Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Pc hängt öfter (https://www.trojaner-board.de/125399-pc-haengt-oefter.html)

mädchen 09.10.2012 10:33

Pc hängt öfter
 
Hallo liebe Experten,
ich bin schon seit Tagen auf der Suche nach der Lösung für mein Problem : der Pc hängt öfter, ist langsam und ich weiß nicht warum. Ich habe Avira,Panda online scanner,Bitdefender,Uniblue Registry Booster, CCleaner,Wash and go, Tune up utilities 2013.Alles gemacht, Problem aber nicht behoben. Wenn ich z.B google und einen Link anklicken will,geht für Minuten erst mal nichts und dann gehts weiter ohne daß ich dafür irgendwas getan hätte. Das Umschalten zwischen den einzelnen Fenster dauert unendlich lange, beim Starten des PCs stottert der Ton, bei you tube kann ich nicht ein einziges Video sehen,der Pc bleibt sofort hängen.Will ich z.B.Word Pad benutzen, muss ich auch erst mal Minuten warten.Gelegentlich öffnet sich einfach so ein Bild aus der Bildergalerie ohne daß ich es angeklickt hätte,ab und zu habe ich kurz mal keinen Mausanzeiger mehr und ganz oft lässt sich Text nicht markieren.:schrei:
Da ich zwar in der Lage bin Anweisungen zu befolgen die mir die Programme empfehlen, aber eigentlich nicht die Bohne von dem verstehe was ich da eigentlich mache ( bin völlig talentfrei was Technik angeht), bin ich auf eine genaue Anleitung angewiesen die keine Vorkenntnisse voraussetzt. Ich habe das hier gelesen wie Ihr jemand mit einem ähnlichen Problem mit einer Anleitung geholfen habt. Der verstand aber auch mehr vom PC als ich.............aber dennoch würde ich es gerne versuchen, das nervt nämlich unendlich. Ich habe früher schon mal einen anderen Pc weggebracht wegen ähnlicher Probleme und das hat ein Schweingeld gekostet das ich jetzt nicht ausgeben kann, deshalb versuche ich mir hier Hilfe zu holen.Ach ja, ich habe Windows Vista

Jig Saw 09.10.2012 10:53

http://www.trojaner-board.de/images/...willkommen.png,

beachte bitte diesen Link und arbeite diesen ab:
http://www.trojaner-board.de/69886-a...-beachten.html
Danach wird sich dir ein Helfer annehmen. Falls dennoch Fragen zu den einzelnen Schritten offen bleiben, einfach nachfragen. Zusätzliche Infos sind noch interessant:
  • Seit wann besteht das Problem?
  • Haben die Scans von den AntiViren-Programmen etwas gefunden? Wenn Ja dann bitte die Logfiles posten

mädchen 10.10.2012 11:21

Hallo Ihr Lieben,
bin dabei das abzuarbeiten. Der defogger hat mit keine Fehlermeldung angezeigt und das Ergebnis vom OTL kommt hier: OTL Logfile:
Code:

OTL logfile created on: 10.10.2012 11:36:54 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\pc\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 1,01 Gb Available Physical Memory | 50,71% Memory free
4,22 Gb Paging File | 2,89 Gb Available in Paging File | 68,44% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 63,48 Gb Total Space | 28,42 Gb Free Space | 44,77% Space Free | Partition Type: NTFS
Drive D: | 20,49 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 387,63 Gb Total Space | 361,73 Gb Free Space | 93,32% Space Free | Partition Type: NTFS
Drive H: | 1,84 Gb Total Space | 1,82 Gb Free Space | 99,16% Space Free | Partition Type: FAT
 
Computer Name: PC-PC | User Name: pc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.10.10 11:31:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\pc\Desktop\OTL.exe
PRC - [2012.10.07 12:48:08 | 000,959,944 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
PRC - [2012.10.07 12:48:08 | 000,711,112 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.0.0\ToolbarUpdater.exe
PRC - [2012.09.19 11:29:44 | 001,869,152 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
PRC - [2012.09.19 11:29:42 | 001,699,168 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
PRC - [2012.09.19 11:27:26 | 001,060,704 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\Integrator.exe
PRC - [2012.09.13 15:26:52 | 001,006,448 | ---- | M] () -- C:\Windows\System32\dmwu.exe
PRC - [2012.08.09 19:44:26 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.07.12 12:04:10 | 000,162,408 | ---- | M] (Geek Software GmbH) -- C:\Program Files\PDF24\pdf24.exe
PRC - [2012.07.08 14:39:22 | 000,056,720 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
PRC - [2012.07.08 14:39:22 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
PRC - [2012.05.20 22:00:07 | 001,823,672 | ---- | M] (Bandoo Media, inc) -- C:\Program Files\Searchqu Toolbar\Datamngr\datamngrUI.exe
PRC - [2012.05.13 20:00:08 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.13 20:00:06 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.05.13 20:00:05 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.10.09 15:57:49 | 002,089,472 | ---- | M] (Bdrive Inc.) -- C:\Program Files\NetDrive\ndsvc.exe
PRC - [2011.10.09 15:57:36 | 002,572,800 | ---- | M] (Bdrive Inc.) -- C:\Program Files\NetDrive\netdrive.exe
PRC - [2011.08.08 13:31:46 | 000,828,416 | ---- | M] (ActMask Co.,Ltd - hxxp://www.all2pdf.com) -- C:\Windows\System32\PrintDisp.exe
PRC - [2011.07.20 03:44:22 | 000,099,688 | ---- | M] (Lunascape Co., LTD.) -- C:\Program Files\Lunascape\Lunascape6\Luna.exe
PRC - [2010.06.28 16:54:38 | 000,339,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows NT\Accessories\wordpad.exe
PRC - [2010.05.08 13:48:36 | 000,229,376 | ---- | M] () -- C:\ProgramData\DatacardService\DCService.exe
PRC - [2010.05.08 13:48:26 | 000,241,664 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe
PRC - [2010.04.29 05:04:12 | 000,069,632 | ---- | M] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) -- C:\Windows\System32\PrintCtrl.exe
PRC - [2009.05.25 13:09:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2008.05.07 10:19:26 | 006,139,904 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008.01.21 04:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.10.07 12:48:08 | 000,959,944 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
MOD - [2012.10.07 12:48:08 | 000,566,728 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\DNTInstaller\13.0.0\avgdttbx.dll
MOD - [2012.10.07 12:48:08 | 000,134,600 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\13.0.0\SiteSafety.dll
MOD - [2012.09.19 10:50:38 | 013,416,256 | ---- | M] () -- C:\Program Files\TuneUp Utilities 2013\libcef.dll
MOD - [2012.08.28 20:11:44 | 000,014,320 | ---- | M] () -- C:\Program Files\Java\jre6\bin\jp2native.dll
MOD - [2012.08.28 20:11:34 | 000,108,528 | ---- | M] () -- C:\Program Files\Java\jre6\bin\jp2iexp.dll
MOD - [2012.07.08 14:39:22 | 000,114,064 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\InstallerExtensions.dll
MOD - [2012.07.08 14:39:22 | 000,018,832 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\cwebpage.dll
MOD - [2012.07.08 14:39:16 | 000,136,592 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\locale\de\de.dll
MOD - [2011.03.22 10:08:22 | 000,138,752 | ---- | M] () -- C:\Program Files\NetDrive\libexpat.dll
MOD - [2009.12.10 11:52:38 | 000,192,512 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll
MOD - [2009.12.10 11:51:36 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll
MOD - [2009.12.10 11:40:20 | 000,991,232 | ---- | M] () -- C:\Program Files\Mobile Partner\NDISAPI.dll
MOD - [2009.09.19 11:21:06 | 000,139,264 | ---- | M] () -- C:\Program Files\Mobile Partner\NetInfoPlugin.dll
MOD - [2009.06.19 15:10:46 | 000,143,360 | ---- | M] () -- C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll
MOD - [2009.06.19 15:10:22 | 000,159,744 | ---- | M] () -- C:\Program Files\Mobile Partner\SMSPlugin.dll
MOD - [2009.06.18 10:56:10 | 000,032,768 | ---- | M] () -- C:\Program Files\Mobile Partner\NotifyServicePlugin.dll
MOD - [2009.06.18 10:54:14 | 000,057,344 | ---- | M] () -- C:\Program Files\Mobile Partner\ConfigFilePlugin.dll
MOD - [2009.06.18 10:48:24 | 000,090,112 | ---- | M] () -- C:\Program Files\Mobile Partner\DialUpPlugin.dll
MOD - [2009.05.25 13:09:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe
MOD - [2009.05.23 11:02:32 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobile Partner\XCodec.dll
MOD - [2009.05.23 11:02:30 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceOperate.dll
MOD - [2009.05.23 11:02:28 | 000,155,648 | ---- | M] () -- C:\Program Files\Mobile Partner\DetectDev.dll
MOD - [2009.05.23 11:02:24 | 000,557,056 | ---- | M] () -- C:\Program Files\Mobile Partner\atcomm.dll
MOD - [2009.02.12 10:53:02 | 000,040,448 | ---- | M] () -- C:\Program Files\NetDrive\ws_ext.dll
MOD - [2007.08.23 16:39:30 | 000,014,848 | ---- | M] () -- C:\Program Files\Mobile Partner\isaputrace.dll
MOD - [2007.07.31 15:50:04 | 000,090,112 | ---- | M] () -- C:\Program Files\Mobile Partner\FileManager.dll
 
 
========== Services (SafeList) ==========
 
SRV - [2012.10.07 12:48:08 | 000,711,112 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.0.0\ToolbarUpdater.exe -- (vToolbarUpdater13.0.0)
SRV - [2012.09.19 11:29:42 | 001,699,168 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2012.09.13 15:26:52 | 001,006,448 | ---- | M] () [Auto | Running] -- C:\Windows\System32\dmwu.exe -- (WebOptimizer)
SRV - [2012.08.23 15:40:04 | 000,188,760 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\Web Assistant\ExtensionUpdaterService.exe -- (Web Assistant Updater)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.05.13 20:00:08 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.13 20:00:05 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.10.09 15:57:49 | 002,089,472 | ---- | M] (Bdrive Inc.) [Auto | Running] -- C:\Program Files\NetDrive\ndsvc.exe -- (ndsvc)
SRV - [2010.05.08 13:48:36 | 000,229,376 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\DCService.exe -- (DCService.exe)
SRV - [2010.04.29 05:04:12 | 000,069,632 | ---- | M] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) [Auto | Running] -- C:\Windows\System32\PrintCtrl.exe -- (Printer Control)
SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - [2012.10.07 12:48:09 | 000,026,984 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtpx86.sys -- (avgtp)
DRV - [2012.09.19 10:50:50 | 000,010,088 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2012.05.13 20:00:08 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.05.13 20:00:08 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.09.16 16:08:07 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2011.03.25 10:21:12 | 000,049,432 | ---- | M] (MacroData Inc.) [File_System | On_Demand | Stopped] -- C:\Program Files\NetDrive\NDFS.sys -- (ndfs)
DRV - [2010.04.09 15:24:12 | 000,063,616 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2010.03.25 10:08:38 | 000,105,984 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2010.03.20 11:56:04 | 000,101,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2010.03.20 10:28:12 | 000,116,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2009.10.08 16:55:33 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.06.30 09:37:16 | 000,028,552 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\pavboot.sys -- (pavboot)
DRV - [2008.07.29 01:53:46 | 000,919,552 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008.05.02 07:59:40 | 000,122,368 | ---- | M] (Realtek Corporation                                            ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://msi.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bigseekpro.com/lickingdogscreen58/{ED7B955B-6018-4426-9A81-2A6584975D27}
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{7C788BE1-99B0-40CD-B58C-788705E205E2}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=MSITDF&pc=MAMI&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=161&systemid=406&sr=0&q={searchTerms}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT3227980
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://msi.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/?pc=AVBR
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.google.de/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://isearch.avg.com/?cid={6F3A6C9B-EBBC-4643-BCE5-1781EE57D853}&mid=6f5268bac3b847d0a364d15756fb0efd-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=de&ds=tt014&pr=sa&d=2012-10-07 12:49:10&v=13.0.0.7&sap=hp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {0cc09160-108c-4759-bab1-5c12c216e005} - No CLSID value found
IE - HKCU\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\DealBulldog Toolbar Toolbar\tbhelper.dll ()
IE - HKCU\..\URLSearchHook: {ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=112542&babsrc=SP_ss&mntrId=5445d1cc000000000000001e101f9843
IE - HKCU\..\SearchScopes\{288575EA-507B-42CB-97BE-ACED08F1998A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
IE - HKCU\..\SearchScopes\{4327FABE-3C22-4689-8DBF-D226CF777FE9}: "URL" = hxxp://www.searchplusnetwork.com/?sp=vit4&q={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADFA_deDE420
IE - HKCU\..\SearchScopes\{7C788BE1-99B0-40CD-B58C-788705E205E2}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=MSITDF&pc=MAMI&src=IE-SearchBox
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = https://isearch.avg.com/search?cid={6F3A6C9B-EBBC-4643-BCE5-1781EE57D853}&mid=6f5268bac3b847d0a364d15756fb0efd-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=de&ds=tt014&pr=sa&d=2012-10-07 12:49:10&v=13.0.0.7&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = hxxp://www.bigseekpro.com/search/browser/lickingdogscreen58/{ED7B955B-6018-4426-9A81-2A6584975D27}?q={searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=161&systemid=406&sr=0&q={searchTerms}
IE - HKCU\..\SearchScopes\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27}: "URL" = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = hxxp://mystart.incredibar.com/mb165/?search={searchTerms}&loc=IB_DS&a=6OyHBdc1Gw&i=26
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\13.0.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2012.09.12 12:24:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\13.0.0.7 [2012.10.07 12:49:31 | 000,000,000 | ---D | M]
 
[2011.07.14 13:58:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\pc\AppData\Roaming\mozilla\Extensions
[2012.07.11 10:56:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
 
========== Chrome  ==========
 
CHR - Extension: No name found = C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\
CHR - Extension: No name found = C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.478_0\
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Browser Companion Helper) - {00cbb66b-1d3b-46d3-9577-323a336acb50} - C:\Program Files\BrowserCompanion\jsloader.dll ( )
O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll ()
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\13.0.0.7\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Browser Companion Helper Verifier) - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files\BrowserCompanion\updatebhoWin32.dll ( )
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files\Searchqu Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc)
O2 - BHO: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\DealBulldog Toolbar Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (DealBulldog Toolbar Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\DealBulldog Toolbar Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\13.0.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (DealBulldog Toolbar Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\DealBulldog Toolbar Toolbar\tbcore3.dll ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Searchqu Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
O4 - HKLM..\Run: [Netdrive] C:\Program Files\NetDrive\netdrive.exe (Bdrive Inc.)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [PrintDisp] C:\Windows\System32\PrintDisp.exe (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
O4 - HKLM..\Run: [ROC_ROC_NT] C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [b1gMail-Utility] C:\Program Files\MailXXL.com Tools\BMUtil.exe ()
O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited)
O4 - Startup: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\pc\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tbhcn.lnk = C:\Users\pc\AppData\Roaming\BrowserCompanion\tbhcn.exe ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 193.189.244.206 193.189.244.225
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{59DDF262-BEC7-46A7-8D06-943CB65610D4}: DhcpNameServer = 193.189.244.206 193.189.244.225
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: NameServer = 132.252.3.10,132.252.1.7
O18 - Protocol\Handler\base64 {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O18 - Protocol\Handler\chrome {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O18 - Protocol\Handler\prox {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\13.0.0\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\pc\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\pc\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O27 - HKLM IFEO\bmutil.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\checkdrive.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\chrome.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\dropbox.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\hpwucli.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\schirmfoto.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\setup.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\tbhcn.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\uninstall.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010.05.08 21:48:36 | 000,126,976 | R--- | M] () - D:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2008.03.10 02:34:52 | 000,000,047 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.10 11:31:07 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\pc\Desktop\OTL.exe
[2012.10.09 05:10:27 | 000,000,000 | -H-D | C] -- C:\Windows\Icons
[2012.10.07 12:50:02 | 000,031,584 | ---- | C] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe
[2012.10.07 12:50:00 | 000,021,344 | ---- | C] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2012.10.07 12:49:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013
[2012.10.07 12:49:08 | 000,026,984 | ---- | C] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2012.10.07 12:47:43 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\TuneUp Software
[2012.10.07 12:47:29 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2013
[2012.10.07 12:46:31 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2012.10.07 12:46:15 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2012.09.18 20:58:26 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\rezepte
[2012.09.12 12:25:02 | 000,000,000 | ---D | C] -- C:\Windows\System32\WNLT
[2012.09.12 12:25:02 | 000,000,000 | ---D | C] -- C:\Windows\System32\ARFC
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.10 11:31:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\pc\Desktop\OTL.exe
[2012.10.10 11:27:05 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.10 11:27:05 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.10 11:22:22 | 000,000,000 | ---- | M] () -- C:\Users\pc\defogger_reenable
[2012.10.10 09:27:27 | 000,000,260 | ---- | M] () -- C:\Windows\tasks\AbelssoftPreloader.job
[2012.10.10 09:27:20 | 000,000,326 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job
[2012.10.10 09:27:03 | 000,271,760 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.10.10 09:27:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.09 09:39:25 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Communicator.job
[2012.10.09 09:39:25 | 000,000,294 | ---- | M] () -- C:\Windows\tasks\WebReg Deskjet F300 series.job
[2012.10.09 04:58:32 | 000,000,270 | ---- | M] () -- C:\Windows\tasks\CheckDriveBackgroundGuard.job
[2012.10.09 04:57:59 | 000,000,234 | ---- | M] () -- C:\Windows\tasks\Schirmfoto.job
[2012.10.07 18:24:56 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.10.07 18:24:56 | 000,001,086 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.10.07 12:49:48 | 000,001,839 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
[2012.10.07 12:49:48 | 000,001,835 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2012.10.07 12:48:09 | 000,026,984 | ---- | M] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2012.09.27 17:53:45 | 000,001,941 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.09.27 11:22:58 | 000,000,193 | ---- | M] () -- C:\Users\pc\Documents\Dokument.rtf
[2012.09.26 11:04:43 | 000,000,786 | ---- | M] () -- C:\Users\Public\Desktop\WashAndGo.lnk
[2012.09.24 22:18:28 | 000,002,174 | ---- | M] () -- C:\Users\pc\Documents\semmelknödel.rtf
[2012.09.23 12:16:20 | 000,001,087 | ---- | M] () -- C:\Users\pc\Desktop\scan.lnk
[2012.09.22 17:44:19 | 000,000,485 | ---- | M] () -- C:\Users\pc\Desktop\°.lnk
[2012.09.19 11:29:46 | 000,031,584 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe
[2012.09.19 11:29:40 | 000,021,344 | ---- | M] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2012.09.13 15:26:52 | 001,006,448 | ---- | M] () -- C:\Windows\System32\dmwu.exe
[2012.09.13 15:24:48 | 000,028,160 | ---- | M] () -- C:\Windows\System32\ImHttpComm.dll
 
========== Files Created - No Company Name ==========
 
[2012.10.10 11:22:22 | 000,000,000 | ---- | C] () -- C:\Users\pc\defogger_reenable
[2012.10.10 09:26:52 | 000,271,760 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.10.07 12:49:48 | 000,001,839 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
[2012.10.07 12:49:48 | 000,001,835 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2012.10.07 12:49:47 | 000,001,847 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013.lnk
[2012.09.26 11:04:43 | 000,000,786 | ---- | C] () -- C:\Users\Public\Desktop\WashAndGo.lnk
[2012.09.24 22:18:28 | 000,002,174 | ---- | C] () -- C:\Users\pc\Documents\semmelknödel.rtf
[2012.09.23 23:10:26 | 000,000,294 | ---- | C] () -- C:\Windows\tasks\WebReg Deskjet F300 series.job
[2012.09.23 12:12:43 | 000,001,087 | ---- | C] () -- C:\Users\pc\Desktop\scan.lnk
[2012.09.22 17:44:19 | 000,000,485 | ---- | C] () -- C:\Users\pc\Desktop\°.lnk
[2012.09.12 12:25:02 | 001,006,448 | ---- | C] () -- C:\Windows\System32\dmwu.exe
[2012.09.12 12:25:02 | 000,028,160 | ---- | C] () -- C:\Windows\System32\ImHttpComm.dll
[2012.07.10 14:48:59 | 000,000,519 | ---- | C] () -- C:\Users\pc\pc - Verknüpfung.lnk
[2012.04.27 18:29:20 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012.03.12 21:21:00 | 000,000,680 | ---- | C] () -- C:\Users\pc\AppData\Local\d3d9caps.dat
[2011.10.29 20:04:04 | 001,391,616 | ---- | C] () -- C:\Windows\System32\ActPDF.dll
[2011.10.29 20:03:43 | 000,691,200 | ---- | C] () -- C:\Windows\System32\PrintLog.exe
[2011.03.13 16:17:06 | 000,000,058 | ---- | C] () -- C:\Users\pc\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
[2011.02.25 15:46:39 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011.02.25 15:46:38 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010.12.31 17:07:07 | 000,164,255 | ---- | C] () -- C:\Windows\hpoins19.dat
[2010.12.31 17:06:48 | 000,026,952 | ---- | C] () -- C:\Windows\hpomdl19.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2011.07.11 19:50:05 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Abelssoft
[2011.07.14 09:12:55 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Avant Downloader
[2012.07.11 22:14:21 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Babylon
[2012.10.09 05:13:23 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\BrowserCompanion
[2011.03.13 16:17:06 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\DonationCoder
[2012.10.09 04:46:09 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Dropbox
[2011.07.14 11:05:34 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\freenet
[2012.09.19 04:44:35 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Image Zone Express
[2012.04.24 18:21:32 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\LibreOffice
[2011.07.14 13:03:56 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Lunascape
[2012.07.01 11:18:14 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\MusicNet
[2011.07.08 11:57:41 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\NetDrive
[2012.07.14 13:35:43 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\OpenCandy
[2012.07.19 18:57:51 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\pdfforge
[2011.11.09 16:23:43 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Printer Info Cache
[2012.09.20 10:21:21 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\QuickScan
[2012.10.07 14:38:51 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\TuneUp Software
[2011.09.21 00:30:12 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Uniblue
[2012.06.10 15:50:39 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Visan
 
========== Purity Check ==========
 
 

< End of report >

--- --- ---
OTL Logfile:
Code:

OTL logfile created on: 10.10.2012 11:36:54 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\pc\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 1,01 Gb Available Physical Memory | 50,71% Memory free
4,22 Gb Paging File | 2,89 Gb Available in Paging File | 68,44% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 63,48 Gb Total Space | 28,42 Gb Free Space | 44,77% Space Free | Partition Type: NTFS
Drive D: | 20,49 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 387,63 Gb Total Space | 361,73 Gb Free Space | 93,32% Space Free | Partition Type: NTFS
Drive H: | 1,84 Gb Total Space | 1,82 Gb Free Space | 99,16% Space Free | Partition Type: FAT
 
