate=20/03/2013
CHR DefaultSuggestURL: (Web) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2013) - C:\Program Files (x86)\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft Office 2013) - C:\PROGRA~2\MIF5BA~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (fluxDVD Browser Plugin) - C:\Program Files (x86)\Common Files\mpDRM\Binaries\NPMPDRM.dll ( )
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U13) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (WacomTabletPlugin) - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
CHR Plugin: (Uplay PC) - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Unity Player) - C:\Users\wfe\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.130.20) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
CHR Extension: (ProxTube) - C:\Users\wfe\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.2.1_0
CHR Extension: (FoxyDeal) - C:\Users\wfe\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiennapmieppnpfhhogglccgepbdajan\6.2.0_0
CHR Extension: (QuickShare Widget) - C:\Users\wfe\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0
CHR Extension: (LyricsTube) - C:\Users\wfe\AppData\Local\Google\Chrome\User Data\Default\Extensions\bebdghdpchfhbbmfeddkijldlpnkbjkk\1.111_0
CHR Extension: (Freemake Video Converter) - C:\Users\wfe\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0
CHR Extension: (BrowserProtect) - C:\Users\wfe\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph\1.0_0
CHR HKLM-x32\...\Chrome\Extension: [aakchaleigkohafkfjfjbblobjifikek] - C:\Users\wfe\AppData\LocalLow\proxtube\CHROME\proxtube.crx
CHR HKLM-x32\...\Chrome\Extension: [aiennapmieppnpfhhogglccgepbdajan] - C:\Program Files (x86)\FoxyDeal\foxydeal.crx
CHR HKLM-x32\...\Chrome\Extension: [bebdghdpchfhbbmfeddkijldlpnkbjkk] - C:\Program Files (x86)\LyricsTube\Chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [pgafcinpmmpklohkojmllohdhomoefph] - C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.crx
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-07-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-01] (Avira Operations GmbH & Co. KG)
R2 BrowserProtect; C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [2550224 2013-01-16] ()
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
R2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation)
R2 SearchAnonymizer; C:\Users\wfe\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [40960 2013-03-11] ()
R2 SProtection; C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe [2859048 2013-07-15] (Iminent)
S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation)
R2 UsbClientService; C:\Program Files\Synology\Assistant\UsbClientService.exe [248704 2012-10-22] ()
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-12-11] (Wacom Technology, Corp.)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-02-26] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130016 2013-02-26] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-02-26] (Avira Operations GmbH & Co. KG)
R3 ManyCam; C:\Windows\system32\DRIVERS\mcvidrv_x64.sys [44544 2013-01-15] (ManyCam LLC)
R3 mcaudrv_simple; C:\Windows\system32\drivers\mcaudrv_x64.sys [29696 2012-10-11] (ManyCam LLC)
R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
R3 RTL8023x64; C:\Windows\system32\DRIVERS\Rtnic64.sys [51712 2012-06-02] (Realtek Semiconductor Corporation )
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
S3 VSPerfDrv100; c:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [68440 2010-03-17] (Microsoft Corporation)