Computer Name: PC-PC | User Name: pc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.10.10 11:31:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\pc\Desktop\OTL.exe
PRC - [2012.10.07 12:48:08 | 000,959,944 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
PRC - [2012.10.07 12:48:08 | 000,711,112 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.0.0\ToolbarUpdater.exe
PRC - [2012.09.19 11:29:44 | 001,869,152 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
PRC - [2012.09.19 11:29:42 | 001,699,168 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
PRC - [2012.09.19 11:27:26 | 001,060,704 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\Integrator.exe
PRC - [2012.09.13 15:26:52 | 001,006,448 | ---- | M] () -- C:\Windows\System32\dmwu.exe
PRC - [2012.08.09 19:44:26 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.07.12 12:04:10 | 000,162,408 | ---- | M] (Geek Software GmbH) -- C:\Program Files\PDF24\pdf24.exe
PRC - [2012.07.08 14:39:22 | 000,056,720 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
PRC - [2012.07.08 14:39:22 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
PRC - [2012.05.20 22:00:07 | 001,823,672 | ---- | M] (Bandoo Media, inc) -- C:\Program Files\Searchqu Toolbar\Datamngr\datamngrUI.exe
PRC - [2012.05.13 20:00:08 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.13 20:00:06 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.05.13 20:00:05 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.10.09 15:57:49 | 002,089,472 | ---- | M] (Bdrive Inc.) -- C:\Program Files\NetDrive\ndsvc.exe
PRC - [2011.10.09 15:57:36 | 002,572,800 | ---- | M] (Bdrive Inc.) -- C:\Program Files\NetDrive\netdrive.exe
PRC - [2011.08.08 13:31:46 | 000,828,416 | ---- | M] (ActMask Co.,Ltd - hxxp://www.all2pdf.com) -- C:\Windows\System32\PrintDisp.exe
PRC - [2011.07.20 03:44:22 | 000,099,688 | ---- | M] (Lunascape Co., LTD.) -- C:\Program Files\Lunascape\Lunascape6\Luna.exe
PRC - [2010.06.28 16:54:38 | 000,339,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows NT\Accessories\wordpad.exe
PRC - [2010.05.08 13:48:36 | 000,229,376 | ---- | M] () -- C:\ProgramData\DatacardService\DCService.exe
PRC - [2010.05.08 13:48:26 | 000,241,664 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe
PRC - [2010.04.29 05:04:12 | 000,069,632 | ---- | M] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) -- C:\Windows\System32\PrintCtrl.exe
PRC - [2009.05.25 13:09:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2008.05.07 10:19:26 | 006,139,904 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008.01.21 04:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.10.07 12:48:08 | 000,959,944 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
MOD - [2012.10.07 12:48:08 | 000,566,728 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\DNTInstaller\13.0.0\avgdttbx.dll
MOD - [2012.10.07 12:48:08 | 000,134,600 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\13.0.0\SiteSafety.dll
MOD - [2012.09.19 10:50:38 | 013,416,256 | ---- | M] () -- C:\Program Files\TuneUp Utilities 2013\libcef.dll
MOD - [2012.08.28 20:11:44 | 000,014,320 | ---- | M] () -- C:\Program Files\Java\jre6\bin\jp2native.dll
MOD - [2012.08.28 20:11:34 | 000,108,528 | ---- | M] () -- C:\Program Files\Java\jre6\bin\jp2iexp.dll
MOD - [2012.07.08 14:39:22 | 000,114,064 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\InstallerExtensions.dll
MOD - [2012.07.08 14:39:22 | 000,018,832 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\cwebpage.dll
MOD - [2012.07.08 14:39:16 | 000,136,592 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\locale\de\de.dll
MOD - [2011.03.22 10:08:22 | 000,138,752 | ---- | M] () -- C:\Program Files\NetDrive\libexpat.dll
MOD - [2009.12.10 11:52:38 | 000,192,512 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll
MOD - [2009.12.10 11:51:36 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll
MOD - [2009.12.10 11:40:20 | 000,991,232 | ---- | M] () -- C:\Program Files\Mobile Partner\NDISAPI.dll
MOD - [2009.09.19 11:21:06 | 000,139,264 | ---- | M] () -- C:\Program Files\Mobile Partner\NetInfoPlugin.dll
MOD - [2009.06.19 15:10:46 | 000,143,360 | ---- | M] () -- C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll
MOD - [2009.06.19 15:10:22 | 000,159,744 | ---- | M] () -- C:\Program Files\Mobile Partner\SMSPlugin.dll
MOD - [2009.06.18 10:56:10 | 000,032,768 | ---- | M] () -- C:\Program Files\Mobile Partner\NotifyServicePlugin.dll
MOD - [2009.06.18 10:54:14 | 000,057,344 | ---- | M] () -- C:\Program Files\Mobile Partner\ConfigFilePlugin.dll
MOD - [2009.06.18 10:48:24 | 000,090,112 | ---- | M] () -- C:\Program Files\Mobile Partner\DialUpPlugin.dll
MOD - [2009.05.25 13:09:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe
MOD - [2009.05.23 11:02:32 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobile Partner\XCodec.dll
MOD - [2009.05.23 11:02:30 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceOperate.dll
MOD - [2009.05.23 11:02:28 | 000,155,648 | ---- | M] () -- C:\Program Files\Mobile Partner\DetectDev.dll
MOD - [2009.05.23 11:02:24 | 000,557,056 | ---- | M] () -- C:\Program Files\Mobile Partner\atcomm.dll
MOD - [2009.02.12 10:53:02 | 000,040,448 | ---- | M] () -- C:\Program Files\NetDrive\ws_ext.dll
MOD - [2007.08.23 16:39:30 | 000,014,848 | ---- | M] () -- C:\Program Files\Mobile Partner\isaputrace.dll
MOD - [2007.07.31 15:50:04 | 000,090,112 | ---- | M] () -- C:\Program Files\Mobile Partner\FileManager.dll
 
 
========== Services (SafeList) ==========
 
SRV - [2012.10.07 12:48:08 | 000,711,112 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.0.0\ToolbarUpdater.exe -- (vToolbarUpdater13.0.0)
SRV - [2012.09.19 11:29:42 | 001,699,168 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2012.09.13 15:26:52 | 001,006,448 | ---- | M] () [Auto | Running] -- C:\Windows\System32\dmwu.exe -- (WebOptimizer)
SRV - [2012.08.23 15:40:04 | 000,188,760 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\Web Assistant\ExtensionUpdaterService.exe -- (Web Assistant Updater)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.05.13 20:00:08 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.13 20:00:05 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.10.09 15:57:49 | 002,089,472 | ---- | M] (Bdrive Inc.) [Auto | Running] -- C:\Program Files\NetDrive\ndsvc.exe -- (ndsvc)
SRV - [2010.05.08 13:48:36 | 000,229,376 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\DCService.exe -- (DCService.exe)
SRV - [2010.04.29 05:04:12 | 000,069,632 | ---- | M] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) [Auto | Running] -- C:\Windows\System32\PrintCtrl.exe -- (Printer Control)
SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - [2012.10.07 12:48:09 | 000,026,984 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtpx86.sys -- (avgtp)
DRV - [2012.09.19 10:50:50 | 000,010,088 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2012.05.13 20:00:08 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.05.13 20:00:08 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.09.16 16:08:07 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2011.03.25 10:21:12 | 000,049,432 | ---- | M] (MacroData Inc.) [File_System | On_Demand | Stopped] -- C:\Program Files\NetDrive\NDFS.sys -- (ndfs)
DRV - [2010.04.09 15:24:12 | 000,063,616 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2010.03.25 10:08:38 | 000,105,984 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2010.03.20 11:56:04 | 000,101,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2010.03.20 10:28:12 | 000,116,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2009.10.08 16:55:33 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.06.30 09:37:16 | 000,028,552 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\pavboot.sys -- (pavboot)
DRV - [2008.07.29 01:53:46 | 000,919,552 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008.05.02 07:59:40 | 000,122,368 | ---- | M] (Realtek Corporation                                            ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://msi.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bigseekpro.com/lickingdogscreen58/{ED7B955B-6018-4426-9A81-2A6584975D27}
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{7C788BE1-99B0-40CD-B58C-788705E205E2}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=161&systemid=406&sr=0&q={searchTerms}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT3227980
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://msi.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/?pc=AVBR
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.google.de/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://isearch.avg.com/?cid={6F3A6C9B-EBBC-4643-BCE5-1781EE57D853}&mid=6f5268bac3b847d0a364d15756fb0efd-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=de&ds=tt014&pr=sa&d=2012-10-07 12:49:10&v=13.0.0.7&sap=hp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {0cc09160-108c-4759-bab1-5c12c216e005} - No CLSID value found
IE - HKCU\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\DealBulldog Toolbar Toolbar\tbhelper.dll ()
IE - HKCU\..\URLSearchHook: {ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=112542&babsrc=SP_ss&mntrId=5445d1cc000000000000001e101f9843
IE - HKCU\..\SearchScopes\{288575EA-507B-42CB-97BE-ACED08F1998A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
IE - HKCU\..\SearchScopes\{4327FABE-3C22-4689-8DBF-D226CF777FE9}: "URL" = hxxp://www.searchplusnetwork.com/?sp=vit4&q={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADFA_deDE420
IE - HKCU\..\SearchScopes\{7C788BE1-99B0-40CD-B58C-788705E205E2}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = https://isearch.avg.com/search?cid={6F3A6C9B-EBBC-4643-BCE5-1781EE57D853}&mid=6f5268bac3b847d0a364d15756fb0efd-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=de&ds=tt014&pr=sa&d=2012-10-07 12:49:10&v=13.0.0.7&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = hxxp://www.bigseekpro.com/search/browser/lickingdogscreen58/{ED7B955B-6018-4426-9A81-2A6584975D27}?q={searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=161&systemid=406&sr=0&q={searchTerms}
IE - HKCU\..\SearchScopes\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27}: "URL" = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = hxxp://mystart.incredibar.com/mb165/?search={searchTerms}&loc=IB_DS&a=6OyHBdc1Gw&i=26
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\13.0.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2012.09.12 12:24:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\13.0.0.7 [2012.10.07 12:49:31 | 000,000,000 | ---D | M]
 
[2011.07.14 13:58:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\pc\AppData\Roaming\mozilla\Extensions
[2012.07.11 10:56:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
 
========== Chrome  ==========
 
CHR - Extension: No name found = C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\
CHR - Extension: No name found = C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.478_0\
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Browser Companion Helper) - {00cbb66b-1d3b-46d3-9577-323a336acb50} - C:\Program Files\BrowserCompanion\jsloader.dll ( )
O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll ()
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\13.0.0.7\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Browser Companion Helper Verifier) - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files\BrowserCompanion\updatebhoWin32.dll ( )
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files\Searchqu Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc)
O2 - BHO: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\DealBulldog Toolbar Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (DealBulldog Toolbar Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\DealBulldog Toolbar Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\13.0.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (DealBulldog Toolbar Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\DealBulldog Toolbar Toolbar\tbcore3.dll ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Searchqu Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
O4 - HKLM..\Run: [Netdrive] C:\Program Files\NetDrive\netdrive.exe (Bdrive Inc.)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [PrintDisp] C:\Windows\System32\PrintDisp.exe (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
O4 - HKLM..\Run: [ROC_ROC_NT] C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [b1gMail-Utility] C:\Program Files\MailXXL.com Tools\BMUtil.exe ()
O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited)
O4 - Startup: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\pc\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tbhcn.lnk = C:\Users\pc\AppData\Roaming\BrowserCompanion\tbhcn.exe ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 193.189.244.206 193.189.244.225
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{59DDF262-BEC7-46A7-8D06-943CB65610D4}: DhcpNameServer = 193.189.244.206 193.189.244.225
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: NameServer = 132.252.3.10,132.252.1.7
O18 - Protocol\Handler\base64 {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O18 - Protocol\Handler\chrome {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O18 - Protocol\Handler\prox {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\13.0.0\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\pc\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\pc\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O27 - HKLM IFEO\bmutil.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\checkdrive.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\chrome.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\dropbox.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\hpwucli.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\schirmfoto.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\setup.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\tbhcn.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\uninstall.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010.05.08 21:48:36 | 000,126,976 | R--- | M] () - D:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2008.03.10 02:34:52 | 000,000,047 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.10 11:31:07 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\pc\Desktop\OTL.exe
[2012.10.09 05:10:27 | 000,000,000 | -H-D | C] -- C:\Windows\Icons
[2012.10.07 12:50:02 | 000,031,584 | ---- | C] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe
[2012.10.07 12:50:00 | 000,021,344 | ---- | C] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2012.10.07 12:49:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013
[2012.10.07 12:49:08 | 000,026,984 | ---- | C] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2012.10.07 12:47:43 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\TuneUp Software
[2012.10.07 12:47:29 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2013
[2012.10.07 12:46:31 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2012.10.07 12:46:15 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2012.09.18 20:58:26 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\rezepte
[2012.09.12 12:25:02 | 000,000,000 | ---D | C] -- C:\Windows\System32\WNLT
[2012.09.12 12:25:02 | 000,000,000 | ---D | C] -- C:\Windows\System32\ARFC
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.10 11:31:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\pc\Desktop\OTL.exe
[2012.10.10 11:27:05 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.10 11:27:05 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.10 11:22:22 | 000,000,000 | ---- | M] () -- C:\Users\pc\defogger_reenable
[2012.10.10 09:27:27 | 000,000,260 | ---- | M] () -- C:\Windows\tasks\AbelssoftPreloader.job
[2012.10.10 09:27:20 | 000,000,326 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job
[2012.10.10 09:27:03 | 000,271,760 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.10.10 09:27:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.09 09:39:25 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Communicator.job
[2012.10.09 09:39:25 | 000,000,294 | ---- | M] () -- C:\Windows\tasks\WebReg Deskjet F300 series.job
[2012.10.09 04:58:32 | 000,000,270 | ---- | M] () -- C:\Windows\tasks\CheckDriveBackgroundGuard.job
[2012.10.09 04:57:59 | 000,000,234 | ---- | M] () -- C:\Windows\tasks\Schirmfoto.job
[2012.10.07 18:24:56 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.10.07 18:24:56 | 000,001,086 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.10.07 12:49:48 | 000,001,839 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
[2012.10.07 12:49:48 | 000,001,835 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2012.10.07 12:48:09 | 000,026,984 | ---- | M] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2012.09.27 17:53:45 | 000,001,941 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.09.27 11:22:58 | 000,000,193 | ---- | M] () -- C:\Users\pc\Documents\Dokument.rtf
[2012.09.26 11:04:43 | 000,000,786 | ---- | M] () -- C:\Users\Public\Desktop\WashAndGo.lnk
[2012.09.24 22:18:28 | 000,002,174 | ---- | M] () -- C:\Users\pc\Documents\semmelknödel.rtf
[2012.09.23 12:16:20 | 000,001,087 | ---- | M] () -- C:\Users\pc\Desktop\scan.lnk
[2012.09.22 17:44:19 | 000,000,485 | ---- | M] () -- C:\Users\pc\Desktop\°.lnk
[2012.09.19 11:29:46 | 000,031,584 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe
[2012.09.19 11:29:40 | 000,021,344 | ---- | M] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2012.09.13 15:26:52 | 001,006,448 | ---- | M] () -- C:\Windows\System32\dmwu.exe
[2012.09.13 15:24:48 | 000,028,160 | ---- | M] () -- C:\Windows\System32\ImHttpComm.dll
 
========== Files Created - No Company Name ==========
 
[2012.10.10 11:22:22 | 000,000,000 | ---- | C] () -- C:\Users\pc\defogger_reenable
[2012.10.10 09:26:52 | 000,271,760 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.10.07 12:49:48 | 000,001,839 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
[2012.10.07 12:49:48 | 000,001,835 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2012.10.07 12:49:47 | 000,001,847 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013.lnk
[2012.09.26 11:04:43 | 000,000,786 | ---- | C] () -- C:\Users\Public\Desktop\WashAndGo.lnk
[2012.09.24 22:18:28 | 000,002,174 | ---- | C] () -- C:\Users\pc\Documents\semmelknödel.rtf
[2012.09.23 23:10:26 | 000,000,294 | ---- | C] () -- C:\Windows\tasks\WebReg Deskjet F300 series.job
[2012.09.23 12:12:43 | 000,001,087 | ---- | C] () -- C:\Users\pc\Desktop\scan.lnk
[2012.09.22 17:44:19 | 000,000,485 | ---- | C] () -- C:\Users\pc\Desktop\°.lnk
[2012.09.12 12:25:02 | 001,006,448 | ---- | C] () -- C:\Windows\System32\dmwu.exe
[2012.09.12 12:25:02 | 000,028,160 | ---- | C] () -- C:\Windows\System32\ImHttpComm.dll
[2012.07.10 14:48:59 | 000,000,519 | ---- | C] () -- C:\Users\pc\pc - Verknüpfung.lnk
[2012.04.27 18:29:20 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012.03.12 21:21:00 | 000,000,680 | ---- | C] () -- C:\Users\pc\AppData\Local\d3d9caps.dat
[2011.10.29 20:04:04 | 001,391,616 | ---- | C] () -- C:\Windows\System32\ActPDF.dll
[2011.10.29 20:03:43 | 000,691,200 | ---- | C] () -- C:\Windows\System32\PrintLog.exe
[2011.03.13 16:17:06 | 000,000,058 | ---- | C] () -- C:\Users\pc\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
[2011.02.25 15:46:39 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011.02.25 15:46:38 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010.12.31 17:07:07 | 000,164,255 | ---- | C] () -- C:\Windows\hpoins19.dat
[2010.12.31 17:06:48 | 000,026,952 | ---- | C] () -- C:\Windows\hpomdl19.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2011.07.11 19:50:05 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Abelssoft
[2011.07.14 09:12:55 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Avant Downloader
[2012.07.11 22:14:21 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Babylon
[2012.10.09 05:13:23 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\BrowserCompanion
[2011.03.13 16:17:06 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\DonationCoder
[2012.10.09 04:46:09 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Dropbox
[2011.07.14 11:05:34 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\freenet
[2012.09.19 04:44:35 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Image Zone Express
[2012.04.24 18:21:32 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\LibreOffice
[2011.07.14 13:03:56 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Lunascape
[2012.07.01 11:18:14 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\MusicNet
[2011.07.08 11:57:41 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\NetDrive
[2012.07.14 13:35:43 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\OpenCandy
[2012.07.19 18:57:51 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\pdfforge
[2011.11.09 16:23:43 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Printer Info Cache
[2012.09.20 10:21:21 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\QuickScan
[2012.10.07 14:38:51 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\TuneUp Software
[2011.09.21 00:30:12 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Uniblue
[2012.06.10 15:50:39 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Visan
 
========== Purity Check ==========
 
 

< End of report >

--- --- ---
OTL Logfile:
Code:

OTL Extras logfile created on: 10.10.2012 11:36:54 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\pc\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 1,01 Gb Available Physical Memory | 50,71% Memory free
4,22 Gb Paging File | 2,89 Gb Available in Paging File | 68,44% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 63,48 Gb Total Space | 28,42 Gb Free Space | 44,77% Space Free | Partition Type: NTFS
Drive D: | 20,49 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 387,63 Gb Total Space | 361,73 Gb Free Space | 93,32% Space Free | Partition Type: NTFS
Drive H: | 1,84 Gb Total Space | 1,82 Gb Free Space | 99,16% Space Free | Partition Type: FAT
 
Computer Name: PC-PC | User Name: pc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1CBD7845-0288-4425-BA04-97252E840043}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{226CBE0F-9F1C-4B84-A7A8-097A9C328133}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{2F8FE96A-37FC-48FC-A274-7179176F6E5E}" = protocol=6 | dir=in | app=c:\users\pc\appdata\roaming\dropbox\bin\dropbox.exe |
"{30A19E42-C52D-4250-AA47-B5CC06F25C75}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{36DFF524-B990-4A6C-9DD8-A35391AF6005}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{570FE284-895B-425F-98A0-58F43085550D}" = protocol=17 | dir=in | app=c:\program files\netdrive\ndsvc.exe |
"{6B5F328B-B609-45E4-B1F0-10A4A8981D6B}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{6CFC040B-44EC-400C-9A72-FE2A642E6067}" = protocol=6 | dir=in | app=c:\program files\netdrive\ndsvc.exe |
"{7406A79B-7E27-41B4-89EF-A91417F64737}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe |
"{779F3503-F364-4FE7-9CE1-37D85F63A158}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe |
"{79957D25-5AAE-4D80-BCD0-5FF98F001471}" = protocol=17 | dir=in | app=c:\program files\netdrive\ndsvc.exe |
"{9395F2EB-E730-41D8-AE48-44C71B493927}" = protocol=6 | dir=in | app=c:\program files\netdrive\ndsvc.exe |
"{96151931-4520-43E4-A689-52E226F4F082}" = protocol=17 | dir=in | app=c:\users\pc\appdata\roaming\dropbox\bin\dropbox.exe |
"{B18D5A65-90AB-4F84-B3D4-CF4A2BCD1A3C}" = protocol=6 | dir=in | app=c:\program files\searchqu toolbar\datamngr\toolbar\dtuser.exe |
"{B652535E-06B3-4831-A7FC-7D3B0C31336C}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{B6569463-37A6-457C-B2CF-CA6BA5D3D665}" = protocol=17 | dir=in | app=c:\program files\searchqu toolbar\datamngr\toolbar\dtuser.exe |
"{CF8C0B69-02D6-4BF4-8F2D-3E3452DFAECC}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{DC710067-43A4-4852-BEE0-693EEF7CABBF}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{E02E6A6E-55B2-47CC-9DAF-A872D61B3CFD}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F34F597B-25CF-41E3-AB7E-9B2E4155FDA1}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F4CF3062-B85A-47D4-AD86-9AEB657CE2B9}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java(TM) 6 Update 35
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{336D0C35-8A85-403a-B9D2-65C292C39087}_is1" = Web Assistant 2.0.0.478
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{4281435C-AD1D-4C8A-B9C0-3961C11EF142}_is1" = YouTube Song Downloader
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}" = Paint.NET v3.5.10
"{5E6D6161-5509-4f55-9372-1E01792F843A}" = F300_Help
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 4.7.0
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch
"{B83513EC-2E4D-4621-816D-4CCF397BE702}_is1" = CheckDrive
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}" = TuneUp Utilities 2013
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C911A0C2-2236-3164-AA47-F2566C01AE5E}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DDD5104F-1C44-49EB-9E6B-29EC5D27658B}" = HP Update
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E55B3271-7CA8-4D0C-AE06-69A24856E997}_is1" = Uniblue RegistryBooster
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1568757-E564-4cb5-8980-9333119A4384}" = F300
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F2AF3E5D-9697-485C-A5AC-E2B9468C446A}" = Safari
"{F4811919-F252-4B25-9AB2-8859A85810B5}" = TuneUp Utilities Language Pack (de-DE)
"{F6AC5364-2FB7-437a-811A-D645F22AA6AC}" = F300Trb
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"AbAlarm_is1" = AbAlarm
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG Secure Search" = AVG Security Toolbar
"Avira AntiVir Desktop" = Avira Free Antivirus
"BrowserCompanion" = BrowserCompanion
"CCleaner" = CCleaner
"DealBulldog Toolbar Toolbar" = DealBulldog Toolbar Toolbar
"Google Chrome" = Google Chrome
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Photo Creations" = HP Photo Creations
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.0.4 (Basic)
"Lunascape6" = Lunascape6 (All Users)
"MailXXL.com" = MailXXL.com Tools
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mobile Partner" = Mobile Partner
"MyKeyFinder_is1" = MyKeyFinder
"NetDrive" = NetDrive
"Schirmfoto_is1" = Schirmfoto
"Searchqu Toolbar" = Searchqu Toolbar
"TuneUp Utilities 2013" = TuneUp Utilities 2013
"WashAndGo_is1" = WashAndGo
"Wincore MediaBar" = Wincore MediaBar
"WNLT" = Web Optimizer
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 10.10.2012 03:36:16 | Computer Name = pc-PC | Source = VSS | ID = 40
Description =
 
Error - 10.10.2012 03:36:16 | Computer Name = pc-PC | Source = VSS | ID = 12292
Description =
 
Error - 10.10.2012 03:36:17 | Computer Name = pc-PC | Source = VSS | ID = 40
Description =
 
Error - 10.10.2012 03:36:17 | Computer Name = pc-PC | Source = VSS | ID = 12292
Description =
 
Error - 10.10.2012 03:36:17 | Computer Name = pc-PC | Source = VSS | ID = 40
Description =
 
Error - 10.10.2012 03:36:17 | Computer Name = pc-PC | Source = VSS | ID = 12292
Description =
 
Error - 10.10.2012 03:36:17 | Computer Name = pc-PC | Source = System Restore | ID = 8193
Description =
 
[ System Events ]
Error - 10.10.2012 03:43:56 | Computer Name = pc-PC | Source = DCOM | ID = 10005
Description =
 
Error - 10.10.2012 03:43:57 | Computer Name = pc-PC | Source = Service Control Manager | ID = 7001
Description =
 
 
< End of report >

--- --- ---

Ich habe noch eingangs vergessen zu erwähnen daß es manchmal Probleme gibt Text einzugeben.Entweder habe ich die Buchstaben doppelt oder gar nicht.Häufig kommt es vor "das Programm kann die Webseite nicht anzeigen " oder dass die Navigation zu der Webseite immer wieder abgebrochen wird. Heute zum Beispiel hier mit dem Trojanerboard......habe es x- Mal versuchen müssen bis es endlich ging.:killpc:

Hallo,
habe nun Gmer durchlaufen gelassen und hier ist das Ergebnis:

GMER Logfile:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-10-10 13:23:25
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 WDC_WD5000AAVS-00G9B1 rev.05.04C05
Running: n2pze84q.exe; Driver: C:\Users\pc\AppData\Local\Temp\pgtdapob.sys


---- System - GMER 1.0.15 ----

SSDT            8D2083CE                      ZwCreateSection
SSDT            8D2083D8                      ZwRequestWaitReplyPort
SSDT            8D2083D3                      ZwSetContextThread
SSDT            8D2083DD                      ZwSetSecurityObject
SSDT            8D2083E2                      ZwSystemDebugControl
SSDT            8D20836F                      ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text          ntkrnlpa.exe!KeSetEvent + 215  81CE18D8 4 Bytes  [CE, 83, 20, 8D] {INTO ; AND DWORD [EAX], -0x73}
.text          ntkrnlpa.exe!KeSetEvent + 539  81CE1BFC 4 Bytes  [D8, 83, 20, 8D]
.text          ntkrnlpa.exe!KeSetEvent + 56D  81CE1C30 4 Bytes  [D3, 83, 20, 8D]
.text          ntkrnlpa.exe!KeSetEvent + 5D1  81CE1C94 4 Bytes  [DD, 83, 20, 8D]
.text          ntkrnlpa.exe!KeSetEvent + 619  81CE1CDC 4 Bytes  [E2, 83, 20, 8D]
.text          ...                           