S3 VSPerfDrv100; c:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [68440 2010-03-17] (Microsoft Corporation)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-26] (Microsoft Corporation)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-26] (Microsoft Corporation)
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [x]
S1 ipikqsbm; \??\C:\Windows\system32\drivers\ipikqsbm.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-26 19:30 - 2013-07-26 19:30 - 00080529 _____ C:\Users\wfe\Desktop\FRST.txt
2013-07-26 19:30 - 2013-07-26 19:30 - 00080529 _____ C:\Users\wfe\Desktop\FRST.txt
2013-07-26 15:03 - 2013-07-26 15:03 - 03441528 _____ (Solvusoft Corporation ) C:\Users\praxo_000\Downloads\LiteOn_iHOS104_Treiber_Update_07-2013.exe
2013-07-26 13:22 - 2013-07-26 13:22 - 00003554 _____ C:\Users\praxo_000\Desktop\FSS.txt
2013-07-26 13:21 - 2013-07-26 13:21 - 00003554 _____ C:\Users\praxo_000\Downloads\FSS.txt
2013-07-26 13:20 - 2013-07-26 13:20 - 00357145 _____ (Farbar) C:\Users\praxo_000\Downloads\FSS.exe
2013-07-26 13:19 - 2013-07-26 13:32 - 00035252 _____ C:\Users\praxo_000\Desktop\Addition.txt
2013-07-26 13:19 - 2013-07-26 13:30 - 00039186 _____ C:\Users\praxo_000\Desktop\FRST.txt
2013-07-26 12:40 - 2013-07-26 12:40 - 00035252 _____ C:\Users\praxo_000\Downloads\Addition.txt
2013-07-26 12:38 - 2013-07-26 12:38 - 01779853 _____ (Farbar) C:\Users\praxo_000\Downloads\FRST64.exe
2013-07-26 12:38 - 2013-07-26 12:38 - 00000000 ____D C:\FRST
2013-07-25 20:47 - 2013-07-25 20:48 - 00000000 ____D C:\Users\praxo_000\Desktop\Unbenannt
2013-07-25 18:07 - 2013-07-25 18:09 - 734937088 _____ C:\Users\praxo_000\Downloads\KNOPPIX_V7.2.0CD-2013-06-16-DE.iso
2013-07-24 19:46 - 2013-07-24 19:46 - 23730176 _____ (Macrovision Corporation) C:\Users\praxo_000\Downloads\IATA89CD.exe
2013-07-24 19:46 - 2013-07-24 19:46 - 00000000 ____D C:\ProgramData\InstallShield
2013-07-24 18:57 - 2013-07-24 18:57 - 27696104 _____ (Advanced Micro Devices, Inc.) C:\Users\praxo_000\Downloads\13-4_vista_win7_win8_32-64_sb.exe
2013-07-24 18:09 - 2013-07-24 18:09 - 04179293 _____ (Lavalys, Inc. ) C:\Users\praxo_000\Downloads\everesthome220.exe
2013-07-24 18:09 - 2013-07-24 18:09 - 00001106 _____ C:\Users\wfe\Desktop\EVEREST Home Edition.lnk
2013-07-24 18:09 - 2013-07-24 18:09 - 00001106 _____ C:\Users\wfe\Desktop\EVEREST Home Edition.lnk
2013-07-24 18:09 - 2013-07-24 18:09 - 00001106 _____ C:\Users\praxo_000\Desktop\EVEREST Home Edition.lnk
2013-07-24 18:09 - 2013-07-24 18:09 - 00000000 ____D C:\Program Files (x86)\Lavalys
2013-07-23 21:01 - 2013-07-23 21:01 - 01067520 _____ () C:\Users\praxo_000\Downloads\WL0G(1).EXE
2013-07-23 21:01 - 2013-07-23 21:01 - 01064448 _____ () C:\Users\praxo_000\Downloads\WL0F.EXE
2013-07-23 21:00 - 2013-07-23 21:01 - 00039411 _____ C:\DEBUG.TXT
2013-07-23 21:00 - 2013-07-23 21:00 - 01067520 _____ () C:\Users\praxo_000\Downloads\WL0G.EXE
2013-07-23 20:57 - 2013-07-23 20:57 - 00000000 ____D C:\Users\praxo_000\Documents\SmartPack
2013-07-23 20:56 - 2013-07-26 15:03 - 00001905 _____ C:\Users\wfe\Desktop\PLDS SmartPack Utility.lnk
2013-07-23 20:56 - 2013-07-26 15:03 - 00001905 _____ C:\Users\wfe\Desktop\PLDS SmartPack Utility.lnk
2013-07-23 20:56 - 2013-07-26 15:03 - 00000000 ____D C:\Users\wfe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartPack
2013-07-23 20:56 - 2013-07-26 15:03 - 00000000 ____D C:\Program Files (x86)\SmartPack
2013-07-20 15:28 - 2013-07-20 15:28 - 02936240 _____ C:\Users\praxo_000\Downloads\installproXPN.exe
2013-07-20 15:28 - 2013-07-20 15:28 - 00001065 _____ C:\Users\wfe\Desktop\proXPN.lnk
2013-07-20 15:28 - 2013-07-20 15:28 - 00001065 _____ C:\Users\wfe\Desktop\proXPN.lnk
2013-07-20 15:28 - 2013-07-20 15:28 - 00000000 ____D C:\Users\wfe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\proXPN