---- Devices - GMER 1.0.15 ----

AttachedDevice  \FileSystem\fastfat \Fat      fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

--- --- ---

:stirn: ich Dussel hatte den Avira Scanner dabei nicht ausgeschaltet....
muss ich jetzt Gmer nochmal machen oder geht das auch so?

Hi,
wollte mir eben 7-ZiP runterladen, ging aber leider nicht , der Zugriff auf den Zielordner wurde verweigert,habe dann von Avira die Meldung bekommen 7-ZiP wurde als Malware erkannt. Soll ich Avira abschalten und es dann noch einmal versuchen? Kann ja eigentlich keine Malware sein wenn Ihr das empfehlt.:wtf:

schrauber 17.10.2012 11:07

Hi,

Sorry für die Verspätung. Brauchst Du noch Hilfe?

mädchen 17.10.2012 18:33

Hallo,
ja, habe das Problem noch nicht lösen können.Hat sich noch keiner erbarmt mich schlau zu machen.

schrauber 18.10.2012 06:05

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Suche.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.



  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Löschen.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.



Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!
Downloade dir bitte Combofix vom folgenden Downloadspiegel

Link 1


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

mädchen 18.10.2012 20:27

Hi Schrauber,
danke dir für deine Mühe. Es hat leider mit dem download von Combofix nicht so hingehauen, Lunascape hat den download geblockt und ich musste den IE nehmen. Da habe ich dann beim speichern irgendwas falsch gemacht....schäm. Blöd wenn man doof ist!
Hier die Ergebnisse mit denen du hoffentlich was anfangen kannst ......damit ich das nicht nochmal machen muss, hat nämlich elend lange gedauert bis Combofix mal fertig war!
# AdwCleaner v2.005 - Datei am 18/10/2012 um 19:46:52 erstellt
# Aktualisiert am 14/10/2012 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : pc - PC-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\pc\Desktop\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****

Gefunden : Web Assistant Updater

***** [Dateien / Ordner] *****

Datei Gefunden : C:\user.js
Ordner Gefunden : C:\Program Files\AVG Secure Search
Ordner Gefunden : C:\Program Files\BrowserCompanion
Ordner Gefunden : C:\Program Files\Common Files\AVG Secure Search
Ordner Gefunden : C:\Program Files\Conduit
Ordner Gefunden : C:\Program Files\Searchqu Toolbar
Ordner Gefunden : C:\Program Files\Web Assistant
Ordner Gefunden : C:\ProgramData\AVG Secure Search
Ordner Gefunden : C:\ProgramData\Babylon
Ordner Gefunden : C:\ProgramData\IBUpdaterService
Ordner Gefunden : C:\ProgramData\Tarma Installer
Ordner Gefunden : C:\Users\pc\AppData\Local\AVG Secure Search
Ordner Gefunden : C:\Users\pc\AppData\Local\Babylon
Ordner Gefunden : C:\Users\pc\AppData\Local\Conduit
Ordner Gefunden : C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Ordner Gefunden : C:\Users\pc\AppData\Local\Ilivid Player
Ordner Gefunden : C:\Users\pc\AppData\LocalLow\AVG Secure Search
Ordner Gefunden : C:\Users\pc\AppData\LocalLow\bbrs_002.tb
Ordner Gefunden : C:\Users\pc\AppData\LocalLow\Conduit
Ordner Gefunden : C:\Users\pc\AppData\LocalLow\incredibar.com
Ordner Gefunden : C:\Users\pc\AppData\LocalLow\Searchqutoolbar
Ordner Gefunden : C:\Users\pc\AppData\LocalLow\Toolbar4
Ordner Gefunden : C:\Users\pc\AppData\Roaming\Babylon
Ordner Gefunden : C:\Users\pc\AppData\Roaming\BrowserCompanion
Ordner Gefunden : C:\Users\pc\AppData\Roaming\OpenCandy
Ordner Gefunden : C:\Users\pc\AppData\Roaming\pdfforge

***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gefunden : HKCU\Software\AVG Secure Search
Schlüssel Gefunden : HKCU\Software\DataMngr
Schlüssel Gefunden : HKCU\Software\DataMngr_Toolbar
Schlüssel Gefunden : HKCU\Software\IGearSettings
Schlüssel Gefunden : HKCU\Software\IM
Schlüssel Gefunden : HKCU\Software\ImInstaller
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{4327FABE-3C22-4689-8DBF-D226CF777FE9}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BrowserCompanion
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\incredibar
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Searchqu Toolbar
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wincore MediaBar
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403a-B9D2-65C292C39087}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{338B4DFE-2E2C-4338-9E41-E176D497299E}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D0F4A166-B8D4-48b8-9D63-80849FE137CB}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9639E4A-801B-4843-AEE3-03D9DA199E77}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}
Schlüssel Gefunden : HKCU\Software\SMTTB2009
Schlüssel Gefunden : HKCU\Software\Softonic
Schlüssel Gefunden : HKCU\Software\Somoto Toolbar
Schlüssel Gefunden : HKLM\Software\AVG Secure Search
Schlüssel Gefunden : HKLM\Software\Babylon
Schlüssel Gefunden : HKLM\Software\BabylonToolbar
Schlüssel Gefunden : HKLM\Software\bProtector
Schlüssel Gefunden : HKLM\Software\BrowserCompanion
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{20EDC024-43C5-423E-B7F5-FD93523E0D9F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{373ED12D-B306-43AC-9485-A7C5133DC34C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{ED6535E7-F778-48A5-A060-549D30024511}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\tdataprotocol.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\updatebho.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\wit4ie.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{338B4DFE-2E2C-4338-9E41-E176D497299E}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{5ACE96C0-C70A-4A4D-AF14-2E7B869345E1}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{9D717F81-9148-4F12-8568-69135F087DB0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\base64
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\chrome
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\prox
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\SMTTB2009.IEToolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\SMTTB2009.IEToolbar.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\SMTTB2009.SMTTB2009
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\SMTTB2009.SMTTB2009.3
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbRequest
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbTask
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\tdataprotocol.CTData
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\tdataprotocol.CTData.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT3196716
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT3227982
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar3.SMTTB2009
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar3.SMTTB2009.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{5B4144E1-B61D-495A-9A50-CD1A95D86D15}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{830B56CB-FD22-44AA-9887-7898F4F4158D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{841D5A49-E48D-413C-9C28-EB3D9081D705}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{8830DDF0-3042-404D-A62C-384A85E34833}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{955B782E-CDC8-4CEE-B6F6-AD7D541A8D8A}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{EC4085F2-8DB3-45A6-AD0B-CA289F3C5D7E}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\updatebho.TimerBHO
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\updatebho.TimerBHO.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\wit4ie.WitBHO
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\wit4ie.WitBHO.2
Schlüssel Gefunden : HKLM\Software\Conduit
Schlüssel Gefunden : HKLM\Software\DataMngr
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Schlüssel Gefunden : HKLM\Software\Iminent
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011501160}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4F12-8568-69135F087DB0}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011501160}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserCompanion
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wincore MediaBar
Schlüssel Gefunden : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Schlüssel Gefunden : HKLM\Software\SearchquMediabarTb
Schlüssel Gefunden : HKLM\Software\Tarma Installer
Schlüssel Gefunden : HKLM\Software\Web Assistant
Schlüssel Gefunden : HKU\S-1-5-21-1085966804-1864869585-2381995735-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gefunden : HKU\S-1-5-21-1085966804-1864869585-2381995735-1000\Software\Microsoft\Internet Explorer\SearchScopes\{4327FABE-3C22-4689-8DBF-D226CF777FE9}
Schlüssel Gefunden : HKU\S-1-5-21-1085966804-1864869585-2381995735-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKU\S-1-5-21-1085966804-1864869585-2381995735-1000\Software\Microsoft\Internet Explorer\SearchScopes\{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E}
Schlüssel Gefunden : HKU\S-1-5-21-1085966804-1864869585-2381995735-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gefunden : HKU\S-1-5-21-1085966804-1864869585-2381995735-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{338B4DFE-2E2C-4338-9E41-E176D497299E}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{CA3EB689-8F09-4026-AA10-B9534C691CE0}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{338B4DFE-2E2C-4338-9E41-E176D497299E}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{99079A25-328F-4BD4-BE04-00955ACAA0A7}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [DataMngr]
Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]
Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.bigseekpro.com/lickingdogscreen58/{ED7B955B-6018-4426-9A81-2A6584975D27}
[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxps://isearch.avg.com/?cid={6F3A6C9B-EBBC-4643-BCE5-1781EE57D853}&mid=6f5268bac3b847d0a364d15756fb0efd-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=de&ds=tt014&pr=sa&d=2012-10-07 12:49:10&v=13.0.0.7&sap=hp
[HKCU\Software\Microsoft\Internet Explorer\Main - bProtector Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT3227980
[HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://www.bigseekpro.com/lickingdogscreen58/{ED7B955B-6018-4426-9A81-2A6584975D27}?s_src=newtab

-\\ Google Chrome v [Version kann nicht ermittelt werden]

Datei : C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Preferences

Gefunden [l.1] : icon_url ={"backup":{"_signature":"NkNAWbkAlnekYlW2ZGSs76bQI+PNXA9oZGa/wqoxxCg=","_version":4,"extensions":{"ids":["ahfgeienlihckogmohjhadlkjgocpleb","bodddioamolcibagionmmobehnbhiakf","dlnembnfbcpjnepmfjmngjenhhajpdfd"]},"homepage":true,"homepage_is_newtabpage":false,"session":{"restore_on_startup":4,"urls_to_restore_on_startup":["hxxps://isearch.avg.com/?cid={6F3A6C9B-EBBC-4643-BCE5-1781EE57D853}&mid=6f5268bac3b847d0a364d15756fb0efd-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=de&ds=tt014&pr=sa&d=2012-10-07 12:49:10&v=13.0.0.7&sap=hp"]}},"browser":{"last_known_google_url":"hxxp://www.google.de/","last_prompted_google_url":"hxxp://www.google.de/","window_placement":{"bottom":824,"left":10,"maximized":false,"right":1060,"top":10,"work_area_bottom":834,"work_area_left":0,"work_area_right":1152, "work_area_top":0}},"countryid_at_install":17477,"default_apps_install_state":2,"default_search_provider":{"enabled":true,"encodings":"UTF-8","hxxp://www.google.com/favicon.ico","id":"2","instant_url":"{google:baseURL}webhp?{google:RLZ}sourceid=chrome-instant&ie={inputEncoding}{google:instantEnabledParameter}{searchTerms}","keyword":"google.de","name":"Google","prepopulate_id":"1","search_url":"{goo gle:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourcei d=chrome&ie={inputEncoding}","suggest_url":"{google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms }"},"distribution":{"create_all_shortcuts":true,"do_not_launch_chrome":true,"import_history":false,"import_search_engine":false,"make_chrome_default": true,"ping_delay":10,"show_welcome_page":true,"skip_first_run_ui":false,"verbose_logging":false},"dns_prefetching":{"host_referral_list": [ 2 ]},"sync_promo":{"show_on_first_run_allowed":false}}

*************************

AdwCleaner[R1].txt - [24846 octets] - [18/10/2012 19:46:52]

########## EOF - C:\AdwCleaner[R1].txt - [24907 octets] ##########


# AdwCleaner v2.005 - Datei am 18/10/2012 um 19:57:40 erstellt
# Aktualisiert am 14/10/2012 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : pc - PC-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\pc\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****

Gestoppt & Gelöscht : Web Assistant Updater

***** [Dateien / Ordner] *****

Datei Gelöscht : C:\user.js
Gelöscht mit Neustart : C:\Program Files\Common Files\AVG Secure Search
Ordner Gelöscht : C:\Program Files\AVG Secure Search
Ordner Gelöscht : C:\Program Files\BrowserCompanion
Ordner Gelöscht : C:\Program Files\Conduit
Ordner Gelöscht : C:\Program Files\Searchqu Toolbar
Ordner Gelöscht : C:\Program Files\Web Assistant
Ordner Gelöscht : C:\ProgramData\AVG Secure Search
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\IBUpdaterService
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\Users\pc\AppData\Local\AVG Secure Search
Ordner Gelöscht : C:\Users\pc\AppData\Local\Babylon
Ordner Gelöscht : C:\Users\pc\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Ordner Gelöscht : C:\Users\pc\AppData\Local\Ilivid Player
Ordner Gelöscht : C:\Users\pc\AppData\LocalLow\AVG Secure Search
Ordner Gelöscht : C:\Users\pc\AppData\LocalLow\bbrs_002.tb
Ordner Gelöscht : C:\Users\pc\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\pc\AppData\LocalLow\incredibar.com
Ordner Gelöscht : C:\Users\pc\AppData\LocalLow\Searchqutoolbar
Ordner Gelöscht : C:\Users\pc\AppData\LocalLow\Toolbar4
Ordner Gelöscht : C:\Users\pc\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\pc\AppData\Roaming\BrowserCompanion
Ordner Gelöscht : C:\Users\pc\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\pc\AppData\Roaming\pdfforge

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\AVG Secure Search
Schlüssel Gelöscht : HKCU\Software\DataMngr
Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\IGearSettings
Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\ImInstaller
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{4327FABE-3C22-4689-8DBF-D226CF777FE9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BrowserCompanion
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\incredibar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Searchqu Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wincore MediaBar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403a-B9D2-65C292C39087}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{338B4DFE-2E2C-4338-9E41-E176D497299E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D0F4A166-B8D4-48b8-9D63-80849FE137CB}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9639E4A-801B-4843-AEE3-03D9DA199E77}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}
Schlüssel Gelöscht : HKCU\Software\SMTTB2009
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\Somoto Toolbar
Schlüssel Gelöscht : HKLM\Software\AVG Secure Search
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\BabylonToolbar
Schlüssel Gelöscht : HKLM\Software\bProtector
Schlüssel Gelöscht : HKLM\Software\BrowserCompanion
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{20EDC024-43C5-423E-B7F5-FD93523E0D9F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{373ED12D-B306-43AC-9485-A7C5133DC34C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{ED6535E7-F778-48A5-A060-549D30024511}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\tdataprotocol.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\updatebho.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\wit4ie.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{338B4DFE-2E2C-4338-9E41-E176D497299E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5ACE96C0-C70A-4A4D-AF14-2E7B869345E1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9D717F81-9148-4F12-8568-69135F087DB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\base64
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\chrome
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\prox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SMTTB2009.IEToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SMTTB2009.IEToolbar.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SMTTB2009.SMTTB2009
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SMTTB2009.SMTTB2009.3
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbRequest
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbTask
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\tdataprotocol.CTData
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\tdataprotocol.CTData.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3196716
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3227982
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.SMTTB2009
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.SMTTB2009.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{5B4144E1-B61D-495A-9A50-CD1A95D86D15}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{830B56CB-FD22-44AA-9887-7898F4F4158D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{841D5A49-E48D-413C-9C28-EB3D9081D705}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{8830DDF0-3042-404D-A62C-384A85E34833}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{955B782E-CDC8-4CEE-B6F6-AD7D541A8D8A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EC4085F2-8DB3-45A6-AD0B-CA289F3C5D7E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\updatebho.TimerBHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\updatebho.TimerBHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wit4ie.WitBHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wit4ie.WitBHO.2
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Schlüssel Gelöscht : HKLM\Software\Iminent
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011501160}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4F12-8568-69135F087DB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011501160}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserCompanion
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wincore MediaBar
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Schlüssel Gelöscht : HKLM\Software\SearchquMediabarTb
Schlüssel Gelöscht : HKLM\Software\Tarma Installer
Schlüssel Gelöscht : HKLM\Software\Web Assistant
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{338B4DFE-2E2C-4338-9E41-E176D497299E}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{CA3EB689-8F09-4026-AA10-B9534C691CE0}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{338B4DFE-2E2C-4338-9E41-E176D497299E}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{99079A25-328F-4BD4-BE04-00955ACAA0A7}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [DataMngr]
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.bigseekpro.com/lickingdogscreen58/{ED7B955B-6018-4426-9A81-2A6584975D27} --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxps://isearch.avg.com/?cid={6F3A6C9B-EBBC-4643-BCE5-1781EE57D853}&mid=6f5268bac3b847d0a364d15756fb0efd-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=de&ds=tt014&pr=sa&d=2012-10-07 12:49:10&v=13.0.0.7&sap=hp --> hxxp://www.google.com
Gelöscht : [HKCU\Software\Microsoft\Internet Explorer\Main - bProtector Start Page]
Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://www.bigseekpro.com/lickingdogscreen58/{ED7B955B-6018-4426-9A81-2A6584975D27}?s_src=newtab --> hxxp://www.google.com

-\\ Google Chrome v [Version kann nicht ermittelt werden]

Datei : C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Preferences

Gelöscht [l.1] : icon_url ={"backup":{"_signature":"NkNAWbkAlnekYlW2ZGSs76bQI+PNXA9oZGa/wqoxxCg=","_version":4,"extensions":{"ids":["ahfgeienlihckogmohjhadlkjgocpleb","bodddioamolcibagionmmobehnbhiakf","dlnembnfbcpjnepmfjmngjenhhajpdfd"]},"homepage":true,"homepage_is_newtabpage":false,"session":{"restore_on_startup":4,"urls_to_restore_on_startup":["hxxps://isearch.avg.com/?cid={6F3A6C9B-EBBC-4643-BCE5-1781EE57D853}&mid=6f5268bac3b847d0a364d15756fb0efd-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=de&ds=tt014&pr=sa&d=2012-10-07 12:49:10&v=13.0.0.7&sap=hp"]}},"browser":{"last_known_google_url":"hxxp://www.google.de/","last_prompted_google_url":"hxxp://www.google.de/","window_placement":{"bottom":824,"left":10,"maximized":false,"right":1060,"top":10,"work_area_bottom":834,"work_area_left":0,"work_area_right":1152, "work_area_top":0}},"countryid_at_install":17477,"default_apps_install_state":2,"default_search_provider":{"enabled":true,"encodings":"UTF-8","hxxp://www.google.com/favicon.ico","id":"2","instant_url":"{google:baseURL}webhp?{google:RLZ}sourceid=chrome-instant&ie={inputEncoding}{google:instantEnabledParameter}{searchTerms}","keyword":"google.de","name":"Google","prepopulate_id":"1","search_url":"{goo gle:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourcei d=chrome&ie={inputEncoding}","suggest_url":"{google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms }"},"distribution":{"create_all_shortcuts":true,"do_not_launch_chrome":true,"import_history":false,"import_search_engine":false,"make_chrome_default": true,"ping_delay":10,"show_welcome_page":true,"skip_first_run_ui":false,"verbose_logging":false},"dns_prefetching":{"host_referral_list": [ 2 ]},"sync_promo":{"show_on_first_run_allowed":false}}

*************************

AdwCleaner[R1].txt - [24977 octets] - [18/10/2012 19:46:52]
AdwCleaner[S1].txt - [24014 octets] - [18/10/2012 19:57:40]

########## EOF - C:\AdwCleaner[S1].txt - [24075 octets] ##########


Combofix Logfile:
Code:

ComboFix 12-10-18.03 - pc 18.10.2012  20:18:37.1.4 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.2039.1257 [GMT 2:00]
ausgeführt von:: c:\users\pc\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-09-18 bis 2012-10-18  ))))))))))))))))))))))))))))))
.
.
2012-10-18 18:57 . 2012-10-18 18:57        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-10-18 12:11 . 2012-10-18 12:11        --------        d-----w-        c:\users\pc\AppData\Roaming\Avira
2012-10-18 12:05 . 2012-10-01 15:14        134184        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2012-10-18 12:05 . 2012-09-24 07:58        36552        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2012-10-18 12:05 . 2012-09-13 08:58        83792        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2012-10-18 12:05 . 2012-10-18 12:05        --------        d-----w-        c:\program files\Avira
2012-10-17 17:27 . 2012-10-12 05:56        6918632        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{A2173B36-4D7D-4EFF-8CE5-2935373F78D6}\mpengine.dll
2012-10-10 12:27 . 2012-06-02 00:02        985088        ----a-w-        c:\windows\system32\crypt32.dll
2012-10-10 12:27 . 2012-06-02 00:02        98304        ----a-w-        c:\windows\system32\cryptnet.dll
2012-10-10 12:27 . 2012-06-02 00:02        133120        ----a-w-        c:\windows\system32\cryptsvc.dll
2012-10-10 12:27 . 2012-08-24 15:53        172544        ----a-w-        c:\windows\system32\wintrust.dll
2012-10-10 12:27 . 2012-09-13 13:28        2048        ----a-w-        c:\windows\system32\tzres.dll
2012-10-10 12:27 . 2012-08-29 11:27        3602816        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2012-10-10 12:27 . 2012-08-29 11:27        3550080        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-10-09 03:10 . 2012-10-09 03:11        --------        d--h--w-        c:\windows\Icons
2012-10-07 10:50 . 2012-09-19 09:29        31584        ----a-w-        c:\windows\system32\TURegOpt.exe
2012-10-07 10:50 . 2012-09-19 09:29        21344        ----a-w-        c:\windows\system32\authuitu.dll
2012-10-07 10:49 . 2012-10-07 10:48        26984        ----a-w-        c:\windows\system32\drivers\avgtpx86.sys
2012-10-07 10:47 . 2012-10-07 12:38        --------        d-----w-        c:\users\pc\AppData\Roaming\TuneUp Software
2012-10-07 10:47 . 2012-10-07 10:49        --------        d-----w-        c:\program files\TuneUp Utilities 2013
2012-10-07 10:46 . 2012-10-07 10:47        --------        d-----w-        c:\programdata\TuneUp Software
2012-10-07 10:46 . 2012-10-07 10:57        --------        d-sh--w-        c:\programdata\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-13 13:26 . 2012-09-12 10:25        1006448        ----a-w-        c:\windows\system32\dmwu.exe
2012-09-13 13:24 . 2012-09-12 10:25        28160        ----a-w-        c:\windows\system32\ImHttpComm.dll
2012-08-28 18:24 . 2012-06-25 16:20        477168        ----a-w-        c:\windows\system32\npdeployJava1.dll
2012-08-28 18:24 . 2011-07-02 14:36        473072        ----a-w-        c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12        94208        ----a-w-        c:\users\pc\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12        94208        ----a-w-        c:\users\pc\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12        94208        ----a-w-        c:\users\pc\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"b1gMail-Utility"="c:\program files\MailXXL.com Tools\BMUtil.exe" [2011-07-08 403968]
"RegistryBooster"="c:\program files\Uniblue\RegistryBooster\launcher.exe" [2012-07-08 68000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-25 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-25 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-25 133656]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-07 6139904]
"Netdrive"="c:\program files\NetDrive\netdrive.exe" [2011-10-09 2572800]
"PrintDisp"="c:\windows\system32\PrintDisp.exe" [2011-08-08 828416]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"PDFPrint"="c:\program files\PDF24\pdf24.exe" [2012-09-06 162408]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-09-25 386336]
.
c:\users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\pc\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
tbhcn.lnk - c:\users\pc\AppData\Roaming\BrowserCompanion\tbhcn.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-21 02:25        125952        ----a-w-        c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
.
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt        REG_MULTI_SZ          hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2012-10-18 c:\windows\Tasks\AbelssoftPreloader.job
- c:\program files\WashAndGo\AbelssoftPreloader.exe [2012-09-01 08:02]
.
2012-10-09 c:\windows\Tasks\CheckDriveBackgroundGuard.job
- c:\program files\CheckDrive\CheckDriveBackgroundGuard.exe [2012-08-17 09:18]
.
2012-10-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-25 13:47]
.
2012-10-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-25 13:47]
.
2012-10-09 c:\windows\Tasks\HP Photo Creations Communicator.job
- c:\programdata\HP Photo Creations\MessageCheck.exe [2011-03-02 10:11]
.
2012-10-18 c:\windows\Tasks\RegistryBooster.job
- c:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2011-12-06 12:39]
.
2012-10-09 c:\windows\Tasks\Schirmfoto.job
- c:\program files\Schirmfoto\schirmfoto.exe [2011-10-08 23:07]
.
2012-10-09 c:\windows\Tasks\WebReg Deskjet F300 series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2006-12-10 20:36]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 193.189.244.225 193.189.244.206
TCP: Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: NameServer = 132.252.3.10,132.252.1.7
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - (no file)
URLSearchHooks-{0cc09160-108c-4759-bab1-5c12c216e005} - (no file)
WebBrowser-{EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} - (no file)
HKLM-Run-vProt - c:\program files\AVG Secure Search\vprot.exe
HKLM-Run-ROC_ROC_NT - c:\program files\AVG Secure Search\ROC_ROC_NT.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
.
.
**************************************************************************
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien:
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(2764)
c:\users\pc\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\programdata\DatacardService\DCService.exe
c:\program files\NetDrive\ndsvc.exe
c:\windows\system32\PrintCtrl.exe
c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\13.0.0\ToolbarUpdater.exe
c:\windows\system32\dmwu.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
c:\windows\system32\conime.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-10-18  21:10:27 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-10-18 19:09
.
Vor Suchlauf: 5 Verzeichnis(se), 29.403.770.880 Bytes frei
Nach Suchlauf: 9 Verzeichnis(se), 29.581.627.392 Bytes frei
.
- - End Of File - - B9E74550A59D11413F09CAD0BFA2B83C

--- --- ---

Schönen Abend noch und lieben Gruß
mädchen

schrauber 18.10.2012 20:34

Hallo mädchen (das wollt ich immer schonmal schreiben :D)

Poste mal bitte ein frisches OTL log und sag mir wie die Kiste läuft :)

mädchen 18.10.2012 21:01

Hi,
ein ganz frisches OTL :OTL Logfile:
Code:

OTL logfile created on: 18.10.2012 21:37:44 - Run 2
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\pc\Desktop\trojaner board
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 1,27 Gb Available Physical Memory | 63,78% Memory free
4,22 Gb Paging File | 3,17 Gb Available in Paging File | 75,08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 63,48 Gb Total Space | 27,59 Gb Free Space | 43,46% Space Free | Partition Type: NTFS
Drive D: | 20,49 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 387,63 Gb Total Space | 361,73 Gb Free Space | 93,32% Space Free | Partition Type: NTFS
Drive H: | 1,84 Gb Total Space | 1,82 Gb Free Space | 99,16% Space Free | Partition Type: FAT
 
Computer Name: PC-PC | User Name: pc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.10.10 11:31:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\pc\Desktop\trojaner board\OTL.exe
PRC - [2012.10.07 12:48:08 | 000,711,112 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.0.0\ToolbarUpdater.exe
PRC - [2012.09.25 11:00:45 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012.09.25 10:52:56 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.09.25 10:52:48 | 000,386,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.09.19 19:20:40 | 000,079,136 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.09.19 11:29:44 | 001,869,152 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
PRC - [2012.09.19 11:29:42 | 001,699,168 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
PRC - [2012.09.13 15:26:52 | 001,006,448 | ---- | M] () -- C:\Windows\System32\dmwu.exe
PRC - [2012.09.06 13:12:20 | 000,162,408 | ---- | M] (Geek Software GmbH) -- C:\Program Files\PDF24\pdf24.exe
PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.07.08 14:39:22 | 000,056,720 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
PRC - [2012.07.08 14:39:22 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
PRC - [2011.10.09 15:57:49 | 002,089,472 | ---- | M] (Bdrive Inc.) -- C:\Program Files\NetDrive\ndsvc.exe
PRC - [2011.10.09 15:57:36 | 002,572,800 | ---- | M] (Bdrive Inc.) -- C:\Program Files\NetDrive\netdrive.exe
PRC - [2011.08.08 13:31:46 | 000,828,416 | ---- | M] (ActMask Co.,Ltd - hxxp://www.all2pdf.com) -- C:\Windows\System32\PrintDisp.exe
PRC - [2011.07.20 03:44:22 | 000,099,688 | ---- | M] (Lunascape Co., LTD.) -- C:\Program Files\Lunascape\Lunascape6\Luna.exe
PRC - [2010.05.08 13:48:36 | 000,229,376 | ---- | M] () -- C:\ProgramData\DatacardService\DCService.exe
PRC - [2010.05.08 13:48:26 | 000,241,664 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe
PRC - [2010.04.29 05:04:12 | 000,069,632 | ---- | M] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) -- C:\Windows\System32\PrintCtrl.exe
PRC - [2009.05.25 13:09:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008.05.07 10:19:26 | 006,139,904 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.08.28 20:11:44 | 000,014,320 | ---- | M] () -- C:\Program Files\Java\jre6\bin\jp2native.dll
MOD - [2012.08.28 20:11:34 | 000,108,528 | ---- | M] () -- C:\Program Files\Java\jre6\bin\jp2iexp.dll
MOD - [2012.07.08 14:39:22 | 000,114,064 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\InstallerExtensions.dll
MOD - [2012.07.08 14:39:22 | 000,018,832 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\cwebpage.dll
MOD - [2012.07.08 14:39:16 | 000,136,592 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\locale\de\de.dll
MOD - [2011.03.22 10:08:22 | 000,138,752 | ---- | M] () -- C:\Program Files\NetDrive\libexpat.dll
MOD - [2009.12.10 11:52:38 | 000,192,512 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll
MOD - [2009.12.10 11:51:36 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll
MOD - [2009.12.10 11:40:20 | 000,991,232 | ---- | M] () -- C:\Program Files\Mobile Partner\NDISAPI.dll
MOD - [2009.09.19 11:21:06 | 000,139,264 | ---- | M] () -- C:\Program Files\Mobile Partner\NetInfoPlugin.dll
MOD - [2009.06.19 15:10:46 | 000,143,360 | ---- | M] () -- C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll
MOD - [2009.06.19 15:10:22 | 000,159,744 | ---- | M] () -- C:\Program Files\Mobile Partner\SMSPlugin.dll
MOD - [2009.06.18 10:56:10 | 000,032,768 | ---- | M] () -- C:\Program Files\Mobile Partner\NotifyServicePlugin.dll
MOD - [2009.06.18 10:54:14 | 000,057,344 | ---- | M] () -- C:\Program Files\Mobile Partner\ConfigFilePlugin.dll
MOD - [2009.06.18 10:48:24 | 000,090,112 | ---- | M] () -- C:\Program Files\Mobile Partner\DialUpPlugin.dll
MOD - [2009.05.25 13:09:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe
MOD - [2009.05.23 11:02:32 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobile Partner\XCodec.dll
MOD - [2009.05.23 11:02:30 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceOperate.dll
MOD - [2009.05.23 11:02:28 | 000,155,648 | ---- | M] () -- C:\Program Files\Mobile Partner\DetectDev.dll
MOD - [2009.05.23 11:02:24 | 000,557,056 | ---- | M] () -- C:\Program Files\Mobile Partner\atcomm.dll
MOD - [2009.02.12 10:53:02 | 000,040,448 | ---- | M] () -- C:\Program Files\NetDrive\ws_ext.dll
MOD - [2007.08.23 16:39:30 | 000,014,848 | ---- | M] () -- C:\Program Files\Mobile Partner\isaputrace.dll
MOD - [2007.07.31 15:50:04 | 000,090,112 | ---- | M] () -- C:\Program Files\Mobile Partner\FileManager.dll
 
 
========== Services (SafeList) ==========
 
SRV - [2012.10.07 12:48:08 | 000,711,112 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.0.0\ToolbarUpdater.exe -- (vToolbarUpdater13.0.0)
SRV - [2012.09.25 11:00:45 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.09.25 10:52:56 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.09.19 11:29:42 | 001,699,168 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2012.09.13 15:26:52 | 001,006,448 | ---- | M] () [Auto | Running] -- C:\Windows\System32\dmwu.exe -- (WebOptimizer)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.10.09 15:57:49 | 002,089,472 | ---- | M] (Bdrive Inc.) [Auto | Running] -- C:\Program Files\NetDrive\ndsvc.exe -- (ndsvc)
SRV - [2010.05.08 13:48:36 | 000,229,376 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\DCService.exe -- (DCService.exe)
SRV - [2010.04.29 05:04:12 | 000,069,632 | ---- | M] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) [Auto | Running] -- C:\Windows\System32\PrintCtrl.exe -- (Printer Control)
SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2012.10.07 12:48:09 | 000,026,984 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtpx86.sys -- (avgtp)
DRV - [2012.10.01 17:14:23 | 000,134,184 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.09.24 09:58:11 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2012.09.19 10:50:50 | 000,010,088 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2012.09.13 10:58:17 | 000,083,792 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.08.27 15:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2011.03.25 10:21:12 | 000,049,432 | ---- | M] (MacroData Inc.) [File_System | On_Demand | Stopped] -- C:\Program Files\NetDrive\NDFS.sys -- (ndfs)
DRV - [2010.04.09 15:24:12 | 000,063,616 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2010.03.25 10:08:38 | 000,105,984 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2010.03.20 11:56:04 | 000,101,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2010.03.20 10:28:12 | 000,116,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2009.06.30 09:37:16 | 000,028,552 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\pavboot.sys -- (pavboot)
DRV - [2008.07.29 01:53:46 | 000,919,552 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008.05.02 07:59:40 | 000,122,368 | ---- | M] (Realtek Corporation                                            ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{7C788BE1-99B0-40CD-B58C-788705E205E2}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {288575EA-507B-42CB-97BE-ACED08F1998A}
IE - HKCU\..\SearchScopes\{288575EA-507B-42CB-97BE-ACED08F1998A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADFA_deDE420
IE - HKCU\..\SearchScopes\{7C788BE1-99B0-40CD-B58C-788705E205E2}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
IE - HKCU\..\SearchScopes\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27}: "URL" = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
 
[2011.07.14 13:58:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\pc\AppData\Roaming\mozilla\Extensions
[2012.07.11 10:56:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
 
========== Chrome  ==========
 
CHR - Extension: No name found = C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Netdrive] C:\Program Files\NetDrive\netdrive.exe (Bdrive Inc.)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [PrintDisp] C:\Windows\System32\PrintDisp.exe (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [b1gMail-Utility] C:\Program Files\MailXXL.com Tools\BMUtil.exe ()
O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited)
O4 - Startup: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\pc\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tbhcn.lnk =  File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab (Bitdefender QuickScan Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} hxxp://acs.pandasoftware.com/activescan/pro/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 193.189.244.225 193.189.244.206
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{59DDF262-BEC7-46A7-8D06-943CB65610D4}: DhcpNameServer = 193.189.244.225 193.189.244.206
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: NameServer = 132.252.3.10,132.252.1.7
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\pc\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\pc\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010.05.08 21:48:36 | 000,126,976 | R--- | M] () - D:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2008.03.10 02:34:52 | 000,000,047 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.18 21:10:31 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.10.18 21:10:31 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\temp
[2012.10.18 21:05:12 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.10.18 20:15:33 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.10.18 20:15:33 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.10.18 20:15:33 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.10.18 20:15:15 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.10.18 20:14:54 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012.10.18 14:11:48 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Avira
[2012.10.18 14:05:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.10.18 14:05:46 | 000,134,184 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2012.10.18 14:05:46 | 000,083,792 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2012.10.18 14:05:46 | 000,036,552 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.10.18 14:05:40 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2012.10.11 16:56:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24
[2012.10.10 14:50:01 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\trojaner board
[2012.10.10 14:27:39 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2012.10.10 14:27:33 | 003,602,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012.10.10 14:27:32 | 003,550,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2012.10.09 05:10:27 | 000,000,000 | -H-D | C] -- C:\Windows\Icons
[2012.10.07 12:50:02 | 000,031,584 | ---- | C] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe
[2012.10.07 12:50:00 | 000,021,344 | ---- | C] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2012.10.07 12:49:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013
[2012.10.07 12:49:08 | 000,026,984 | ---- | C] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2012.10.07 12:47:43 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\TuneUp Software
[2012.10.07 12:47:29 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2013
[2012.10.07 12:46:31 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2012.10.07 12:46:15 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2012.09.23 04:15:46 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012.09.23 04:15:44 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012.09.23 04:15:44 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012.09.23 04:15:44 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012.09.23 04:15:44 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012.09.23 04:15:41 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012.09.23 04:15:41 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012.09.23 04:15:37 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012.09.21 09:45:06 | 000,157,680 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2012.09.21 09:45:06 | 000,149,488 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2012.09.21 09:45:06 | 000,149,488 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.18 21:15:30 | 000,000,260 | ---- | M] () -- C:\Windows\tasks\AbelssoftPreloader.job
[2012.10.18 21:15:24 | 000,000,326 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job
[2012.10.18 21:15:23 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.18 21:15:23 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.18 21:15:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.18 20:12:40 | 000,000,541 | ---- | M] () -- C:\Users\pc\Desktop\ComboFix - Verknüpfung.lnk
[2012.10.18 19:46:38 | 000,538,941 | ---- | M] () -- C:\Users\pc\Desktop\adwcleaner.exe
[2012.10.18 14:05:59 | 000,001,817 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.10.13 18:36:56 | 000,010,240 | ---- | M] () -- C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.10.13 12:30:09 | 000,572,634 | ---- | M] () -- C:\Users\pc\Desktop\stui.jpg
[2012.10.13 09:10:12 | 000,271,760 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.10.11 16:56:57 | 000,001,608 | ---- | M] () -- C:\Users\Public\Desktop\PDF24 Fax.lnk
[2012.10.11 16:56:56 | 000,001,623 | ---- | M] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk
[2012.10.11 13:01:56 | 000,006,562 | ---- | M] () -- C:\Users\pc\Desktop\vvvvc.eml
[2012.10.10 11:22:22 | 000,000,000 | ---- | M] () -- C:\Users\pc\defogger_reenable
[2012.10.09 09:39:25 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Communicator.job
[2012.10.09 09:39:25 | 000,000,294 | ---- | M] () -- C:\Windows\tasks\WebReg Deskjet F300 series.job
[2012.10.09 04:58:32 | 000,000,270 | ---- | M] () -- C:\Windows\tasks\CheckDriveBackgroundGuard.job
[2012.10.09 04:57:59 | 000,000,234 | ---- | M] () -- C:\Windows\tasks\Schirmfoto.job
[2012.10.07 18:24:56 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.10.07 18:24:56 | 000,001,086 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.10.07 12:49:48 | 000,001,839 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
[2012.10.07 12:49:48 | 000,001,835 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2012.10.07 12:48:09 | 000,026,984 | ---- | M] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2012.10.01 17:14:23 | 000,134,184 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2012.09.27 17:53:45 | 000,001,941 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.09.27 11:22:58 | 000,000,193 | ---- | M] () -- C:\Users\pc\Documents\Dokument.rtf
[2012.09.26 11:04:43 | 000,000,786 | ---- | M] () -- C:\Users\Public\Desktop\WashAndGo.lnk
[2012.09.24 22:18:28 | 000,002,174 | ---- | M] () -- C:\Users\pc\Documents\semmelknödel.rtf
[2012.09.24 09:58:11 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.09.23 12:16:20 | 000,001,087 | ---- | M] () -- C:\Users\pc\Desktop\scan.lnk
[2012.09.22 17:44:19 | 000,000,485 | ---- | M] () -- C:\Users\pc\Desktop\°.lnk
[2012.09.19 11:29:46 | 000,031,584 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe
[2012.09.19 11:29:40 | 000,021,344 | ---- | M] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
 
========== Files Created - No Company Name ==========
 
[2012.10.18 20:15:33 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.10.18 20:15:33 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.10.18 20:15:33 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.10.18 20:15:33 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.10.18 20:15:33 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.10.18 20:12:40 | 000,000,541 | ---- | C] () -- C:\Users\pc\Desktop\ComboFix - Verknüpfung.lnk
[2012.10.18 19:46:07 | 000,538,941 | ---- | C] () -- C:\Users\pc\Desktop\adwcleaner.exe
[2012.10.18 14:05:59 | 000,001,817 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.10.13 12:26:19 | 000,010,240 | ---- | C] () -- C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.10.13 09:09:54 | 000,271,760 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.10.11 16:56:57 | 000,001,608 | ---- | C] () -- C:\Users\Public\Desktop\PDF24 Fax.lnk
[2012.10.11 16:56:56 | 000,001,623 | ---- | C] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk
[2012.10.11 13:01:42 | 000,006,562 | ---- | C] () -- C:\Users\pc\Desktop\vvvvc.eml
[2012.10.10 11:22:22 | 000,000,000 | ---- | C] () -- C:\Users\pc\defogger_reenable
[2012.10.07 12:49:48 | 000,001,839 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
[2012.10.07 12:49:48 | 000,001,835 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2012.10.07 12:49:47 | 000,001,847 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013.lnk
[2012.09.26 11:04:43 | 000,000,786 | ---- | C] () -- C:\Users\Public\Desktop\WashAndGo.lnk
[2012.09.24 22:18:28 | 000,002,174 | ---- | C] () -- C:\Users\pc\Documents\semmelknödel.rtf
[2012.09.23 23:10:26 | 000,000,294 | ---- | C] () -- C:\Windows\tasks\WebReg Deskjet F300 series.job
[2012.09.23 12:12:43 | 000,001,087 | ---- | C] () -- C:\Users\pc\Desktop\scan.lnk
[2012.09.22 17:44:19 | 000,000,485 | ---- | C] () -- C:\Users\pc\Desktop\°.lnk
[2012.09.12 12:25:02 | 001,006,448 | ---- | C] () -- C:\Windows\System32\dmwu.exe
[2012.09.12 12:25:02 | 000,028,160 | ---- | C] () -- C:\Windows\System32\ImHttpComm.dll
[2012.07.10 14:48:59 | 000,000,519 | ---- | C] () -- C:\Users\pc\pc - Verknüpfung.lnk
[2012.04.27 18:29:20 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012.03.12 21:21:00 | 000,000,680 | ---- | C] () -- C:\Users\pc\AppData\Local\d3d9caps.dat
[2011.10.29 20:04:04 | 001,391,616 | ---- | C] () -- C:\Windows\System32\ActPDF.dll
[2011.10.29 20:03:43 | 000,691,200 | ---- | C] () -- C:\Windows\System32\PrintLog.exe
[2011.03.13 16:17:06 | 000,000,058 | ---- | C] () -- C:\Users\pc\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
[2011.02.25 15:46:39 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011.02.25 15:46:38 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010.12.31 17:07:07 | 000,164,255 | ---- | C] () -- C:\Windows\hpoins19.dat
[2010.12.31 17:06:48 | 000,026,952 | ---- | C] () -- C:\Windows\hpomdl19.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 925 bytes -> C:\Users\pc\Desktop\vvvvc.eml:OECustomProperty

< End of report >

--- --- ---


Sag mal wie schnell wertest du denn diese ganzen Informationen aus????

Ich werde den Rechner gleich neu anwerfen und mal schauen wie es jetzt so ist und dann melde ich mich nochmal.Was ich aber jetzt schon sagen kann : zwischen neues OTL machen und hier antworten hat er sich dreimal aufgehängt.


Bis später!
mädchen

mädchen 18.10.2012 21:49

Hallo Schrauber,
bin verblüfft. Bisher hat sich der Pc jedes Mal beim ersten Klick nach dem Starten aufgehängt - und jetzt nicht mehr. Das hast du aber schön gemacht!
Immer wenn ich was gegoogelt habe und dann was anklickte blieb er hängen, das klappt jetzt auch wieder . Das Umschalten zwischen den einzelenen Webseiten funktioniert auch wieder ohne dass man dabei Socken stricken kann.Habe zwar noch nicht alles ausprobiert ( you tube noch nicht) aber freu mich schon über die Erfolge, das geht jetzt alles fixer.Ich hatte ein Problem mit dem Drucker, es hat oft lange gedauert bis der Druckauftrag dann auch ausgeführt wurde. Hab eben einen Test gemacht, ging gut.
Leider besteht aber immer noch das Ding mit der Texteingabe, da fehlen manchmal Buchstaben oder ich habe sie doppelt. Aber ich will nicht meckern......das hast du wirklich schön hingekriegt. :bussi:

Liebe Grüße vom mädchen

Hi Schrauber,
da habe ich mich wohl zu früh gefreut....schade.
Nach Eingabe des Benutzerkennwortes stotterte der Pc wieder und hing auch wieder beim ersten Klick. :killpc:

schrauber 19.10.2012 16:26

Zitat:

Sag mal wie schnell wertest du denn diese ganzen Informationen aus????
joah, schnell halt :D


Malwarebytes' Anti-Malware
  • Lies dir die Entfernungsanleitung durch und lass alles entfernen was gefunden wurde:
(nach dem scannen auf den Button klicken und Funde löschen lassen!)







ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Öffne OTL, bei Extra Registrierung auf Benutze Safe List stellen und Scan Button drücken, poste beide Logfiles :).

mädchen 19.10.2012 18:58

Hi Schrauber,

puuuh. Ob ich das alles hinkriege?
Heute mache ich das nicht mehr, bin eh nicht mehr aufnahmefähig. Morgen.
Bis dann!


mädchen

schrauber 19.10.2012 19:09

Sicher bekommste das hin :)

mädchen 20.10.2012 08:30

Guten Morgen!

Irgendwas stimmt da mit dem Link für den anti-malware Download nicht.:kaffee:
Habe den Download für die neueste Version angeklickt und hatte dann ... zipper ... installiert. Aber kann man vielleicht auch mal gebrauchen.
Dann habe ich es nochmal versucht....und da hatte ich ...download accelerator ...installiert.
Eh ich mir jetzt nach und nach noch mehr Sachen runterlade die ich gar nicht haben will frage ich dich erstmal wo ich denn nun den download für malwarebytes herbekomme.
Übrigens kann ich wieder störungsfrei Musikvideos bei you tube ansehen.

Liebe Grüße
mädchen

schrauber 20.10.2012 14:50

Versuchs hier:

Malwarebytes : Free anti-malware download

mädchen 20.10.2012 16:46

Hallo,
danke, aber hatte Mbam dann doch noch beim Pony gefunden. Lach. Man sollte auch erst mal richtig hinschauen bevor man klickt...
Habe das anti-malware Programm auch schon durchlaufen lassen, gefunden wurde nichts.
Die anderen Sachen mache ich heute noch.
Ach ja, ich weiß nicht was "Skriptblocking und ähnliches" ist, ob ich sowas habe und wenn ja, wo ich den Knopf zum ausschalten finde . :wtf:
Hm, ich verstehe eben nichts vom Pc...aber jetzt weiß ich jedenfalls schon mal was logfiles sind.

Grüße vom mädchen

schrauber 20.10.2012 18:45

Hast Du nicht, also kannste den Scan einfach laufen lassen :)

mädchen 22.10.2012 08:40

Hallo schrauber,

es klappt nicht mit dem Eset Scanner. Es wird gewartet..... und gewartet..... und gewartet....., tut sich auch nach 10 Minuten nichts.
Und ich habe leider so gut wie alle Probleme die ich am Anfang hatte jetzt auch wieder.