2013-07-20 15:28 - 2013-07-20 15:28 - 00000000 ____D C:\Program Files (x86)\proXPN
2013-07-14 14:49 - 2013-07-14 14:49 - 00000000 ____D C:\Users\praxo_000\Documents\Benutzerdefinierte Office-Vorlagen
2013-07-14 14:15 - 2013-07-14 14:15 - 00000162 ____H C:\Users\praxo_000\Desktop\~$nährung.odt
2013-07-14 13:38 - 2013-07-14 13:38 - 12779056 _____ C:\Users\praxo_000\Downloads\LOOP 7.wmv
2013-07-13 14:57 - 2013-07-13 14:57 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-07-13 14:57 - 2013-07-13 14:57 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-07-13 14:57 - 2013-07-13 14:57 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-07-13 14:57 - 2013-07-13 14:57 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-07-13 14:55 - 2013-07-13 14:55 - 00903080 _____ (Oracle Corporation) C:\Users\praxo_000\Downloads\jxpiinstall.exe
2013-07-13 14:51 - 2013-07-13 14:51 - 00000000 ____D C:\Windows\system32\appmgmt
2013-07-13 12:55 - 2013-07-13 12:55 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1ce7fb78c30f148.job
2013-07-11 17:28 - 2013-07-11 17:28 - 00009166 _____ C:\Users\praxo_000\Downloads\1373556032.html
2013-06-30 20:56 - 2013-06-30 20:56 - 00000404 _____ C:\Users\praxo_000\SciTE.session
2013-06-30 20:18 - 2013-06-30 20:18 - 00000000 ____D C:\Users\praxo_000\AppData\Local\FileTypeAssistant
2013-06-30 11:00 - 2013-06-30 11:00 - 00000000 ____D C:\Users\praxo_000\Desktop\Aufnahmen
2013-06-28 20:10 - 2013-06-28 20:10 - 00000000 ____D C:\Users\praxo_000\AppData\Roaming\Unity
2013-06-28 19:57 - 2013-06-28 19:57 - 00643592 _____ (Unity Technologies ApS) C:\Users\praxo_000\Downloads\UnityWebPlayer.exe
2013-06-28 19:57 - 2013-06-28 19:57 - 00000000 ____D C:\Users\praxo_000\AppData\Local\Unity
2013-06-28 14:29 - 2013-06-28 14:29 - 00000000 ____D C:\Users\praxo_000\AppData\Roaming\Milestone
2013-06-28 14:29 - 2013-06-28 14:29 - 00000000 ____D C:\Users\praxo_000\AppData\Roaming\InstallShield Installation Information
2013-06-27 19:31 - 2013-06-27 19:31 - 00000000 ____D C:\Users\praxo_000\AppData\Roaming\OpenOffice.org
2013-06-26 16:20 - 2013-07-25 20:49 - 00002259 _____ C:\Users\Public\Desktop\Google Chrome.lnk
==================== One Month Modified Files and Folders =======
2013-07-26 19:31 - 2013-06-11 18:37 - 00000000 ____D C:\Users\praxo_000\AppData\Local\PMB Files
2013-07-26 19:30 - 2013-07-26 19:30 - 00080529 _____ C:\Users\wfe\Desktop\FRST.txt
2013-07-26 19:30 - 2013-07-26 19:30 - 00080529 _____ C:\Users\wfe\Desktop\FRST.txt
2013-07-26 19:23 - 2013-06-11 18:38 - 00000000 ____D C:\Users\praxo_000\AppData\Roaming\Skype
2013-07-26 15:26 - 2013-04-01 20:08 - 00000000 ____D C:\Users\praxo_000\AppData\Roaming\vlc
2013-07-26 15:03 - 2013-07-26 15:03 - 03441528 _____ (Solvusoft Corporation ) C:\Users\praxo_000\Downloads\LiteOn_iHOS104_Treiber_Update_07-2013.exe
2013-07-26 15:03 - 2013-07-23 20:56 - 00001905 _____ C:\Users\wfe\Desktop\PLDS SmartPack Utility.lnk
2013-07-26 15:03 - 2013-07-23 20:56 - 00001905 _____ C:\Users\wfe\Desktop\PLDS SmartPack Utility.lnk
2013-07-26 15:03 - 2013-07-23 20:56 - 00000000 ____D C:\Users\wfe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartPack
2013-07-26 15:03 - 2013-07-23 20:56 - 00000000 ____D C:\Program Files (x86)\SmartPack
2013-07-26 14:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru
2013-07-26 13:32 - 2013-07-26 13:19 - 00035252 _____ C:\Users\praxo_000\Desktop\Addition.txt
2013-07-26 13:30 - 2013-07-26 13:19 - 00039186 _____ C:\Users\praxo_000\Desktop\FRST.txt
2013-07-26 13:22 - 2013-07-26 13:22 - 00003554 _____ C:\Users\praxo_000\Desktop\FSS.txt
2013-07-26 13:21 - 2013-07-26 13:21 - 00003554 _____ C:\Users\praxo_000\Downloads\FSS.txt