Gruß
mädchen

schrauber 22.10.2012 08:42

Dann poste mal bitte ein frisches OTL logfile.

mädchen 22.10.2012 09:06

OTL Logfile:
Code:

OTL logfile created on: 22.10.2012 09:48:48 - Run 3
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\pc\Desktop\trojaner board
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 1,16 Gb Available Physical Memory | 58,39% Memory free
4,22 Gb Paging File | 3,08 Gb Available in Paging File | 73,11% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 63,48 Gb Total Space | 27,36 Gb Free Space | 43,10% Space Free | Partition Type: NTFS
Drive D: | 20,49 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 387,63 Gb Total Space | 362,61 Gb Free Space | 93,54% Space Free | Partition Type: NTFS
Drive H: | 1,84 Gb Total Space | 1,82 Gb Free Space | 99,16% Space Free | Partition Type: FAT
 
Computer Name: PC-PC | User Name: pc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.10.10 11:31:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\pc\Desktop\trojaner board\OTL.exe
PRC - [2012.10.07 12:48:08 | 000,711,112 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.0.0\ToolbarUpdater.exe
PRC - [2012.09.29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.09.25 11:00:45 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012.09.25 10:52:56 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.09.25 10:52:48 | 000,386,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.09.19 19:20:40 | 000,079,136 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.09.19 11:29:44 | 001,869,152 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
PRC - [2012.09.19 11:29:42 | 001,699,168 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
PRC - [2012.09.13 15:26:52 | 001,006,448 | ---- | M] () -- C:\Windows\System32\dmwu.exe
PRC - [2012.09.06 13:12:20 | 000,162,408 | ---- | M] (Geek Software GmbH) -- C:\Program Files\PDF24\pdf24.exe
PRC - [2012.08.15 19:08:34 | 000,231,768 | ---- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe
PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.05.29 15:50:04 | 000,115,032 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\SweetIM.exe
PRC - [2011.10.09 15:57:49 | 002,089,472 | ---- | M] (Bdrive Inc.) -- C:\Program Files\NetDrive\ndsvc.exe
PRC - [2011.10.09 15:57:36 | 002,572,800 | ---- | M] (Bdrive Inc.) -- C:\Program Files\NetDrive\netdrive.exe
PRC - [2011.08.08 13:31:46 | 000,828,416 | ---- | M] (ActMask Co.,Ltd - hxxp://www.all2pdf.com) -- C:\Windows\System32\PrintDisp.exe
PRC - [2011.07.20 03:44:22 | 000,099,688 | ---- | M] (Lunascape Co., LTD.) -- C:\Program Files\Lunascape\Lunascape6\Luna.exe
PRC - [2010.05.08 13:48:36 | 000,229,376 | ---- | M] () -- C:\ProgramData\DatacardService\DCService.exe
PRC - [2010.05.08 13:48:26 | 000,241,664 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe
PRC - [2010.04.29 05:04:12 | 000,069,632 | ---- | M] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) -- C:\Windows\System32\PrintCtrl.exe
PRC - [2009.05.25 13:09:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008.05.07 10:19:26 | 006,139,904 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.08.28 20:11:44 | 000,014,320 | ---- | M] () -- C:\Program Files\Java\jre6\bin\jp2native.dll
MOD - [2012.08.28 20:11:34 | 000,108,528 | ---- | M] () -- C:\Program Files\Java\jre6\bin\jp2iexp.dll
MOD - [2011.03.22 10:08:22 | 000,138,752 | ---- | M] () -- C:\Program Files\NetDrive\libexpat.dll
MOD - [2009.12.10 11:52:38 | 000,192,512 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll
MOD - [2009.12.10 11:51:36 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll
MOD - [2009.12.10 11:40:20 | 000,991,232 | ---- | M] () -- C:\Program Files\Mobile Partner\NDISAPI.dll
MOD - [2009.09.19 11:21:06 | 000,139,264 | ---- | M] () -- C:\Program Files\Mobile Partner\NetInfoPlugin.dll
MOD - [2009.06.19 15:10:46 | 000,143,360 | ---- | M] () -- C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll
MOD - [2009.06.19 15:10:22 | 000,159,744 | ---- | M] () -- C:\Program Files\Mobile Partner\SMSPlugin.dll
MOD - [2009.06.18 10:56:10 | 000,032,768 | ---- | M] () -- C:\Program Files\Mobile Partner\NotifyServicePlugin.dll
MOD - [2009.06.18 10:54:14 | 000,057,344 | ---- | M] () -- C:\Program Files\Mobile Partner\ConfigFilePlugin.dll
MOD - [2009.06.18 10:48:24 | 000,090,112 | ---- | M] () -- C:\Program Files\Mobile Partner\DialUpPlugin.dll
MOD - [2009.05.25 13:09:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe
MOD - [2009.05.23 11:02:32 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobile Partner\XCodec.dll
MOD - [2009.05.23 11:02:30 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceOperate.dll
MOD - [2009.05.23 11:02:28 | 000,155,648 | ---- | M] () -- C:\Program Files\Mobile Partner\DetectDev.dll
MOD - [2009.05.23 11:02:24 | 000,557,056 | ---- | M] () -- C:\Program Files\Mobile Partner\atcomm.dll
MOD - [2009.02.12 10:53:02 | 000,040,448 | ---- | M] () -- C:\Program Files\NetDrive\ws_ext.dll
MOD - [2007.08.23 16:39:30 | 000,014,848 | ---- | M] () -- C:\Program Files\Mobile Partner\isaputrace.dll
MOD - [2007.07.31 15:50:04 | 000,090,112 | ---- | M] () -- C:\Program Files\Mobile Partner\FileManager.dll
 
 
========== Services (SafeList) ==========
 
SRV - [2012.10.19 10:38:38 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.10.07 12:48:08 | 000,711,112 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.0.0\ToolbarUpdater.exe -- (vToolbarUpdater13.0.0)
SRV - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.09.25 11:00:45 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.09.25 10:52:56 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.09.19 11:29:42 | 001,699,168 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2012.09.13 15:26:52 | 001,006,448 | ---- | M] () [Auto | Running] -- C:\Windows\System32\dmwu.exe -- (WebOptimizer)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.10.09 15:57:49 | 002,089,472 | ---- | M] (Bdrive Inc.) [Auto | Running] -- C:\Program Files\NetDrive\ndsvc.exe -- (ndsvc)
SRV - [2010.05.08 13:48:36 | 000,229,376 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\DCService.exe -- (DCService.exe)
SRV - [2010.04.29 05:04:12 | 000,069,632 | ---- | M] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) [Auto | Running] -- C:\Windows\System32\PrintCtrl.exe -- (Printer Control)
SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (catchme)
DRV - [2012.10.07 12:48:09 | 000,026,984 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtpx86.sys -- (avgtp)
DRV - [2012.10.01 17:14:23 | 000,134,184 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.09.29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.09.24 09:58:11 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2012.09.19 10:50:50 | 000,010,088 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2012.09.13 10:58:17 | 000,083,792 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.08.27 15:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2011.03.25 10:21:12 | 000,049,432 | ---- | M] (MacroData Inc.) [File_System | On_Demand | Stopped] -- C:\Program Files\NetDrive\NDFS.sys -- (ndfs)
DRV - [2010.04.09 15:24:12 | 000,063,616 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2010.03.25 10:08:38 | 000,105,984 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2010.03.20 11:56:04 | 000,101,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2010.03.20 10:28:12 | 000,116,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2009.06.30 09:37:16 | 000,028,552 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\pavboot.sys -- (pavboot)
DRV - [2008.07.29 01:53:46 | 000,919,552 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008.05.02 07:59:40 | 000,122,368 | ---- | M] (Realtek Corporation                                            ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.sweetim.com/?crg=3.1010006.10031&barid={8EAAC8C9-1A84-11E2-AEA6-001E101F3315}
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{7C788BE1-99B0-40CD-B58C-788705E205E2}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010006.10031&barid={8EAAC8C9-1A84-11E2-AEA6-001E101F3315}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.sweetim.com/?crg=3.1010006.10031&barid={8EAAC8C9-1A84-11E2-AEA6-001E101F3315}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {288575EA-507B-42CB-97BE-ACED08F1998A}
IE - HKCU\..\SearchScopes\{288575EA-507B-42CB-97BE-ACED08F1998A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADFA_deDE420
IE - HKCU\..\SearchScopes\{7C788BE1-99B0-40CD-B58C-788705E205E2}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
IE - HKCU\..\SearchScopes\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27}: "URL" = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010006.10031&barid={8EAAC8C9-1A84-11E2-AEA6-001E101F3315}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
 
[2011.07.14 13:58:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\pc\AppData\Roaming\mozilla\Extensions
[2012.07.11 10:56:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
 
========== Chrome  ==========
 
CHR - Extension: No name found = C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\
CHR - Extension: No name found = C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Netdrive] C:\Program Files\NetDrive\netdrive.exe (Bdrive Inc.)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [PrintDisp] C:\Windows\System32\PrintDisp.exe (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [Sweetpacks Communicator] C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe (SweetIM Technologies Ltd.)
O4 - HKCU..\Run: [b1gMail-Utility] C:\Program Files\MailXXL.com Tools\BMUtil.exe ()
O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited)
O4 - Startup: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\pc\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab (Bitdefender QuickScan Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} hxxp://acs.pandasoftware.com/activescan/pro/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 193.189.244.225 193.189.244.206
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{59DDF262-BEC7-46A7-8D06-943CB65610D4}: DhcpNameServer = 193.189.244.225 193.189.244.206
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: NameServer = 132.252.3.10,132.252.1.7
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O27 - HKLM IFEO\registrybooster.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\unins000.exe: Debugger - C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe (TuneUp Software)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010.05.08 21:48:36 | 000,126,976 | R--- | M] () - D:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2008.03.10 02:34:52 | 000,000,047 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.20 09:53:11 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Malwarebytes
[2012.10.20 09:53:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.10.20 09:53:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.10.20 09:53:04 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.10.20 09:53:04 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.10.20 09:12:52 | 000,000,000 | ---D | C] -- C:\Program Files\DownloadManager
[2012.10.20 09:05:38 | 000,000,000 | ---D | C] -- C:\ProgramData\SweetIM
[2012.10.20 09:05:38 | 000,000,000 | ---D | C] -- C:\Program Files\SweetIM
[2012.10.19 09:54:21 | 000,696,760 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.10.18 21:10:31 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.10.18 21:10:31 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\temp
[2012.10.18 21:05:12 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.10.18 20:15:33 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.10.18 20:15:33 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.10.18 20:15:33 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.10.18 20:15:15 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.10.18 20:14:54 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012.10.18 14:11:48 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Avira
[2012.10.18 14:05:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.10.18 14:05:46 | 000,134,184 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2012.10.18 14:05:46 | 000,083,792 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2012.10.18 14:05:46 | 000,036,552 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.10.18 14:05:40 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2012.10.11 16:56:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24
[2012.10.10 14:50:01 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\trojaner board
[2012.10.10 14:27:39 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2012.10.10 14:27:33 | 003,602,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012.10.10 14:27:32 | 003,550,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2012.10.09 05:10:27 | 000,000,000 | -H-D | C] -- C:\Windows\Icons
[2012.10.07 12:50:02 | 000,031,584 | ---- | C] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe
[2012.10.07 12:50:00 | 000,021,344 | ---- | C] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2012.10.07 12:49:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013
[2012.10.07 12:49:08 | 000,026,984 | ---- | C] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2012.10.07 12:47:43 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\TuneUp Software
[2012.10.07 12:47:29 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2013
[2012.10.07 12:46:31 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2012.10.07 12:46:15 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2012.09.23 04:15:46 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012.09.23 04:15:44 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012.09.23 04:15:44 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012.09.23 04:15:44 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012.09.23 04:15:44 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012.09.23 04:15:41 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012.09.23 04:15:41 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012.09.23 04:15:37 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.22 09:38:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.10.22 08:58:10 | 000,000,260 | ---- | M] () -- C:\Windows\tasks\AbelssoftPreloader.job
[2012.10.22 08:56:00 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.22 08:56:00 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.22 08:55:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.21 19:00:39 | 000,271,760 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.10.20 09:16:39 | 000,001,828 | ---- | M] () -- C:\Users\pc\Desktop\JDownloader.lnk
[2012.10.20 09:05:25 | 000,000,231 | ---- | M] () -- C:\Users\pc\Desktop\Search the Web.url
[2012.10.20 09:05:25 | 000,000,225 | ---- | M] () -- C:\Users\pc\Desktop\SweetPcFix.url
[2012.10.20 08:45:10 | 000,000,258 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job
[2012.10.19 10:38:37 | 000,696,760 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.10.19 10:38:37 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012.10.18 14:05:59 | 000,001,817 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.10.13 12:30:09 | 000,572,634 | ---- | M] () -- C:\Users\pc\Desktop\stui.jpg
[2012.10.11 16:56:57 | 000,001,608 | ---- | M] () -- C:\Users\Public\Desktop\PDF24 Fax.lnk
[2012.10.11 16:56:56 | 000,001,623 | ---- | M] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk
[2012.10.11 13:01:56 | 000,006,562 | ---- | M] () -- C:\Users\pc\Desktop\vvvvc.eml
[2012.10.10 11:22:22 | 000,000,000 | ---- | M] () -- C:\Users\pc\defogger_reenable
[2012.10.09 09:39:25 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Communicator.job
[2012.10.09 09:39:25 | 000,000,294 | ---- | M] () -- C:\Windows\tasks\WebReg Deskjet F300 series.job
[2012.10.09 04:58:32 | 000,000,270 | ---- | M] () -- C:\Windows\tasks\CheckDriveBackgroundGuard.job
[2012.10.09 04:57:59 | 000,000,234 | ---- | M] () -- C:\Windows\tasks\Schirmfoto.job
[2012.10.07 18:24:56 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.10.07 18:24:56 | 000,001,086 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.10.07 12:49:48 | 000,001,839 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
[2012.10.07 12:49:48 | 000,001,835 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2012.10.07 12:48:09 | 000,026,984 | ---- | M] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2012.10.01 17:14:23 | 000,134,184 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2012.09.29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.27 17:53:45 | 000,001,941 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.09.27 11:22:58 | 000,000,193 | ---- | M] () -- C:\Users\pc\Documents\Dokument.rtf
[2012.09.26 11:04:43 | 000,000,786 | ---- | M] () -- C:\Users\Public\Desktop\WashAndGo.lnk
[2012.09.24 22:18:28 | 000,002,174 | ---- | M] () -- C:\Users\pc\Documents\semmelknödel.rtf
[2012.09.24 09:58:11 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.09.23 12:16:20 | 000,001,087 | ---- | M] () -- C:\Users\pc\Desktop\scan.lnk
[2012.09.22 17:44:19 | 000,000,485 | ---- | M] () -- C:\Users\pc\Desktop\°.lnk
 
========== Files Created - No Company Name ==========
 
[2012.10.21 19:00:23 | 000,271,760 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.10.20 09:16:39 | 000,001,828 | ---- | C] () -- C:\Users\pc\Desktop\JDownloader.lnk
[2012.10.20 09:16:31 | 000,001,792 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2012.10.20 09:16:31 | 000,001,736 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Uninstaller.lnk
[2012.10.20 09:16:31 | 000,001,715 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2012.10.20 09:05:25 | 000,000,231 | ---- | C] () -- C:\Users\pc\Desktop\Search the Web.url
[2012.10.20 09:05:25 | 000,000,225 | ---- | C] () -- C:\Users\pc\Desktop\SweetPcFix.url
[2012.10.19 09:54:24 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.10.18 20:15:33 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.10.18 20:15:33 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.10.18 20:15:33 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.10.18 20:15:33 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.10.18 20:15:33 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.10.18 14:05:59 | 000,001,817 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.10.11 16:56:57 | 000,001,608 | ---- | C] () -- C:\Users\Public\Desktop\PDF24 Fax.lnk
[2012.10.11 16:56:56 | 000,001,623 | ---- | C] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk
[2012.10.11 13:01:42 | 000,006,562 | ---- | C] () -- C:\Users\pc\Desktop\vvvvc.eml
[2012.10.10 11:22:22 | 000,000,000 | ---- | C] () -- C:\Users\pc\defogger_reenable
[2012.10.07 12:49:48 | 000,001,839 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
[2012.10.07 12:49:48 | 000,001,835 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2012.10.07 12:49:47 | 000,001,847 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013.lnk
[2012.09.26 11:04:43 | 000,000,786 | ---- | C] () -- C:\Users\Public\Desktop\WashAndGo.lnk
[2012.09.24 22:18:28 | 000,002,174 | ---- | C] () -- C:\Users\pc\Documents\semmelknödel.rtf
[2012.09.23 23:10:26 | 000,000,294 | ---- | C] () -- C:\Windows\tasks\WebReg Deskjet F300 series.job
[2012.09.23 12:12:43 | 000,001,087 | ---- | C] () -- C:\Users\pc\Desktop\scan.lnk
[2012.09.22 17:44:19 | 000,000,485 | ---- | C] () -- C:\Users\pc\Desktop\°.lnk
[2012.09.12 12:25:02 | 001,006,448 | ---- | C] () -- C:\Windows\System32\dmwu.exe
[2012.09.12 12:25:02 | 000,028,160 | ---- | C] () -- C:\Windows\System32\ImHttpComm.dll
[2012.07.10 14:48:59 | 000,000,519 | ---- | C] () -- C:\Users\pc\pc - Verknüpfung.lnk
[2012.04.27 18:29:20 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012.03.12 21:21:00 | 000,000,680 | ---- | C] () -- C:\Users\pc\AppData\Local\d3d9caps.dat
[2011.10.29 20:04:04 | 001,391,616 | ---- | C] () -- C:\Windows\System32\ActPDF.dll
[2011.10.29 20:03:43 | 000,691,200 | ---- | C] () -- C:\Windows\System32\PrintLog.exe
[2011.03.13 16:17:06 | 000,000,058 | ---- | C] () -- C:\Users\pc\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
[2011.02.25 15:46:39 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011.02.25 15:46:38 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010.12.31 17:07:07 | 000,164,255 | ---- | C] () -- C:\Windows\hpoins19.dat
[2010.12.31 17:06:48 | 000,026,952 | ---- | C] () -- C:\Windows\hpomdl19.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 925 bytes -> C:\Users\pc\Desktop\vvvvc.eml:OECustomProperty

< End of report >

--- --- ---

schrauber 22.10.2012 09:43

Da wären noch ein paar Einträge, die raus müssen, aber zuerst kümmern wir uns mal um das hängenbleiben.


ProcessExplorer als Ersatz für den Windows Taskmanager installieren

Lade Dir den Process Explorer als Ersatz für den Taskmanager herunter und installiere ihn, hier findest Du eine Anleitung. Das ist ein wesentlich leistungsfähigerer Ersatz für den Windows-Taskmanager. Im Menü unter "Options" kannst Du den ProcessExplorer dauerhaft als Ersatz für den Taskmanager einrichten (Replace Taskmanager). Das ist sehr empfehlenswert, weil der ProcessExplorer erheblich mehr Funktionen als der Taskmanager hat. Wenn Du diese Einstellung gemacht hast, öffnet sich mit der Tastenkombination STRG + ALT + Entf. nicht mehr der Taskmanager, sondern der ProcessExplorer. Das kann jederzeit durch Abhaken dieser Einstellung wieder rückgängig gemacht werden.

Was wir jetzt konkret brauchen: In jeder Zeile steht ein Prozess, ein paar der Zeilen sind keine richtigen Prozesse, sondern nur Pseudoprozesse für die Tätigkeit des Windos-Kernels. Im Menü View => Select Columns wird ein Dialog geöffnet, in dem Du auswählen kannst, welche Spalten mit Informationen zu den Prozessen angezeigt werden sollen. In dem gehe in das Register "Process Performance" und stelle sicher, dass dort "CPU Usage" angehakt ist, "CPU History" wäre ebenfalls sinnvoll. Unter "CPU Usage" wird der aktuelle Wert der Prozessorauslastung für jeden Prozess angezeigt (im Tabellentitel steht nur kurz "CPU"), "CPU History" blendet für jeden Prozess ein Diagramm ein, das eine Kurve mit der Prozessorauslastung für die letzte Zeit anzeigt.

Damit sollte es Dir möglich sein, zu identifizieren, welcher Prozess Deine CPU in Trab hält. Mache einen Doppelklick auf den Prozess. Du kannst von dem ganzen auch einen Screenshot machen und ihn als Anhang mit Deiner Antwort hochladen (auf "Erweitert" unter dem Textfeld klicken und über "Anhänge verwalten" auf Deinem Rechner suchen lassen und über "Hochladen" anhängen).

mädchen 22.10.2012 12:04

Boah, Wurm drin!
Unter Anleitung ist die Seite nicht mehr verfügbar.
Beim Process Explorer kann die Webseite nicht angezeigt werden.
:killpc:

Grüße mädchen

schrauber 22.10.2012 12:12

Versuch mal das hier :)

Process Explorer

mädchen 22.10.2012 12:54

Liste der Anhänge anzeigen (Anzahl: 2)
Au weia,
ich weiß weder was eine CPU ist noch wie man einen screenshot macht. Aber jetzt habe ich das Vista snipping tool kennengelernt ! Hoffentlich ist das so richtig. Mehr kann ich jetzt leider nicht machen, habe gleich einen Termin.
Melde mich heute nachmittag wieder.LG

mädchen

schrauber 22.10.2012 13:04

LAss das Tool mal offen udn schau in dem Moment, wo der PC hängt, ob irgend ein Prozess extrem viel CPU-Auslastung verursacht.

mädchen 22.10.2012 15:34

Armer schrauber,
du hast es nicht leicht mit mir! Ich habe das mit dem Doppelklick auf den Prozess übersehen. :stirn:
Habe eben einen Prozess doppelgeklickt und hatte dann ein Fenster mit einigen Schaltflächen...........oh Gott..........ist das peinlich.......was brauchst du davon?Alles was angezeigt werden kann?Und : wieviel ist denn extrem viel?
Ach ich nehm einfach den höchsten Wert den ich finde.....ich fühl mich so hilflos........


mädchen





Also die höchsten Werte haben System Idle Process, WmiPrvSE.exe,Luna.exe,procexp.exe,svchost.exe.
Ich hoffe ich habe das richtig abgeschrieben,das springt da alles so schnell um , so schnell kann ich gar nicht gucken.

schrauber 22.10.2012 17:41

Öffne mal bitte OTL, bei Extra Registrierung auf Benutze Safe List stellen und Scan Button drücken. Poste bitte beide Logfiles :)

mädchen 22.10.2012 21:10

OTL Logfile:
Code:

OTL logfile created on: 22.10.2012 21:42:32 - Run 4
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\pc\Desktop\trojaner board
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 50,45% Memory free
4,22 Gb Paging File | 2,92 Gb Available in Paging File | 69,12% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 63,48 Gb Total Space | 29,17 Gb Free Space | 45,95% Space Free | Partition Type: NTFS
Drive D: | 20,49 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 387,63 Gb Total Space | 362,61 Gb Free Space | 93,54% Space Free | Partition Type: NTFS
Drive H: | 1,84 Gb Total Space | 1,82 Gb Free Space | 99,16% Space Free | Partition Type: FAT
 
Computer Name: PC-PC | User Name: pc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.10.10 11:31:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\pc\Desktop\trojaner board\OTL.exe
PRC - [2012.10.07 12:48:08 | 000,711,112 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.0.0\ToolbarUpdater.exe
PRC - [2012.09.29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.09.25 11:00:45 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012.09.25 10:52:56 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.09.25 10:52:48 | 000,386,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.09.19 19:20:40 | 000,079,136 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.09.19 11:29:44 | 001,869,152 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
PRC - [2012.09.19 11:29:42 | 001,699,168 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
PRC - [2012.09.13 15:26:52 | 001,006,448 | ---- | M] () -- C:\Windows\System32\dmwu.exe
PRC - [2012.09.06 13:12:20 | 000,162,408 | ---- | M] (Geek Software GmbH) -- C:\Program Files\PDF24\pdf24.exe
PRC - [2012.08.15 19:08:34 | 000,231,768 | ---- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe
PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.07.08 14:39:22 | 000,056,720 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
PRC - [2012.07.08 14:39:22 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
PRC - [2012.07.02 11:18:42 | 000,525,776 | ---- | M] (Abelssoft) -- C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
PRC - [2012.05.29 15:50:04 | 000,115,032 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\SweetIM.exe
PRC - [2012.05.24 20:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.) -- C:\Users\pc\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2011.10.09 15:57:49 | 002,089,472 | ---- | M] (Bdrive Inc.) -- C:\Program Files\NetDrive\ndsvc.exe
PRC - [2011.10.09 15:57:36 | 002,572,800 | ---- | M] (Bdrive Inc.) -- C:\Program Files\NetDrive\netdrive.exe
PRC - [2011.08.08 13:31:46 | 000,828,416 | ---- | M] (ActMask Co.,Ltd - hxxp://www.all2pdf.com) -- C:\Windows\System32\PrintDisp.exe
PRC - [2011.07.20 03:44:22 | 000,099,688 | ---- | M] (Lunascape Co., LTD.) -- C:\Program Files\Lunascape\Lunascape6\Luna.exe
PRC - [2011.07.08 17:12:13 | 000,403,968 | ---- | M] () -- C:\Program Files\MailXXL.com Tools\BMUtil.exe
PRC - [2011.05.09 01:07:54 | 000,703,392 | ---- | M] (Abelssoft GmbH) -- C:\Program Files\Schirmfoto\schirmfoto.exe
PRC - [2010.05.08 13:48:36 | 000,229,376 | ---- | M] () -- C:\ProgramData\DatacardService\DCService.exe
PRC - [2010.05.08 13:48:26 | 000,241,664 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe
PRC - [2010.04.29 05:04:12 | 000,069,632 | ---- | M] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) -- C:\Windows\System32\PrintCtrl.exe
PRC - [2009.05.25 13:09:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2008.05.07 10:19:26 | 006,139,904 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.09.24 15:27:06 | 000,014,320 | ---- | M] () -- C:\Program Files\Java\jre6\bin\jp2native.dll
MOD - [2012.09.24 15:25:46 | 000,108,528 | ---- | M] () -- C:\Program Files\Java\jre6\bin\jp2iexp.dll
MOD - [2012.07.08 14:39:22 | 000,114,064 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\InstallerExtensions.dll
MOD - [2012.07.08 14:39:22 | 000,018,832 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\cwebpage.dll
MOD - [2012.07.08 14:39:16 | 000,136,592 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\locale\de\de.dll
MOD - [2012.07.02 11:18:42 | 000,585,680 | ---- | M] () -- C:\Program Files\CheckDrive\AbScheduler.dll
MOD - [2012.07.02 11:18:42 | 000,013,776 | ---- | M] () -- C:\Program Files\CheckDrive\AbMessages.dll
MOD - [2012.06.15 09:24:57 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8bbcd31ecc8edc7d1f9cdd83ef2bb2d3\System.ServiceProcess.ni.dll
MOD - [2012.06.14 10:47:16 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012.06.14 10:46:37 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012.05.14 08:37:18 | 000,998,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f3d4d5fe5ab848fbfcf91a49960dc8ae\System.Management.ni.dll
MOD - [2012.05.14 08:32:23 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012.05.14 08:31:52 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012.05.14 08:30:08 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012.05.14 08:25:40 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012.05.14 08:24:58 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2011.07.08 17:12:13 | 000,403,968 | ---- | M] () -- C:\Program Files\MailXXL.com Tools\BMUtil.exe
MOD - [2011.05.09 01:07:54 | 000,585,632 | ---- | M] () -- C:\Program Files\Schirmfoto\AbScheduler.dll
MOD - [2011.05.09 01:07:54 | 000,180,128 | ---- | M] () -- C:\Program Files\Schirmfoto\AbBugReporter.dll
MOD - [2011.05.09 01:07:54 | 000,177,056 | ---- | M] () -- C:\Program Files\Schirmfoto\SchirmfotoCommon.dll
MOD - [2011.05.09 01:07:54 | 000,104,352 | ---- | M] () -- C:\Program Files\Schirmfoto\Cropper.dll
MOD - [2011.05.09 01:07:54 | 000,049,056 | ---- | M] () -- C:\Program Files\Schirmfoto\AbCommons.dll
MOD - [2011.05.09 01:07:54 | 000,028,576 | ---- | M] () -- C:\Program Files\Schirmfoto\AbSettingsKeeper.dll
MOD - [2011.05.09 01:07:54 | 000,010,144 | ---- | M] () -- C:\Program Files\Schirmfoto\AbUpdateBugReporter.dll
MOD - [2011.03.22 10:08:22 | 000,138,752 | ---- | M] () -- C:\Program Files\NetDrive\libexpat.dll
MOD - [2009.12.10 11:52:38 | 000,192,512 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll
MOD - [2009.12.10 11:51:36 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll
MOD - [2009.12.10 11:40:20 | 000,991,232 | ---- | M] () -- C:\Program Files\Mobile Partner\NDISAPI.dll
MOD - [2009.09.19 11:21:06 | 000,139,264 | ---- | M] () -- C:\Program Files\Mobile Partner\NetInfoPlugin.dll
MOD - [2009.06.19 15:10:46 | 000,143,360 | ---- | M] () -- C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll
MOD - [2009.06.19 15:10:22 | 000,159,744 | ---- | M] () -- C:\Program Files\Mobile Partner\SMSPlugin.dll
MOD - [2009.06.18 10:56:10 | 000,032,768 | ---- | M] () -- C:\Program Files\Mobile Partner\NotifyServicePlugin.dll
MOD - [2009.06.18 10:54:14 | 000,057,344 | ---- | M] () -- C:\Program Files\Mobile Partner\ConfigFilePlugin.dll
MOD - [2009.06.18 10:48:24 | 000,090,112 | ---- | M] () -- C:\Program Files\Mobile Partner\DialUpPlugin.dll
MOD - [2009.05.25 13:09:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe
MOD - [2009.05.23 11:02:32 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobile Partner\XCodec.dll
MOD - [2009.05.23 11:02:30 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceOperate.dll
MOD - [2009.05.23 11:02:28 | 000,155,648 | ---- | M] () -- C:\Program Files\Mobile Partner\DetectDev.dll
MOD - [2009.05.23 11:02:24 | 000,557,056 | ---- | M] () -- C:\Program Files\Mobile Partner\atcomm.dll
MOD - [2009.03.30 06:42:12 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll
MOD - [2009.03.30 06:42:11 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2009.02.12 10:53:02 | 000,040,448 | ---- | M] () -- C:\Program Files\NetDrive\ws_ext.dll
MOD - [2007.08.23 16:39:30 | 000,014,848 | ---- | M] () -- C:\Program Files\Mobile Partner\isaputrace.dll
MOD - [2007.07.31 15:50:04 | 000,090,112 | ---- | M] () -- C:\Program Files\Mobile Partner\FileManager.dll
 