2013-07-26 13:20 - 2013-07-26 13:20 - 00357145 _____ (Farbar) C:\Users\praxo_000\Downloads\FSS.exe
2013-07-26 12:40 - 2013-07-26 12:40 - 00035252 _____ C:\Users\praxo_000\Downloads\Addition.txt
2013-07-26 12:38 - 2013-07-26 12:38 - 01779853 _____ (Farbar) C:\Users\praxo_000\Downloads\FRST64.exe
2013-07-26 12:38 - 2013-07-26 12:38 - 00000000 ____D C:\FRST
2013-07-26 12:34 - 2013-06-11 18:37 - 00000000 ____D C:\Users\praxo_000\AppData\Local\TSVNCache
2013-07-25 21:01 - 2013-06-16 13:06 - 00006656 _____ C:\Users\praxo_000\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-07-25 20:49 - 2013-06-26 16:20 - 00002259 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-07-25 20:48 - 2013-07-25 20:47 - 00000000 ____D C:\Users\praxo_000\Desktop\Unbenannt
2013-07-25 18:09 - 2013-07-25 18:07 - 734937088 _____ C:\Users\praxo_000\Downloads\KNOPPIX_V7.2.0CD-2013-06-16-DE.iso
2013-07-24 19:46 - 2013-07-24 19:46 - 23730176 _____ (Macrovision Corporation) C:\Users\praxo_000\Downloads\IATA89CD.exe
2013-07-24 19:46 - 2013-07-24 19:46 - 00000000 ____D C:\ProgramData\InstallShield
2013-07-24 18:57 - 2013-07-24 18:57 - 27696104 _____ (Advanced Micro Devices, Inc.) C:\Users\praxo_000\Downloads\13-4_vista_win7_win8_32-64_sb.exe
2013-07-24 18:26 - 2013-02-04 18:33 - 01409015 _____ C:\Windows\WindowsUpdate.log
2013-07-24 18:26 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-07-24 18:13 - 2012-07-26 07:26 - 00524288 ___SH C:\Windows\system32\config\BBI
2013-07-24 18:09 - 2013-07-24 18:09 - 04179293 _____ (Lavalys, Inc. ) C:\Users\praxo_000\Downloads\everesthome220.exe
2013-07-24 18:09 - 2013-07-24 18:09 - 00001106 _____ C:\Users\wfe\Desktop\EVEREST Home Edition.lnk
2013-07-24 18:09 - 2013-07-24 18:09 - 00001106 _____ C:\Users\wfe\Desktop\EVEREST Home Edition.lnk
2013-07-24 18:09 - 2013-07-24 18:09 - 00001106 _____ C:\Users\praxo_000\Desktop\EVEREST Home Edition.lnk
2013-07-24 18:09 - 2013-07-24 18:09 - 00000000 ____D C:\Program Files (x86)\Lavalys
2013-07-23 21:01 - 2013-07-23 21:01 - 01067520 _____ () C:\Users\praxo_000\Downloads\WL0G(1).EXE
2013-07-23 21:01 - 2013-07-23 21:01 - 01064448 _____ () C:\Users\praxo_000\Downloads\WL0F.EXE
2013-07-23 21:01 - 2013-07-23 21:00 - 00039411 _____ C:\DEBUG.TXT
2013-07-23 21:00 - 2013-07-23 21:00 - 01067520 _____ () C:\Users\praxo_000\Downloads\WL0G.EXE
2013-07-23 20:57 - 2013-07-23 20:57 - 00000000 ____D C:\Users\praxo_000\Documents\SmartPack
2013-07-21 16:27 - 2013-04-01 20:08 - 00000000 ____D C:\Users\praxo_000\AppData\Local\CrashDumps
2013-07-20 15:28 - 2013-07-20 15:28 - 02936240 _____ C:\Users\praxo_000\Downloads\installproXPN.exe
2013-07-20 15:28 - 2013-07-20 15:28 - 00001065 _____ C:\Users\wfe\Desktop\proXPN.lnk
2013-07-20 15:28 - 2013-07-20 15:28 - 00001065 _____ C:\Users\wfe\Desktop\proXPN.lnk
2013-07-20 15:28 - 2013-07-20 15:28 - 00000000 ____D C:\Users\wfe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\proXPN
2013-07-20 15:28 - 2013-07-20 15:28 - 00000000 ____D C:\Program Files (x86)\proXPN
2013-07-20 15:28 - 2012-07-26 07:26 - 00000190 _____ C:\Windows\win.ini
2013-07-20 14:53 - 2013-04-04 14:11 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-07-20 14:53 - 2013-04-04 14:11 - 00000000 ____D C:\ProgramData\Skype
2013-07-14 14:49 - 2013-07-14 14:49 - 00000000 ____D C:\Users\praxo_000\Documents\Benutzerdefinierte Office-Vorlagen
2013-07-14 14:15 - 2013-07-14 14:15 - 00000162 ____H C:\Users\praxo_000\Desktop\~$nährung.odt