 
========== Services (SafeList) ==========
 
SRV - [2012.10.19 10:38:38 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.10.07 12:48:08 | 000,711,112 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.0.0\ToolbarUpdater.exe -- (vToolbarUpdater13.0.0)
SRV - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.09.25 11:00:45 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.09.25 10:52:56 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.09.19 11:29:42 | 001,699,168 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2012.09.13 15:26:52 | 001,006,448 | ---- | M] () [Auto | Running] -- C:\Windows\System32\dmwu.exe -- (WebOptimizer)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.10.09 15:57:49 | 002,089,472 | ---- | M] (Bdrive Inc.) [Auto | Running] -- C:\Program Files\NetDrive\ndsvc.exe -- (ndsvc)
SRV - [2010.05.08 13:48:36 | 000,229,376 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\DCService.exe -- (DCService.exe)
SRV - [2010.04.29 05:04:12 | 000,069,632 | ---- | M] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) [Auto | Running] -- C:\Windows\System32\PrintCtrl.exe -- (Printer Control)
SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (catchme)
DRV - [2012.10.07 12:48:09 | 000,026,984 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtpx86.sys -- (avgtp)
DRV - [2012.10.01 17:14:23 | 000,134,184 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.09.29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.09.24 09:58:11 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2012.09.19 10:50:50 | 000,010,088 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2012.09.13 10:58:17 | 000,083,792 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.08.27 15:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2011.03.25 10:21:12 | 000,049,432 | ---- | M] (MacroData Inc.) [File_System | On_Demand | Stopped] -- C:\Program Files\NetDrive\NDFS.sys -- (ndfs)
DRV - [2010.04.09 15:24:12 | 000,063,616 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2010.03.25 10:08:38 | 000,105,984 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2010.03.20 11:56:04 | 000,101,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2010.03.20 10:28:12 | 000,116,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2009.06.30 09:37:16 | 000,028,552 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\pavboot.sys -- (pavboot)
DRV - [2008.07.29 01:53:46 | 000,919,552 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008.05.02 07:59:40 | 000,122,368 | ---- | M] (Realtek Corporation                                            ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.sweetim.com/?crg=3.1010006.10031&barid={8EAAC8C9-1A84-11E2-AEA6-001E101F3315}
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{7C788BE1-99B0-40CD-B58C-788705E205E2}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010006.10031&barid={8EAAC8C9-1A84-11E2-AEA6-001E101F3315}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.sweetim.com/?crg=3.1010006.10031&barid={8EAAC8C9-1A84-11E2-AEA6-001E101F3315}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {288575EA-507B-42CB-97BE-ACED08F1998A}
IE - HKCU\..\SearchScopes\{288575EA-507B-42CB-97BE-ACED08F1998A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADFA_deDE420
IE - HKCU\..\SearchScopes\{7C788BE1-99B0-40CD-B58C-788705E205E2}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
IE - HKCU\..\SearchScopes\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27}: "URL" = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010006.10031&barid={8EAAC8C9-1A84-11E2-AEA6-001E101F3315}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
 
[2011.07.14 13:58:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\pc\AppData\Roaming\mozilla\Extensions
[2012.07.11 10:56:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
 
========== Chrome  ==========
 
CHR - Extension: No name found = C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\
CHR - Extension: No name found = C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Netdrive] C:\Program Files\NetDrive\netdrive.exe (Bdrive Inc.)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [PrintDisp] C:\Windows\System32\PrintDisp.exe (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [Sweetpacks Communicator] C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe (SweetIM Technologies Ltd.)
O4 - HKCU..\Run: [b1gMail-Utility] C:\Program Files\MailXXL.com Tools\BMUtil.exe ()
O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited)
O4 - Startup: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\pc\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab (Bitdefender QuickScan Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} hxxp://acs.pandasoftware.com/activescan/pro/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 193.189.244.206 193.189.244.225
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{59DDF262-BEC7-46A7-8D06-943CB65610D4}: DhcpNameServer = 193.189.244.206 193.189.244.225
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: NameServer = 132.252.3.10,132.252.1.7
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010.05.08 21:48:36 | 000,126,976 | R--- | M] () - D:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2008.03.10 02:34:52 | 000,000,047 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.22 10:14:33 | 000,157,680 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2012.10.22 10:14:33 | 000,149,488 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2012.10.22 10:14:33 | 000,149,488 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2012.10.20 09:53:11 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Malwarebytes
[2012.10.20 09:53:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.10.20 09:53:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.10.20 09:53:04 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.10.20 09:53:04 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.10.20 09:12:52 | 000,000,000 | ---D | C] -- C:\Program Files\DownloadManager
[2012.10.20 09:05:38 | 000,000,000 | ---D | C] -- C:\ProgramData\SweetIM
[2012.10.20 09:05:38 | 000,000,000 | ---D | C] -- C:\Program Files\SweetIM
[2012.10.19 09:54:21 | 000,696,760 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.10.18 21:10:31 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.10.18 21:10:31 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\temp
[2012.10.18 21:05:12 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.10.18 20:15:33 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.10.18 20:15:33 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.10.18 20:15:33 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.10.18 20:15:15 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.10.18 20:14:54 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012.10.18 14:11:48 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Avira
[2012.10.18 14:05:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.10.18 14:05:46 | 000,134,184 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2012.10.18 14:05:46 | 000,083,792 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2012.10.18 14:05:46 | 000,036,552 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.10.18 14:05:40 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2012.10.11 16:56:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24
[2012.10.10 14:50:01 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\trojaner board
[2012.10.10 14:27:39 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2012.10.10 14:27:33 | 003,602,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012.10.10 14:27:32 | 003,550,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2012.10.09 05:10:27 | 000,000,000 | -H-D | C] -- C:\Windows\Icons
[2012.10.07 12:50:02 | 000,031,584 | ---- | C] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe
[2012.10.07 12:50:00 | 000,021,344 | ---- | C] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2012.10.07 12:49:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013
[2012.10.07 12:49:08 | 000,026,984 | ---- | C] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2012.10.07 12:47:43 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\TuneUp Software
[2012.10.07 12:47:29 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2013
[2012.10.07 12:46:31 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2012.10.07 12:46:15 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2012.09.23 04:15:46 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012.09.23 04:15:44 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012.09.23 04:15:44 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012.09.23 04:15:44 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012.09.23 04:15:44 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012.09.23 04:15:41 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012.09.23 04:15:41 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012.09.23 04:15:37 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.22 21:50:00 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Communicator.job
[2012.10.22 21:44:03 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.10.22 21:38:48 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.10.22 21:36:31 | 000,001,086 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.10.22 21:36:23 | 000,000,260 | ---- | M] () -- C:\Windows\tasks\AbelssoftPreloader.job
[2012.10.22 21:36:20 | 000,000,270 | ---- | M] () -- C:\Windows\tasks\CheckDriveBackgroundGuard.job
[2012.10.22 21:36:20 | 000,000,258 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job
[2012.10.22 21:36:20 | 000,000,234 | ---- | M] () -- C:\Windows\tasks\Schirmfoto.job
[2012.10.22 21:36:06 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.22 21:36:06 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.22 21:35:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.22 18:17:53 | 000,000,172 | ---- | M] () -- C:\Users\pc\Desktop\3.rtf
[2012.10.22 16:09:23 | 000,000,207 | ---- | M] () -- C:\Users\pc\Desktop\Dokument2.rtf
[2012.10.22 12:52:06 | 000,000,200 | ---- | M] () -- C:\Users\pc\Desktop\Dokument.rtf
[2012.10.21 19:00:39 | 000,271,760 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.10.20 09:16:39 | 000,001,828 | ---- | M] () -- C:\Users\pc\Desktop\JDownloader.lnk
[2012.10.20 09:05:25 | 000,000,231 | ---- | M] () -- C:\Users\pc\Desktop\Search the Web.url
[2012.10.20 09:05:25 | 000,000,225 | ---- | M] () -- C:\Users\pc\Desktop\SweetPcFix.url
[2012.10.19 10:38:37 | 000,696,760 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.10.19 10:38:37 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012.10.18 14:05:59 | 000,001,817 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.10.13 12:30:09 | 000,572,634 | ---- | M] () -- C:\Users\pc\Desktop\stui.jpg
[2012.10.11 16:56:57 | 000,001,608 | ---- | M] () -- C:\Users\Public\Desktop\PDF24 Fax.lnk
[2012.10.11 16:56:56 | 000,001,623 | ---- | M] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk
[2012.10.11 13:01:56 | 000,006,562 | ---- | M] () -- C:\Users\pc\Desktop\vvvvc.eml
[2012.10.10 11:22:22 | 000,000,000 | ---- | M] () -- C:\Users\pc\defogger_reenable
[2012.10.09 09:39:25 | 000,000,294 | ---- | M] () -- C:\Windows\tasks\WebReg Deskjet F300 series.job
[2012.10.07 12:49:48 | 000,001,839 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
[2012.10.07 12:49:48 | 000,001,835 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2012.10.07 12:48:09 | 000,026,984 | ---- | M] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2012.10.01 17:14:23 | 000,134,184 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2012.09.29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.27 17:53:45 | 000,001,941 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.09.27 11:22:58 | 000,000,193 | ---- | M] () -- C:\Users\pc\Documents\Dokument.rtf
[2012.09.26 11:04:43 | 000,000,786 | ---- | M] () -- C:\Users\Public\Desktop\WashAndGo.lnk
[2012.09.24 22:18:28 | 000,002,174 | ---- | M] () -- C:\Users\pc\Documents\semmelknödel.rtf
[2012.09.24 15:32:24 | 000,477,168 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\npdeployJava1.dll
[2012.09.24 15:32:20 | 000,473,072 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2012.09.24 15:23:41 | 000,157,680 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2012.09.24 15:23:37 | 000,149,488 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2012.09.24 15:23:26 | 000,149,488 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2012.09.24 09:58:11 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.09.23 12:16:20 | 000,001,087 | ---- | M] () -- C:\Users\pc\Desktop\scan.lnk
 
========== Files Created - No Company Name ==========
 
[2012.10.22 18:17:53 | 000,000,172 | ---- | C] () -- C:\Users\pc\Desktop\3.rtf
[2012.10.22 15:41:33 | 000,000,207 | ---- | C] () -- C:\Users\pc\Desktop\Dokument2.rtf
[2012.10.22 12:52:06 | 000,000,200 | ---- | C] () -- C:\Users\pc\Desktop\Dokument.rtf
[2012.10.21 19:00:23 | 000,271,760 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.10.20 09:16:39 | 000,001,828 | ---- | C] () -- C:\Users\pc\Desktop\JDownloader.lnk
[2012.10.20 09:16:31 | 000,001,792 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2012.10.20 09:16:31 | 000,001,736 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Uninstaller.lnk
[2012.10.20 09:16:31 | 000,001,715 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2012.10.20 09:05:25 | 000,000,231 | ---- | C] () -- C:\Users\pc\Desktop\Search the Web.url
[2012.10.20 09:05:25 | 000,000,225 | ---- | C] () -- C:\Users\pc\Desktop\SweetPcFix.url
[2012.10.19 09:54:24 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.10.18 20:15:33 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.10.18 20:15:33 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.10.18 20:15:33 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.10.18 20:15:33 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.10.18 20:15:33 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.10.18 14:05:59 | 000,001,817 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.10.11 16:56:57 | 000,001,608 | ---- | C] () -- C:\Users\Public\Desktop\PDF24 Fax.lnk
[2012.10.11 16:56:56 | 000,001,623 | ---- | C] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk
[2012.10.11 13:01:42 | 000,006,562 | ---- | C] () -- C:\Users\pc\Desktop\vvvvc.eml
[2012.10.10 11:22:22 | 000,000,000 | ---- | C] () -- C:\Users\pc\defogger_reenable
[2012.10.07 12:49:48 | 000,001,839 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
[2012.10.07 12:49:48 | 000,001,835 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2012.10.07 12:49:47 | 000,001,847 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013.lnk
[2012.09.26 11:04:43 | 000,000,786 | ---- | C] () -- C:\Users\Public\Desktop\WashAndGo.lnk
[2012.09.24 22:18:28 | 000,002,174 | ---- | C] () -- C:\Users\pc\Documents\semmelknödel.rtf
[2012.09.23 23:10:26 | 000,000,294 | ---- | C] () -- C:\Windows\tasks\WebReg Deskjet F300 series.job
[2012.09.23 12:12:43 | 000,001,087 | ---- | C] () -- C:\Users\pc\Desktop\scan.lnk
[2012.09.12 12:25:02 | 001,006,448 | ---- | C] () -- C:\Windows\System32\dmwu.exe
[2012.09.12 12:25:02 | 000,028,160 | ---- | C] () -- C:\Windows\System32\ImHttpComm.dll
[2012.07.10 14:48:59 | 000,000,519 | ---- | C] () -- C:\Users\pc\pc - Verknüpfung.lnk
[2012.04.27 18:29:20 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012.03.12 21:21:00 | 000,000,680 | ---- | C] () -- C:\Users\pc\AppData\Local\d3d9caps.dat
[2011.10.29 20:04:04 | 001,391,616 | ---- | C] () -- C:\Windows\System32\ActPDF.dll
[2011.10.29 20:03:43 | 000,691,200 | ---- | C] () -- C:\Windows\System32\PrintLog.exe
[2011.03.13 16:17:06 | 000,000,058 | ---- | C] () -- C:\Users\pc\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
[2011.02.25 15:46:39 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011.02.25 15:46:38 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010.12.31 17:07:07 | 000,164,255 | ---- | C] () -- C:\Windows\hpoins19.dat
[2010.12.31 17:06:48 | 000,026,952 | ---- | C] () -- C:\Windows\hpomdl19.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 925 bytes -> C:\Users\pc\Desktop\vvvvc.eml:OECustomProperty

< End of report >

--- --- ---
OTL Logfile:
Code:

OTL Extras logfile created on: 22.10.2012 21:42:32 - Run 4
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\pc\Desktop\trojaner board
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 50,45% Memory free
4,22 Gb Paging File | 2,92 Gb Available in Paging File | 69,12% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 63,48 Gb Total Space | 29,17 Gb Free Space | 45,95% Space Free | Partition Type: NTFS
Drive D: | 20,49 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 387,63 Gb Total Space | 362,61 Gb Free Space | 93,54% Space Free | Partition Type: NTFS
Drive H: | 1,84 Gb Total Space | 1,82 Gb Free Space | 99,16% Space Free | Partition Type: FAT
 
Computer Name: PC-PC | User Name: pc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01DAFA34-45E8-46A6-843F-AF34F4467C9C}" = protocol=6 | dir=in | app=c:\windows\system32\msiexec.exe |
"{1CBD7845-0288-4425-BA04-97252E840043}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{226CBE0F-9F1C-4B84-A7A8-097A9C328133}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{2F8FE96A-37FC-48FC-A274-7179176F6E5E}" = protocol=6 | dir=in | app=c:\users\pc\appdata\roaming\dropbox\bin\dropbox.exe |
"{30A19E42-C52D-4250-AA47-B5CC06F25C75}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{36DFF524-B990-4A6C-9DD8-A35391AF6005}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{55E9438A-EA76-4F28-B6FC-6D4B06A6EE3A}" = protocol=6 | dir=in | app=c:\program files\sweetim\communicator\sweetpacksupdatemanager.exe |
"{570FE284-895B-425F-98A0-58F43085550D}" = protocol=17 | dir=in | app=c:\program files\netdrive\ndsvc.exe |
"{6B5F328B-B609-45E4-B1F0-10A4A8981D6B}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{6CFC040B-44EC-400C-9A72-FE2A642E6067}" = protocol=6 | dir=in | app=c:\program files\netdrive\ndsvc.exe |
"{7406A79B-7E27-41B4-89EF-A91417F64737}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe |
"{779F3503-F364-4FE7-9CE1-37D85F63A158}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe |
"{79957D25-5AAE-4D80-BCD0-5FF98F001471}" = protocol=17 | dir=in | app=c:\program files\netdrive\ndsvc.exe |
"{822A9053-E4C8-4229-A730-70E667EB0997}" = protocol=17 | dir=in | app=c:\windows\system32\msiexec.exe |
"{9395F2EB-E730-41D8-AE48-44C71B493927}" = protocol=6 | dir=in | app=c:\program files\netdrive\ndsvc.exe |
"{96151931-4520-43E4-A689-52E226F4F082}" = protocol=17 | dir=in | app=c:\users\pc\appdata\roaming\dropbox\bin\dropbox.exe |
"{B18D5A65-90AB-4F84-B3D4-CF4A2BCD1A3C}" = protocol=6 | dir=in | app=c:\program files\searchqu toolbar\datamngr\toolbar\dtuser.exe |
"{B652535E-06B3-4831-A7FC-7D3B0C31336C}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{B6569463-37A6-457C-B2CF-CA6BA5D3D665}" = protocol=17 | dir=in | app=c:\program files\searchqu toolbar\datamngr\toolbar\dtuser.exe |
"{CF8C0B69-02D6-4BF4-8F2D-3E3452DFAECC}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{DB981E26-B54D-42DC-980D-44D30D7A2EA1}" = protocol=17 | dir=in | app=c:\program files\sweetim\communicator\sweetpacksupdatemanager.exe |
"{DC710067-43A4-4852-BEE0-693EEF7CABBF}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{E02E6A6E-55B2-47CC-9DAF-A872D61B3CFD}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F34F597B-25CF-41E3-AB7E-9B2E4155FDA1}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F4CF3062-B85A-47D4-AD86-9AEB657CE2B9}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"TCP Query User{83523A5E-6197-4677-9AB9-1354342A3F07}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{5825ABB3-A8F9-4ED4-B057-F4799EC1B792}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java(TM) 6 Update 37
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{4281435C-AD1D-4C8A-B9C0-3961C11EF142}_is1" = YouTube Song Downloader
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}" = Paint.NET v3.5.10
"{5E6D6161-5509-4f55-9372-1E01792F843A}" = F300_Help
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7683B745-6060-41FD-AA75-0BBB383FEAD4}" = SweetIM for Messenger 3.7
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 4.9.0
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch
"{B83513EC-2E4D-4621-816D-4CCF397BE702}_is1" = CheckDrive
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}" = Internet Explorer Toolbar 4.6 by SweetPacks
"{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}" = TuneUp Utilities 2013
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C911A0C2-2236-3164-AA47-F2566C01AE5E}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DDD5104F-1C44-49EB-9E6B-29EC5D27658B}" = HP Update
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E55B3271-7CA8-4D0C-AE06-69A24856E997}_is1" = Uniblue RegistryBooster
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}" = Update Manager for SweetPacks 1.1
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1568757-E564-4cb5-8980-9333119A4384}" = F300
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F2AF3E5D-9697-485C-A5AC-E2B9468C446A}" = Safari
"{F4811919-F252-4B25-9AB2-8859A85810B5}" = TuneUp Utilities Language Pack (de-DE)
"{F6AC5364-2FB7-437a-811A-D645F22AA6AC}" = F300Trb
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"5513-1208-7298-9440" = JDownloader 0.9
"AbAlarm_is1" = AbAlarm
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Avira AntiVir Desktop" = Avira Free Antivirus
"CCleaner" = CCleaner
"DealBulldog Toolbar Toolbar" = DealBulldog Toolbar Toolbar
"Google Chrome" = Google Chrome
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Photo Creations" = HP Photo Creations
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.0.4 (Basic)
"Lunascape6" = Lunascape6 (All Users)
"MailXXL.com" = MailXXL.com Tools
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.65.1.1000
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mobile Partner" = Mobile Partner
"MyKeyFinder_is1" = MyKeyFinder
"NetDrive" = NetDrive
"Schirmfoto_is1" = Schirmfoto
"TuneUp Utilities 2013" = TuneUp Utilities 2013
"WashAndGo_is1" = WashAndGo
"WNLT" = Web Optimizer
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 22.10.2012 11:54:35 | Computer Name = pc-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 22.10.2012 15:37:06 | Computer Name = pc-PC | Source = WinMgmt | ID = 10
Description =
 
[ System Events ]
Error - 22.10.2012 11:55:35 | Computer Name = pc-PC | Source = Dhcp | ID = 1002
Description = Die IP-Adresslease 10.161.154.243 für die Netzwerkkarte mit der Netzwerkadresse
 001E101FA1F5 wurde durch den DHCP-Server 10.49.195.162 abgelehnt (der DHCP-Server
 hat eine DHCPNACK-Meldung gesendet).
 