2013-07-13 14:57 - 2013-07-13 14:57 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-07-13 14:57 - 2013-07-13 14:57 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-07-13 14:57 - 2013-07-13 14:57 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-07-13 14:57 - 2013-07-13 14:57 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-07-13 14:57 - 2013-02-09 18:18 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-07-13 14:57 - 2013-02-09 18:18 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-07-13 14:55 - 2013-07-13 14:55 - 00903080 _____ (Oracle Corporation) C:\Users\praxo_000\Downloads\jxpiinstall.exe
2013-07-13 14:51 - 2013-07-13 14:51 - 00000000 ____D C:\Windows\system32\appmgmt
2013-07-13 12:55 - 2013-07-13 12:55 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1ce7fb78c30f148.job
2013-07-11 17:28 - 2013-07-11 17:28 - 00009166 _____ C:\Users\praxo_000\Downloads\1373556032.html
2013-07-01 19:11 - 2013-06-20 15:06 - 00000244 _____ C:\Users\praxo_000\Desktop\Neues Textdokument.txt
2013-07-01 17:11 - 2013-06-11 18:44 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-06-30 20:56 - 2013-06-30 20:56 - 00000404 _____ C:\Users\praxo_000\SciTE.session
2013-06-30 20:56 - 2013-04-01 15:20 - 00000000 ____D C:\Users\praxo_000
2013-06-30 20:18 - 2013-06-30 20:18 - 00000000 ____D C:\Users\praxo_000\AppData\Local\FileTypeAssistant
2013-06-30 11:00 - 2013-06-30 11:00 - 00000000 ____D C:\Users\praxo_000\Desktop\Aufnahmen
2013-06-29 20:38 - 2013-02-09 01:20 - 00000000 ____D C:\Users\wfe\Desktop\Unbenannt
2013-06-29 20:38 - 2013-02-09 01:20 - 00000000 ____D C:\Users\wfe\Desktop\Unbenannt
2013-06-28 20:10 - 2013-06-28 20:10 - 00000000 ____D C:\Users\praxo_000\AppData\Roaming\Unity
2013-06-28 19:57 - 2013-06-28 19:57 - 00643592 _____ (Unity Technologies ApS) C:\Users\praxo_000\Downloads\UnityWebPlayer.exe
2013-06-28 19:57 - 2013-06-28 19:57 - 00000000 ____D C:\Users\praxo_000\AppData\Local\Unity
2013-06-28 14:35 - 2013-02-04 18:41 - 00154400 _____ C:\Windows\DirectX.log
2013-06-28 14:29 - 2013-06-28 14:29 - 00000000 ____D C:\Users\praxo_000\AppData\Roaming\Milestone
2013-06-28 14:29 - 2013-06-28 14:29 - 00000000 ____D C:\Users\praxo_000\AppData\Roaming\InstallShield Installation Information
2013-06-27 19:31 - 2013-06-27 19:31 - 00000000 ____D C:\Users\praxo_000\AppData\Roaming\OpenOffice.org
Files to move or delete:
====================
C:\ProgramData\rundll32.exe
C:\ProgramData\23lldnur.pad
C:\ProgramData\l01dz.bat
C:\ProgramData\l01dz.pad
C:\ProgramData\l01dz.reg
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-06-12 17:02
==================== End Of Log ============================ --- --- ---
FSS.txt: Code:
Farbar Service Scanner Version: 26-07-2013
Ran by admin (administrator) on 26-07-2013 at 19:34:28
Running from "C:\Users\praxo_000\Downloads"
Microsoft Windows 8 Pro (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is set to Demand. The default start type is Auto.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.
Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is set to Demand. The default start type is Auto.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv service is OK.
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend: ""%ProgramFiles%\Windows Defender\MsMpEng.exe"".
Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
Other Services:
==============
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2013-04-12 19:59] - [2013-03-02 11:59] - 2231528 ____A (Microsoft Corporation) B6D52E2C38B49A156E58FF5B9C6CA8BE
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll
[2013-04-12 19:59] - [2013-03-02 04:45] - 3240448 ____A (Microsoft Corporation) 79F95469604B77296346DE7DB463EA2A
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MsMpEng.exe => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log **** |