Error - 22.10.2012 11:56:49 | Computer Name = pc-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
 
Error - 22.10.2012 15:39:56 | Computer Name = pc-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
 
 
< End of report >

--- --- ---


Tschuldigung, habe mal wieder einen Fehler gemacht, die Programme vorher nicht geschlossen. Ich mach neue OTLS...

mädchen

OTL Logfile:
Code:

OTL logfile created on: 22.10.2012 22:30:58 - Run 5
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\pc\Desktop\trojaner board
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 1,01 Gb Available Physical Memory | 50,63% Memory free
4,22 Gb Paging File | 2,94 Gb Available in Paging File | 69,80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 63,48 Gb Total Space | 29,16 Gb Free Space | 45,93% Space Free | Partition Type: NTFS
Drive D: | 20,49 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 387,63 Gb Total Space | 362,61 Gb Free Space | 93,54% Space Free | Partition Type: NTFS
Drive H: | 1,84 Gb Total Space | 1,82 Gb Free Space | 99,16% Space Free | Partition Type: FAT
 
Computer Name: PC-PC | User Name: pc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.10.10 11:31:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\pc\Desktop\trojaner board\OTL.exe
PRC - [2012.10.07 12:48:08 | 000,711,112 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.0.0\ToolbarUpdater.exe
PRC - [2012.09.29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.09.25 11:00:45 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012.09.25 10:52:56 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.09.25 10:52:48 | 000,386,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.09.19 19:20:40 | 000,079,136 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.09.19 11:29:44 | 001,869,152 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
PRC - [2012.09.19 11:29:42 | 001,699,168 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
PRC - [2012.09.13 15:26:52 | 001,006,448 | ---- | M] () -- C:\Windows\System32\dmwu.exe
PRC - [2012.09.06 13:12:20 | 000,162,408 | ---- | M] (Geek Software GmbH) -- C:\Program Files\PDF24\pdf24.exe
PRC - [2012.08.15 19:08:34 | 000,231,768 | ---- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe
PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.07.08 14:39:22 | 000,056,720 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
PRC - [2012.07.08 14:39:22 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
PRC - [2012.07.02 11:18:42 | 000,525,776 | ---- | M] (Abelssoft) -- C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
PRC - [2012.05.29 15:50:04 | 000,115,032 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\SweetIM.exe
PRC - [2012.05.24 20:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.) -- C:\Users\pc\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2011.10.09 15:57:49 | 002,089,472 | ---- | M] (Bdrive Inc.) -- C:\Program Files\NetDrive\ndsvc.exe
PRC - [2011.10.09 15:57:36 | 002,572,800 | ---- | M] (Bdrive Inc.) -- C:\Program Files\NetDrive\netdrive.exe
PRC - [2011.08.08 13:31:46 | 000,828,416 | ---- | M] (ActMask Co.,Ltd - hxxp://www.all2pdf.com) -- C:\Windows\System32\PrintDisp.exe
PRC - [2011.07.08 17:12:13 | 000,403,968 | ---- | M] () -- C:\Program Files\MailXXL.com Tools\BMUtil.exe
PRC - [2011.05.09 01:07:54 | 000,703,392 | ---- | M] (Abelssoft GmbH) -- C:\Program Files\Schirmfoto\schirmfoto.exe
PRC - [2010.05.08 13:48:36 | 000,229,376 | ---- | M] () -- C:\ProgramData\DatacardService\DCService.exe
PRC - [2010.05.08 13:48:26 | 000,241,664 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe
PRC - [2010.04.29 05:04:12 | 000,069,632 | ---- | M] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) -- C:\Windows\System32\PrintCtrl.exe
PRC - [2009.05.25 13:09:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2008.05.07 10:19:26 | 006,139,904 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.07.08 14:39:22 | 000,114,064 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\InstallerExtensions.dll
MOD - [2012.07.08 14:39:22 | 000,018,832 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\cwebpage.dll
MOD - [2012.07.08 14:39:16 | 000,136,592 | ---- | M] () -- C:\Program Files\Uniblue\RegistryBooster\locale\de\de.dll
MOD - [2012.07.02 11:18:42 | 000,585,680 | ---- | M] () -- C:\Program Files\CheckDrive\AbScheduler.dll
MOD - [2012.07.02 11:18:42 | 000,013,776 | ---- | M] () -- C:\Program Files\CheckDrive\AbMessages.dll
MOD - [2012.06.15 09:24:57 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8bbcd31ecc8edc7d1f9cdd83ef2bb2d3\System.ServiceProcess.ni.dll
MOD - [2012.06.14 10:47:16 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012.06.14 10:46:37 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012.05.14 08:37:18 | 000,998,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f3d4d5fe5ab848fbfcf91a49960dc8ae\System.Management.ni.dll
MOD - [2012.05.14 08:32:23 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012.05.14 08:31:52 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012.05.14 08:30:08 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012.05.14 08:25:40 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012.05.14 08:24:58 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2011.07.08 17:12:13 | 000,403,968 | ---- | M] () -- C:\Program Files\MailXXL.com Tools\BMUtil.exe
MOD - [2011.05.09 01:07:54 | 000,585,632 | ---- | M] () -- C:\Program Files\Schirmfoto\AbScheduler.dll
MOD - [2011.05.09 01:07:54 | 000,180,128 | ---- | M] () -- C:\Program Files\Schirmfoto\AbBugReporter.dll
MOD - [2011.05.09 01:07:54 | 000,177,056 | ---- | M] () -- C:\Program Files\Schirmfoto\SchirmfotoCommon.dll
MOD - [2011.05.09 01:07:54 | 000,104,352 | ---- | M] () -- C:\Program Files\Schirmfoto\Cropper.dll
MOD - [2011.05.09 01:07:54 | 000,049,056 | ---- | M] () -- C:\Program Files\Schirmfoto\AbCommons.dll
MOD - [2011.05.09 01:07:54 | 000,028,576 | ---- | M] () -- C:\Program Files\Schirmfoto\AbSettingsKeeper.dll
MOD - [2011.05.09 01:07:54 | 000,010,144 | ---- | M] () -- C:\Program Files\Schirmfoto\AbUpdateBugReporter.dll
MOD - [2011.03.22 10:08:22 | 000,138,752 | ---- | M] () -- C:\Program Files\NetDrive\libexpat.dll
MOD - [2009.12.10 11:52:38 | 000,192,512 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll
MOD - [2009.12.10 11:51:36 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll
MOD - [2009.12.10 11:40:20 | 000,991,232 | ---- | M] () -- C:\Program Files\Mobile Partner\NDISAPI.dll
MOD - [2009.09.19 11:21:06 | 000,139,264 | ---- | M] () -- C:\Program Files\Mobile Partner\NetInfoPlugin.dll
MOD - [2009.06.19 15:10:46 | 000,143,360 | ---- | M] () -- C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll
MOD - [2009.06.19 15:10:22 | 000,159,744 | ---- | M] () -- C:\Program Files\Mobile Partner\SMSPlugin.dll
MOD - [2009.06.18 10:56:10 | 000,032,768 | ---- | M] () -- C:\Program Files\Mobile Partner\NotifyServicePlugin.dll
MOD - [2009.06.18 10:54:14 | 000,057,344 | ---- | M] () -- C:\Program Files\Mobile Partner\ConfigFilePlugin.dll
MOD - [2009.06.18 10:48:24 | 000,090,112 | ---- | M] () -- C:\Program Files\Mobile Partner\DialUpPlugin.dll
MOD - [2009.05.25 13:09:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe
MOD - [2009.05.23 11:02:32 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobile Partner\XCodec.dll
MOD - [2009.05.23 11:02:30 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceOperate.dll
MOD - [2009.05.23 11:02:28 | 000,155,648 | ---- | M] () -- C:\Program Files\Mobile Partner\DetectDev.dll
MOD - [2009.05.23 11:02:24 | 000,557,056 | ---- | M] () -- C:\Program Files\Mobile Partner\atcomm.dll
MOD - [2009.03.30 06:42:12 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll
MOD - [2009.03.30 06:42:11 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2009.02.12 10:53:02 | 000,040,448 | ---- | M] () -- C:\Program Files\NetDrive\ws_ext.dll
MOD - [2007.08.23 16:39:30 | 000,014,848 | ---- | M] () -- C:\Program Files\Mobile Partner\isaputrace.dll
MOD - [2007.07.31 15:50:04 | 000,090,112 | ---- | M] () -- C:\Program Files\Mobile Partner\FileManager.dll
 
 
========== Services (SafeList) ==========
 
SRV - [2012.10.19 10:38:38 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.10.07 12:48:08 | 000,711,112 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.0.0\ToolbarUpdater.exe -- (vToolbarUpdater13.0.0)
SRV - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.09.25 11:00:45 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.09.25 10:52:56 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.09.19 11:29:42 | 001,699,168 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2012.09.13 15:26:52 | 001,006,448 | ---- | M] () [Auto | Running] -- C:\Windows\System32\dmwu.exe -- (WebOptimizer)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.10.09 15:57:49 | 002,089,472 | ---- | M] (Bdrive Inc.) [Auto | Running] -- C:\Program Files\NetDrive\ndsvc.exe -- (ndsvc)
SRV - [2010.05.08 13:48:36 | 000,229,376 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\DCService.exe -- (DCService.exe)
SRV - [2010.04.29 05:04:12 | 000,069,632 | ---- | M] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) [Auto | Running] -- C:\Windows\System32\PrintCtrl.exe -- (Printer Control)
SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (catchme)
DRV - [2012.10.07 12:48:09 | 000,026,984 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtpx86.sys -- (avgtp)
DRV - [2012.10.01 17:14:23 | 000,134,184 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.09.29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.09.24 09:58:11 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2012.09.19 10:50:50 | 000,010,088 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2012.09.13 10:58:17 | 000,083,792 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.08.27 15:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2011.03.25 10:21:12 | 000,049,432 | ---- | M] (MacroData Inc.) [File_System | On_Demand | Stopped] -- C:\Program Files\NetDrive\NDFS.sys -- (ndfs)
DRV - [2010.04.09 15:24:12 | 000,063,616 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2010.03.25 10:08:38 | 000,105,984 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2010.03.20 11:56:04 | 000,101,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2010.03.20 10:28:12 | 000,116,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2009.06.30 09:37:16 | 000,028,552 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\pavboot.sys -- (pavboot)
DRV - [2008.07.29 01:53:46 | 000,919,552 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008.05.02 07:59:40 | 000,122,368 | ---- | M] (Realtek Corporation                                            ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.sweetim.com/?crg=3.1010006.10031&barid={8EAAC8C9-1A84-11E2-AEA6-001E101F3315}
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{7C788BE1-99B0-40CD-B58C-788705E205E2}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010006.10031&barid={8EAAC8C9-1A84-11E2-AEA6-001E101F3315}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.sweetim.com/?crg=3.1010006.10031&barid={8EAAC8C9-1A84-11E2-AEA6-001E101F3315}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {288575EA-507B-42CB-97BE-ACED08F1998A}
IE - HKCU\..\SearchScopes\{288575EA-507B-42CB-97BE-ACED08F1998A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADFA_deDE420
IE - HKCU\..\SearchScopes\{7C788BE1-99B0-40CD-B58C-788705E205E2}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
IE - HKCU\..\SearchScopes\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27}: "URL" = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010006.10031&barid={8EAAC8C9-1A84-11E2-AEA6-001E101F3315}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
 
[2011.07.14 13:58:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\pc\AppData\Roaming\mozilla\Extensions
[2012.07.11 10:56:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
 
========== Chrome  ==========
 
CHR - Extension: No name found = C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\
CHR - Extension: No name found = C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Netdrive] C:\Program Files\NetDrive\netdrive.exe (Bdrive Inc.)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [PrintDisp] C:\Windows\System32\PrintDisp.exe (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [Sweetpacks Communicator] C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe (SweetIM Technologies Ltd.)
O4 - HKCU..\Run: [b1gMail-Utility] C:\Program Files\MailXXL.com Tools\BMUtil.exe ()
O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited)
O4 - Startup: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\pc\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab (Bitdefender QuickScan Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} hxxp://acs.pandasoftware.com/activescan/pro/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 193.189.244.206 193.189.244.225
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{59DDF262-BEC7-46A7-8D06-943CB65610D4}: DhcpNameServer = 193.189.244.206 193.189.244.225
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: NameServer = 132.252.3.10,132.252.1.7
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010.05.08 21:48:36 | 000,126,976 | R--- | M] () - D:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2008.03.10 02:34:52 | 000,000,047 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.22 10:14:33 | 000,157,680 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2012.10.22 10:14:33 | 000,149,488 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2012.10.22 10:14:33 | 000,149,488 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2012.10.20 09:53:11 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Malwarebytes
[2012.10.20 09:53:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.10.20 09:53:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.10.20 09:53:04 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.10.20 09:53:04 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.10.20 09:12:52 | 000,000,000 | ---D | C] -- C:\Program Files\DownloadManager
[2012.10.20 09:05:38 | 000,000,000 | ---D | C] -- C:\ProgramData\SweetIM
[2012.10.20 09:05:38 | 000,000,000 | ---D | C] -- C:\Program Files\SweetIM
[2012.10.19 09:54:21 | 000,696,760 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.10.18 21:10:31 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.10.18 21:10:31 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\temp
[2012.10.18 21:05:12 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.10.18 20:15:33 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.10.18 20:15:33 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.10.18 20:15:33 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.10.18 20:15:15 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.10.18 20:14:54 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012.10.18 14:11:48 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Avira
[2012.10.18 14:05:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.10.18 14:05:46 | 000,134,184 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2012.10.18 14:05:46 | 000,083,792 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2012.10.18 14:05:46 | 000,036,552 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.10.18 14:05:40 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2012.10.11 16:56:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24
[2012.10.10 14:50:01 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\trojaner board
[2012.10.10 14:27:39 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2012.10.10 14:27:33 | 003,602,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012.10.10 14:27:32 | 003,550,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2012.10.09 05:10:27 | 000,000,000 | -H-D | C] -- C:\Windows\Icons
[2012.10.07 12:50:02 | 000,031,584 | ---- | C] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe
[2012.10.07 12:50:00 | 000,021,344 | ---- | C] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2012.10.07 12:49:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013
[2012.10.07 12:49:08 | 000,026,984 | ---- | C] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2012.10.07 12:47:43 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\TuneUp Software
[2012.10.07 12:47:29 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2013
[2012.10.07 12:46:31 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2012.10.07 12:46:15 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2012.09.23 04:15:46 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012.09.23 04:15:44 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012.09.23 04:15:44 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012.09.23 04:15:44 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012.09.23 04:15:44 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012.09.23 04:15:41 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012.09.23 04:15:41 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012.09.23 04:15:37 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.22 21:50:00 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Communicator.job
[2012.10.22 21:44:03 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.10.22 21:38:48 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.10.22 21:36:31 | 000,001,086 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.10.22 21:36:23 | 000,000,260 | ---- | M] () -- C:\Windows\tasks\AbelssoftPreloader.job
[2012.10.22 21:36:20 | 000,000,270 | ---- | M] () -- C:\Windows\tasks\CheckDriveBackgroundGuard.job
[2012.10.22 21:36:20 | 000,000,258 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job
[2012.10.22 21:36:20 | 000,000,234 | ---- | M] () -- C:\Windows\tasks\Schirmfoto.job
[2012.10.22 21:36:06 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.22 21:36:06 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.22 21:35:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.22 18:17:53 | 000,000,172 | ---- | M] () -- C:\Users\pc\Desktop\3.rtf
[2012.10.22 16:09:23 | 000,000,207 | ---- | M] () -- C:\Users\pc\Desktop\Dokument2.rtf
[2012.10.22 12:52:06 | 000,000,200 | ---- | M] () -- C:\Users\pc\Desktop\Dokument.rtf
[2012.10.21 19:00:39 | 000,271,760 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.10.20 09:16:39 | 000,001,828 | ---- | M] () -- C:\Users\pc\Desktop\JDownloader.lnk
[2012.10.20 09:05:25 | 000,000,231 | ---- | M] () -- C:\Users\pc\Desktop\Search the Web.url
[2012.10.20 09:05:25 | 000,000,225 | ---- | M] () -- C:\Users\pc\Desktop\SweetPcFix.url
[2012.10.19 10:38:37 | 000,696,760 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.10.19 10:38:37 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012.10.18 14:05:59 | 000,001,817 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.10.13 12:30:09 | 000,572,634 | ---- | M] () -- C:\Users\pc\Desktop\stui.jpg
[2012.10.11 16:56:57 | 000,001,608 | ---- | M] () -- C:\Users\Public\Desktop\PDF24 Fax.lnk
[2012.10.11 16:56:56 | 000,001,623 | ---- | M] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk
[2012.10.11 13:01:56 | 000,006,562 | ---- | M] () -- C:\Users\pc\Desktop\vvvvc.eml
[2012.10.10 11:22:22 | 000,000,000 | ---- | M] () -- C:\Users\pc\defogger_reenable
[2012.10.09 09:39:25 | 000,000,294 | ---- | M] () -- C:\Windows\tasks\WebReg Deskjet F300 series.job
[2012.10.07 12:49:48 | 000,001,839 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
[2012.10.07 12:49:48 | 000,001,835 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2012.10.07 12:48:09 | 000,026,984 | ---- | M] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2012.10.01 17:14:23 | 000,134,184 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2012.09.29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.27 17:53:45 | 000,001,941 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.09.27 11:22:58 | 000,000,193 | ---- | M] () -- C:\Users\pc\Documents\Dokument.rtf
[2012.09.26 11:04:43 | 000,000,786 | ---- | M] () -- C:\Users\Public\Desktop\WashAndGo.lnk
[2012.09.24 22:18:28 | 000,002,174 | ---- | M] () -- C:\Users\pc\Documents\semmelknödel.rtf
[2012.09.24 15:32:24 | 000,477,168 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\npdeployJava1.dll
[2012.09.24 15:32:20 | 000,473,072 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2012.09.24 15:23:41 | 000,157,680 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2012.09.24 15:23:37 | 000,149,488 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2012.09.24 15:23:26 | 000,149,488 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2012.09.24 09:58:11 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.09.23 12:16:20 | 000,001,087 | ---- | M] () -- C:\Users\pc\Desktop\scan.lnk
 
========== Files Created - No Company Name ==========
 
[2012.10.22 18:17:53 | 000,000,172 | ---- | C] () -- C:\Users\pc\Desktop\3.rtf
[2012.10.22 15:41:33 | 000,000,207 | ---- | C] () -- C:\Users\pc\Desktop\Dokument2.rtf
[2012.10.22 12:52:06 | 000,000,200 | ---- | C] () -- C:\Users\pc\Desktop\Dokument.rtf
[2012.10.21 19:00:23 | 000,271,760 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.10.20 09:16:39 | 000,001,828 | ---- | C] () -- C:\Users\pc\Desktop\JDownloader.lnk
[2012.10.20 09:16:31 | 000,001,792 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2012.10.20 09:16:31 | 000,001,736 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Uninstaller.lnk
[2012.10.20 09:16:31 | 000,001,715 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2012.10.20 09:05:25 | 000,000,231 | ---- | C] () -- C:\Users\pc\Desktop\Search the Web.url
[2012.10.20 09:05:25 | 000,000,225 | ---- | C] () -- C:\Users\pc\Desktop\SweetPcFix.url
[2012.10.19 09:54:24 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.10.18 20:15:33 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.10.18 20:15:33 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.10.18 20:15:33 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.10.18 20:15:33 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.10.18 20:15:33 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.10.18 14:05:59 | 000,001,817 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.10.11 16:56:57 | 000,001,608 | ---- | C] () -- C:\Users\Public\Desktop\PDF24 Fax.lnk
[2012.10.11 16:56:56 | 000,001,623 | ---- | C] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk
[2012.10.11 13:01:42 | 000,006,562 | ---- | C] () -- C:\Users\pc\Desktop\vvvvc.eml
[2012.10.10 11:22:22 | 000,000,000 | ---- | C] () -- C:\Users\pc\defogger_reenable
[2012.10.07 12:49:48 | 000,001,839 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
[2012.10.07 12:49:48 | 000,001,835 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2012.10.07 12:49:47 | 000,001,847 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013.lnk
[2012.09.26 11:04:43 | 000,000,786 | ---- | C] () -- C:\Users\Public\Desktop\WashAndGo.lnk
[2012.09.24 22:18:28 | 000,002,174 | ---- | C] () -- C:\Users\pc\Documents\semmelknödel.rtf
[2012.09.23 23:10:26 | 000,000,294 | ---- | C] () -- C:\Windows\tasks\WebReg Deskjet F300 series.job
[2012.09.23 12:12:43 | 000,001,087 | ---- | C] () -- C:\Users\pc\Desktop\scan.lnk
[2012.09.12 12:25:02 | 001,006,448 | ---- | C] () -- C:\Windows\System32\dmwu.exe
[2012.09.12 12:25:02 | 000,028,160 | ---- | C] () -- C:\Windows\System32\ImHttpComm.dll
[2012.07.10 14:48:59 | 000,000,519 | ---- | C] () -- C:\Users\pc\pc - Verknüpfung.lnk
[2012.04.27 18:29:20 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012.03.12 21:21:00 | 000,000,680 | ---- | C] () -- C:\Users\pc\AppData\Local\d3d9caps.dat
[2011.10.29 20:04:04 | 001,391,616 | ---- | C] () -- C:\Windows\System32\ActPDF.dll
[2011.10.29 20:03:43 | 000,691,200 | ---- | C] () -- C:\Windows\System32\PrintLog.exe
[2011.03.13 16:17:06 | 000,000,058 | ---- | C] () -- C:\Users\pc\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
[2011.02.25 15:46:39 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011.02.25 15:46:38 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010.12.31 17:07:07 | 000,164,255 | ---- | C] () -- C:\Windows\hpoins19.dat
[2010.12.31 17:06:48 | 000,026,952 | ---- | C] () -- C:\Windows\hpomdl19.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 925 bytes -> C:\Users\pc\Desktop\vvvvc.eml:OECustomProperty

< End of report >

--- --- ---
OTL Logfile:
Code:

OTL Extras logfile created on: 22.10.2012 22:30:58 - Run 5
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\pc\Desktop\trojaner board
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 1,01 Gb Available Physical Memory | 50,63% Memory free
4,22 Gb Paging File | 2,94 Gb Available in Paging File | 69,80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 63,48 Gb Total Space | 29,16 Gb Free Space | 45,93% Space Free | Partition Type: NTFS
Drive D: | 20,49 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 387,63 Gb Total Space | 362,61 Gb Free Space | 93,54% Space Free | Partition Type: NTFS
Drive H: | 1,84 Gb Total Space | 1,82 Gb Free Space | 99,16% Space Free | Partition Type: FAT
 
Computer Name: PC-PC | User Name: pc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01DAFA34-45E8-46A6-843F-AF34F4467C9C}" = protocol=6 | dir=in | app=c:\windows\system32\msiexec.exe |
"{1CBD7845-0288-4425-BA04-97252E840043}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{226CBE0F-9F1C-4B84-A7A8-097A9C328133}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{2F8FE96A-37FC-48FC-A274-7179176F6E5E}" = protocol=6 | dir=in | app=c:\users\pc\appdata\roaming\dropbox\bin\dropbox.exe |
"{30A19E42-C52D-4250-AA47-B5CC06F25C75}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{36DFF524-B990-4A6C-9DD8-A35391AF6005}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{55E9438A-EA76-4F28-B6FC-6D4B06A6EE3A}" = protocol=6 | dir=in | app=c:\program files\sweetim\communicator\sweetpacksupdatemanager.exe |
"{570FE284-895B-425F-98A0-58F43085550D}" = protocol=17 | dir=in | app=c:\program files\netdrive\ndsvc.exe |
"{6B5F328B-B609-45E4-B1F0-10A4A8981D6B}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{6CFC040B-44EC-400C-9A72-FE2A642E6067}" = protocol=6 | dir=in | app=c:\program files\netdrive\ndsvc.exe |
"{7406A79B-7E27-41B4-89EF-A91417F64737}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe |
"{779F3503-F364-4FE7-9CE1-37D85F63A158}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe |
"{79957D25-5AAE-4D80-BCD0-5FF98F001471}" = protocol=17 | dir=in | app=c:\program files\netdrive\ndsvc.exe |
"{822A9053-E4C8-4229-A730-70E667EB0997}" = protocol=17 | dir=in | app=c:\windows\system32\msiexec.exe |
"{9395F2EB-E730-41D8-AE48-44C71B493927}" = protocol=6 | dir=in | app=c:\program files\netdrive\ndsvc.exe |
"{96151931-4520-43E4-A689-52E226F4F082}" = protocol=17 | dir=in | app=c:\users\pc\appdata\roaming\dropbox\bin\dropbox.exe |
"{B18D5A65-90AB-4F84-B3D4-CF4A2BCD1A3C}" = protocol=6 | dir=in | app=c:\program files\searchqu toolbar\datamngr\toolbar\dtuser.exe |
"{B652535E-06B3-4831-A7FC-7D3B0C31336C}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{B6569463-37A6-457C-B2CF-CA6BA5D3D665}" = protocol=17 | dir=in | app=c:\program files\searchqu toolbar\datamngr\toolbar\dtuser.exe |
"{CF8C0B69-02D6-4BF4-8F2D-3E3452DFAECC}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{DB981E26-B54D-42DC-980D-44D30D7A2EA1}" = protocol=17 | dir=in | app=c:\program files\sweetim\communicator\sweetpacksupdatemanager.exe |
"{DC710067-43A4-4852-BEE0-693EEF7CABBF}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{E02E6A6E-55B2-47CC-9DAF-A872D61B3CFD}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F34F597B-25CF-41E3-AB7E-9B2E4155FDA1}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F4CF3062-B85A-47D4-AD86-9AEB657CE2B9}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"TCP Query User{83523A5E-6197-4677-9AB9-1354342A3F07}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{5825ABB3-A8F9-4ED4-B057-F4799EC1B792}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java(TM) 6 Update 37
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{4281435C-AD1D-4C8A-B9C0-3961C11EF142}_is1" = YouTube Song Downloader
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}" = Paint.NET v3.5.10
"{5E6D6161-5509-4f55-9372-1E01792F843A}" = F300_Help
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7683B745-6060-41FD-AA75-0BBB383FEAD4}" = SweetIM for Messenger 3.7
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 4.9.0
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch
"{B83513EC-2E4D-4621-816D-4CCF397BE702}_is1" = CheckDrive
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}" = Internet Explorer Toolbar 4.6 by SweetPacks
"{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}" = TuneUp Utilities 2013
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C911A0C2-2236-3164-AA47-F2566C01AE5E}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DDD5104F-1C44-49EB-9E6B-29EC5D27658B}" = HP Update
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E55B3271-7CA8-4D0C-AE06-69A24856E997}_is1" = Uniblue RegistryBooster
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}" = Update Manager for SweetPacks 1.1
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1568757-E564-4cb5-8980-9333119A4384}" = F300
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F2AF3E5D-9697-485C-A5AC-E2B9468C446A}" = Safari
"{F4811919-F252-4B25-9AB2-8859A85810B5}" = TuneUp Utilities Language Pack (de-DE)
"{F6AC5364-2FB7-437a-811A-D645F22AA6AC}" = F300Trb
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"5513-1208-7298-9440" = JDownloader 0.9
"AbAlarm_is1" = AbAlarm
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Avira AntiVir Desktop" = Avira Free Antivirus
"CCleaner" = CCleaner
"DealBulldog Toolbar Toolbar" = DealBulldog Toolbar Toolbar
"Google Chrome" = Google Chrome
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Photo Creations" = HP Photo Creations
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.0.4 (Basic)
"Lunascape6" = Lunascape6 (All Users)
"MailXXL.com" = MailXXL.com Tools
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.65.1.1000
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mobile Partner" = Mobile Partner
"MyKeyFinder_is1" = MyKeyFinder
"NetDrive" = NetDrive
"Schirmfoto_is1" = Schirmfoto
"TuneUp Utilities 2013" = TuneUp Utilities 2013
"WashAndGo_is1" = WashAndGo
"WNLT" = Web Optimizer
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 22.10.2012 11:54:35 | Computer Name = pc-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 22.10.2012 15:37:06 | Computer Name = pc-PC | Source = WinMgmt | ID = 10
Description =
 
[ System Events ]
Error - 22.10.2012 11:55:35 | Computer Name = pc-PC | Source = Dhcp | ID = 1002
Description = Die IP-Adresslease 10.161.154.243 für die Netzwerkkarte mit der Netzwerkadresse
 001E101FA1F5 wurde durch den DHCP-Server 10.49.195.162 abgelehnt (der DHCP-Server
 hat eine DHCPNACK-Meldung gesendet).
 
Error - 22.10.2012 11:56:49 | Computer Name = pc-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
 
Error - 22.10.2012 15:39:56 | Computer Name = pc-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
 
 
< End of report >

--- --- ---

schrauber 23.10.2012 07:24

Downloade dir bitte Windows Repair (All In One) von hier.

mädchen 23.10.2012 09:02

Hallo,
mh,auf der Windows Repair Seite sind unter Installer sechs Download-Buttons und unter Portable nochmal vier. Zwei davon sind direct download. Welche(n) muss ich nehmen?

LG (du machst dir eine Mühe mit mir, is ja toll )
mädchen

schrauber 23.10.2012 10:20

Nimm den :)

Windows Repair (All In One) Download

mädchen 23.10.2012 16:07

Hi,

habe Windows Repair gemacht.
Was soll ich jetzt machen? Wieder ein OTL?

Grüße

mädchen


habe eben feststellen müssen dass es mit den you tube videos wieder nicht klappt und auch sonst hängt der Pc öfter wie bisher. Ist das alles frustrierend...

schrauber 23.10.2012 17:22

Hm, definier ma bitte hängt:

Geht die Maus/Das Keyboard dann noch? Bleibt das Ding komplett stehen, heisst auch ein Cursor der am Blinken war steht?

mädchen 23.10.2012 18:44

Hi,
Maus geht manchmal nicht, oder ist gar nicht da.Aber nur kurz.
Text eingeben ist manchmal überhaupt nicht drin, dann hör ich bei Tastendruck nur bing .Mit dem Cursor ist das so auch schon mal vorgekommen, is aber länger her. Ist öfter so dass gar nichts mehr geht.Und ne Minute später,oder auch länger,funktionierts wieder.Oder beim einschalten stockt das Teil, der Kreisel bei Willkommen steht,läuft wieder, steht wieder usw.

mädchen

schrauber 23.10.2012 18:50

Also:

als erstes sicherst du jetzt mal alle wichtigen Daten auf externen Medien. Ich hab so das Gefühl dass da demnächst was abrauchen könnte.

Wenn das erledigt ist gib mir Bescheid :).

mädchen 23.10.2012 19:00

Och nee!

Abrauchen heißt völlig fratze? Das kann doch nicht wahr sein, das Ding habe ich erst 1,5 Jahre. So talentiert wie ich bin werde ich so meine lieben Schwierigkeiten haben meine Daten woandershin zu verfrachten...

armes mädchen


Ach, das Windows Sicherheitscenter meldet mir seit Windows repair es wäre kein Virenprogramm vorhanden. Avira ist aber nach wie vor da und auch eingeschaltet und Panda active scan habe ich auch noch und Mbam ja auch grade erst installiert. Wer soll das verstehen?

schrauber 23.10.2012 19:03

Das war jetzt der worst case, muss nit sein. aber bevor wir rumprobieren will ich erst deine daten in sicherheit wissen.

Zitat:

So talentiert wie ich bin werde ich so meine lieben Schwierigkeiten haben meine Daten woandershin zu verfrachten...
keine angst, ich bin doch da :). einfach fragen :).

mädchen 23.10.2012 22:37

Hallo und heuuuul,:heulen:
ich krieg einen anne Nerven........ich sitz schon den ganzen Abend am PC und versuche mir meinen Kram auf CDs zu sichern. 3 habe ich geschafft....weil immer und immer wieder das Programm nicht reagiert. Frage (ich soll ja fragen :lach:) : was kann man tun damit es reagiert ???
War nicht ganz ernst gemeint. Ich habe jetzt keine Lust mehr.
Morgen versuche ich es weiter.
Muss ich mit meinen teuer bezahlten Programmen auch irgendwas machen?
Und wenn ja, was?

mädchen:sleepy:

schrauber 24.10.2012 06:28

Die kannst Du dir ganz normal neu installieren falls was abschmiert, nen Lizenzkey solltest Du ja haben. Was für programme sind das?

mädchen 24.10.2012 10:40

Guten Morgen Malware - fighter :),

ich habe drei : Registry Booster, Abelsoft Wash and go, Panda active scan 2.0.
Alles andere sind kostenlose legale Programme Ich wüßte jetzt so auf Anhieb aber nicht wie ich mir die 3 gekauften neu installieren sollte falls sie flöten gehen. Aber du hilfst mir bestimmt dann. Du musst ja ein sehr geduldiger Mensch sein wenn du dich gerne mit Pc Problemen befasst! Das ist ja alles sowas von zeitraubend.
Hatte keine Lust mehr auf die CD Nervereien und habe mir vor gut ner Stunde ne kostenlose box mit 5 GB Onlinespeicher besorgt. Bis jetzt habe ich da noch nicht mal zwei kurze Videos komplett hochladen können! Ist das normal daß das so lang dauert? Da bin ich ja in einer Woche noch nicht fertig.Stöhn. Man kann doch während der PC etwas hochlädt was anderes machen,ne? Oder ist das nicht so gut? Sonst ist mir das zu langweilig.
Es kommt mir Irgendwie so vor als ob die Kiste immer lahmer wird.Bis ne Mail geöffnet ist kann ich in Ruhe eine rauchen.....Und mit der Grafik stimmt auch was nicht.Wenn ich n Fenster verschiebe siehts aus als lägen hundert übereinander.
Ich werde dann mal weiter speichern,
Bis dann

mädchen

schrauber 24.10.2012 10:44

Kommt auf deine Internetleitung, den Speed an. Upload is immer langsam :). Einfacher wäre Stick oder externe Festplatte. Und ja, Du kannst nebenher was andres machen :).

Registry Booster würd ich lassen, damit kann man ganz schnell das System zerschiessen.

mädchen 24.10.2012 10:55

Stick oder Festplatte müßte ich kaufen.Habe aber gähnende Leere im Portemonnaie.
Ich habe zwar noch ein paar Sticks da aber die sind fast voll und ich habe keine Lust das alles durchzusehen ob ich da noch was draufquetschen kann.
Registry Booster is nix? Und ich bezahle auch noch Geld dafür!

Grüße mädchen


Verflixte Kiste!!!!!!!! Upload wurde abgebrochen,Problem aufgetreten. Grrrrrrrrrrrr.
Gibts sonst noch irgendeine Möglichkeit zu speichern? Nee,glaube ich nicht. Ich schmeiss die Kiste am besten aus dem Fenster und nehme meinen alten PC wieder. Aber mit dem hatte ich ähnliche Sorgen

schrauber 24.10.2012 11:01

Locker bleiben :)

Was definierst Du denn als wichtige Daten die gesichert gehören?

mädchen 24.10.2012 11:40

Na ja, diversen Papierkram den man aufheben sollte.Das habe ich weitgehend auch schon auf 5 CDs.Einige Fotos und ein paar kurze Videos von meinem Sohn.Möchte ich als Erinnerung behalten weil er nicht mehr da ist. Und ein paar private Aufzeichnungen die mir lieb und teuer sind.
Habe jetzt den Upload nochmal versucht. Vielleicht klappt es ja jetzt.Zur Not leere ich einen Stick auf den alten PC und mach mir dann die Videos auf den Stick. Aber dann muss ich erst wieder die ganzen Kabel rumstöpseln, die gut versteckt und schlecht zu erreichen sind. Habe ich da ne Lust zu.......

schrauber 24.10.2012 12:35

5 CD´s? Klingt nach ner Menge :). Keine DVD-Rohlinge da?

mädchen 24.10.2012 15:38

Wieviel das schon ist , ist mir beim Speichern auch erst so richtig aufgefallen.
DVDs habe ich da, aber der Pc spielt ja nicht mit. Der formatiert da ne Stunde rum, geht nicht weiter, Programm reagiert nicht. Habe es vorhin noch mal probiert, aber geht einfach nicht und wenn ich den Prozess beende dauert es ewig bis ich weitermachen kann, habe dann nur einen einfarbigen Bildschirm und ne Eieruhr die mich langsam wahnsinig macht! Und der Media Player will auch nicht mehr so richtig, Programm reagiert auch nicht,nebenbei erwähnt.
Ich schmeiß jetzt den alten Pc zum Speichern an.Hoffentlich klappt das jedenfalls problemlos. Bei meinem Glück gibt noch der Stick den Geist auf.Ist mir schon mal passiert das so ein Ding kaputt gegangen ist.

schrauber 24.10.2012 16:28

Versuch mal den Rechner im abgesicherten Modus zu betreiben, vielleicht läuft er da besser.

mädchen 24.10.2012 16:37

So. Alles gespeichert auf dem alten PC und auf einem Stick.Reparatur kann losgehen.
"Abgesicherter Modus" das habe ich ja noch nie gehört. Wo stelle ich das ein?


Systemsteuerung Internetoptionen Sicherheit ? Geschützter Modus ist schon aktiviert.

schrauber 24.10.2012 16:39

Rechner neu starten und schnell paar mal F8 drücken, dann im Auswahlmenü welches erscheint Abgesicherter Modus wählen mit Netzwerktreibern. Mach das mal, läuft er besser?

mädchen 24.10.2012 17:29

Also Fenster verschieben sieht im abgesicherten Modus normal aus. Eine Internetverbindung habe ich in dem Modus nicht bekommen. Ich weiß gar nicht was man da ausprobieren könnte,da geht ja nix. :confused:Fotogalerie geht nicht,Datenträger lesen geht nicht,drucken geht nicht. Habe dann wieder neu gestartet nachdem ich lange meine Schnellstartleiste gesucht habe....und nun bin ich wieder im normalen Modus. Glaube ich jedenfalls.
Mails öffnen geht jetzt fix,im Mailprogramm zwischen den Ordner umschalten geht auch schnell, you tube geht nicht,Texteingabe nach wie vor schwierig.Media Player funktioniert,Lunascape gibt aber manchmal keine Rückmeldung und der Bildschirm hat n Grauschleier.Zwischen den Webseiten wechseln dauert immer noch ziemlich lang,hatte eben dabei ne Eieruhr und keine Rückmeldung.Jetzt versuche ich obwohl nicht mehr nötig mir die videos auf eine Dvd zu brennen...............................und das Progrmm reagiert wieder nicht.
Sag mir mal was ich in welchem Modus ausprobieren soll , damit ich nicht unwissend dir was schreib was du gar nicht brauchst.

mädchen

Das Windows Sicherheitscenter meldet wieder kein Sicherheitsprogramm vorhanden. Was ist das fürn Quatsch? Avira ist an und meldet einen sicheren Computer.

schrauber 25.10.2012 07:03

Mach mal bitte folgendes:

Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!
Downloade dir bitte Combofix vom folgenden Downloadspiegel

Link 1


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.





Downloade dir bitte Farbar's Service Scanner
  • Starte das Tool mit Doppelklick auf die FSS.exe
  • Gehe sicher, dass folgende Optionen angehakt sind.
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Klicke auf Scan.
  • Wenn das Tool fertig ist, wird es eine FSS.txt in dem Verzeichnis erstellen, wo das Tool gelaufen ist.
Poste bitte den Inhalt hier.

mädchen 25.10.2012 14:48

Hi schrauber,


Combofix Logfile:
Code:

ComboFix 12-10-25.01 - pc 25.10.2012  14:56:05.2.4 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.2039.906 [GMT 2:00]
ausgeführt von:: c:\users\pc\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-09-25 bis 2012-10-25  ))))))))))))))))))))))))))))))
.
.
2012-10-25 13:08 . 2012-10-25 13:08        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-10-23 14:53 . 2012-10-23 14:58        --------        d-----w-        c:\windows\system32\catroot2
2012-10-23 14:46 . 2008-05-08 05:03        303616        ----a-w-        C:\SetACL.exe
2012-10-23 14:45 . 2004-06-11 23:33        290304        ----a-w-        C:\subinacl.exe
2012-10-23 14:34 . 2012-10-23 14:34        --------        d-----w-        C:\RegBackup
2012-10-23 13:57 . 2012-10-23 14:51        181064        ----a-w-        c:\windows\PSEXESVC.EXE
2012-10-23 10:22 . 2012-10-23 14:46        --------        d-----w-        C:\Tweaking.com_Windows_Repair_Logs
2012-10-23 10:22 . 2012-10-23 10:22        --------        d-----w-        c:\program files\Tweaking.com
2012-10-23 08:55 . 2012-10-12 05:56        6918632        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{62E5F31D-D69F-4034-AB82-5DEAA6552C29}\mpengine.dll
2012-10-20 07:53 . 2012-10-20 07:53        --------        d-----w-        c:\users\pc\AppData\Roaming\Malwarebytes
2012-10-20 07:53 . 2012-10-20 07:53        --------        d-----w-        c:\programdata\Malwarebytes
2012-10-20 07:53 . 2012-10-20 07:53        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2012-10-20 07:53 . 2012-09-29 17:54        22856        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-10-20 07:12 . 2012-10-20 07:17        --------        d-----w-        c:\program files\DownloadManager
2012-10-20 07:05 . 2012-10-20 07:06        --------        d-----w-        c:\programdata\SweetIM
2012-10-20 07:05 . 2012-10-20 07:06        --------        d-----w-        c:\program files\SweetIM
2012-10-19 07:54 . 2012-10-19 08:38        696760        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-10-18 19:10 . 2012-10-25 13:10        --------        d-----w-        c:\users\pc\AppData\Local\temp
2012-10-18 12:11 . 2012-10-18 12:11        --------        d-----w-        c:\users\pc\AppData\Roaming\Avira
2012-10-18 12:05 . 2012-10-01 15:14        134184        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2012-10-18 12:05 . 2012-09-24 07:58        36552        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2012-10-18 12:05 . 2012-09-13 08:58        83792        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2012-10-18 12:05 . 2012-10-18 12:05        --------        d-----w-        c:\program files\Avira
2012-10-10 12:27 . 2012-06-02 00:02        985088        ----a-w-        c:\windows\system32\crypt32.dll
2012-10-10 12:27 . 2012-06-02 00:02        98304        ----a-w-        c:\windows\system32\cryptnet.dll
2012-10-10 12:27 . 2012-06-02 00:02        133120        ----a-w-        c:\windows\system32\cryptsvc.dll
2012-10-10 12:27 . 2012-08-24 15:53        172544        ----a-w-        c:\windows\system32\wintrust.dll
2012-10-10 12:27 . 2012-09-13 13:28        2048        ----a-w-        c:\windows\system32\tzres.dll
2012-10-10 12:27 . 2012-08-29 11:27        3602816        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2012-10-10 12:27 . 2012-08-29 11:27        3550080        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-10-09 03:10 . 2012-10-09 03:11        --------        d--h--w-        c:\windows\Icons
2012-10-07 10:49 . 2012-10-07 10:48        26984        ----a-w-        c:\windows\system32\drivers\avgtpx86.sys
2012-10-07 10:47 . 2012-10-07 12:38        --------        d-----w-        c:\users\pc\AppData\Roaming\TuneUp Software
2012-10-07 10:46 . 2012-10-07 10:47        --------        d-----w-        c:\programdata\TuneUp Software
2012-10-07 10:46 . 2012-10-07 10:57        --------        d-sh--w-        c:\programdata\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-19 08:38 . 2011-07-02 14:39        73656        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-24 13:32 . 2012-06-25 16:20        477168        ----a-w-        c:\windows\system32\npdeployJava1.dll
2012-09-24 13:32 . 2011-07-02 14:36        473072        ----a-w-        c:\windows\system32\deployJava1.dll
2012-09-13 13:26 . 2012-09-12 10:25        1006448        ----a-w-        c:\windows\system32\dmwu.exe
2012-09-13 13:24 . 2012-09-12 10:25        28160        ----a-w-        c:\windows\system32\ImHttpComm.dll
2012-08-24 06:59 . 2012-09-23 02:15        1800704        ----a-w-        c:\windows\system32\jscript9.dll
2012-08-24 06:51 . 2012-09-23 02:15        1129472        ----a-w-        c:\windows\system32\wininet.dll
2012-08-24 06:51 . 2012-09-23 02:15        1427968        ----a-w-        c:\windows\system32\inetcpl.cpl
2012-08-24 06:47 . 2012-09-23 02:15        142848        ----a-w-        c:\windows\system32\ieUnatt.exe
2012-08-24 06:47 . 2012-09-23 02:15        420864        ----a-w-        c:\windows\system32\vbscript.dll
2012-08-24 06:43 . 2012-09-23 02:15        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2012-07-04 13:03        1310040        ----a-r-        c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2012-07-04 1310040]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12        94208        ----a-w-        c:\users\pc\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12        94208        ----a-w-        c:\users\pc\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12        94208        ----a-w-        c:\users\pc\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"b1gMail-Utility"="c:\program files\MailXXL.com Tools\BMUtil.exe" [2011-07-08 403968]
"RegistryBooster"="c:\program files\Uniblue\RegistryBooster\launcher.exe" [2012-07-08 68000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-25 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-25 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-25 133656]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-07 6139904]
"Netdrive"="c:\program files\NetDrive\netdrive.exe" [2011-10-09 2572800]
"PrintDisp"="c:\windows\system32\PrintDisp.exe" [2011-08-08 828416]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"PDFPrint"="c:\program files\PDF24\pdf24.exe" [2012-09-06 162408]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-09-25 386336]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2012-05-29 115032]
"Sweetpacks Communicator"="c:\program files\SweetIM\Communicator\SweetPacksUpdateManager.exe" [2012-08-15 231768]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896]
.
c:\users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\pc\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-21 02:25        125952        ----a-w-        c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt        REG_MULTI_SZ          hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2012-10-25 c:\windows\Tasks\AbelssoftPreloader.job
- c:\program files\WashAndGo\AbelssoftPreloader.exe [2012-09-01 08:02]
.
2012-10-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-19 08:38]
.
2012-10-25 c:\windows\Tasks\CheckDriveBackgroundGuard.job
- c:\program files\CheckDrive\CheckDriveBackgroundGuard.exe [2012-08-17 09:18]
.
2012-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-25 13:47]
.
2012-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-25 13:47]
.
2012-10-25 c:\windows\Tasks\HP Photo Creations Communicator.job
- c:\programdata\HP Photo Creations\MessageCheck.exe [2011-03-02 10:11]
.
2012-10-25 c:\windows\Tasks\RegistryBooster.job
- c:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2011-12-06 12:39]
.
2012-10-25 c:\windows\Tasks\Schirmfoto.job
- c:\program files\Schirmfoto\schirmfoto.exe [2011-10-08 23:07]
.
2012-10-09 c:\windows\Tasks\WebReg Deskjet F300 series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2006-12-10 20:36]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://home.sweetim.com/?crg=3.1010006.10031&barid={8EAAC8C9-1A84-11E2-AEA6-001E101F3315}
mStart Page = hxxp://home.sweetim.com/?crg=3.1010006.10031&barid={8EAAC8C9-1A84-11E2-AEA6-001E101F3315}
TCP: DhcpNameServer = 193.189.244.225 193.189.244.206
TCP: Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: NameServer = 132.252.3.10,132.252.1.7
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-10-25 15:09
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(1856)
c:\users\pc\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
Zeit der Fertigstellung: 2012-10-25  15:13:42
ComboFix-quarantined-files.txt  2012-10-25 13:13
ComboFix2.txt  2012-10-18 19:10
.
Vor Suchlauf: 10 Verzeichnis(se), 31.684.837.376 Bytes frei
Nach Suchlauf: 11 Verzeichnis(se), 31.712.866.304 Bytes frei
.
- - End Of File - - 83F49B9E1CE28985F4035D6D9C5F9083

--- --- ---


Farbars Service Scanner kann ich nicht downloaden, wird geblockt.Habe es mit beiden Browser ausprobiert.Meldet dass das Programm Schaden anrichten kann.

LG
mädchen

schrauber 25.10.2012 15:44

Wer blockt das? Dein AV oder so kurz abschalten beim Download.

mädchen 26.10.2012 16:22

Hi, nee ist nicht das Antivirenprogramm. Lunascape blockt aus Sicherheitsgründen.Aber das kommt öfter vor,so dass ich dann immer auf den Internet Explorer zum downloaden ausgewichen bin. Aber der will den Download auch nicht.

Gruß, mädchen

schrauber 26.10.2012 17:28

Dann schalt Lunascape ab, das Tool ist sicher.

mädchen 29.10.2012 23:19

Hallo schrauber,

tschuldigung dass ich mich nicht gemeldet hab, aber bin allergiekrank.Morgen ins Krankenhaus, vermutlich für 8-10 Wochen.Kann in der Zeit nix machen.

LG,
mädchen
:heulen:

schrauber 30.10.2012 07:45

Ich geh nit weg :).

Gute Besserung, und meld dich einfach wenn Du wieder da bist :)

mädchen 12.11.2013 21:03

Hi Schrauber,
kennz mich noch? :crazy:

Konnte leider ein paar Monate nicht an den Pc.
Ob Du es glaubst oder nicht,ich bin so nebenbei auf Emsisoft gestoßen und habe prompt damit Trace.File.Media Pipe(A) gefunden.Und auch damit im vierten Versuch gelöscht. Bei den ersten drei Versuche das Ding unter Quarantäne zu stellen blieb das Programm immer stehen. Heute hat dann das Löschen geklappt. Dann habe ich noch den AdwCleaner bemüht.
Aber denkste dass die Kiste nun besser läuft !! Nach wie vor die gleichen Probleme,mal keinen Mausanzeiger,mal hängt der Pc wieder, Programme reagieren nicht und was neu wäre, ist, dass bei jedem Einschalten mein Drucker automatisch neu installiert wird.Und eben war plötzlich für ein paar Minuten kein Eingangssignal mehr da. Tja.
Ich habe meinem PC viel Pflege zukommen lassen,täglich wash and go, defragmentiert und trotzdem will er nicht wie ich.
Magst mir noch mal helfen?

LG,mädchen

schrauber 13.11.2013 10:01

Poste bitte die geforderten FRST logfiles :)

mädchen 13.11.2013 11:49

Guten Morgen Schrauber! Dankeschön für deine Hilfe!

Farbar Service Scanner Version: 10-11-2013
Ran by pc (administrator) on 13-11-2013 at 11:47:06
Running from "C:\Users\pc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5IKIKOP1"
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Other Services:
==============


File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcsvc.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll => MD5 is legit
C:\Windows\system32\qmgr.dll => MD5 is legit
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\system32\ipnathlp.dll => MD5 is legit
C:\Windows\system32\iphlpsvc.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit


**** End of log ****

LG,mädchen

schrauber 14.11.2013 08:51

Das ist aber nicht FRST, sondern FSS, und bitte in Codetags posten :)

mädchen 15.11.2013 05:45

Hallo Schrauber,
da siehst du mal wie wenig ich von dem versteh was ich da mach. Ich schick dir das gerne sobald ich weiß was das ist....erklärst du mir das bitte was du brauchst? Ich habe keine Ahnung was Codetags sind.

Gruß,mädchen:heulen:

Guten Morgen Schrauber,

ich glaub mein Pc gibt den Geist auf. Gestern abend ging fast nichts mehr.Auf das Scrollen hat er nur mit langer Verzögerung oder auch gar nicht reagiert, die Kreuzchen zum Schließen von Seiten wurden nicht mehr angezeigt,das Umschalten zwischen den einzelnen Seiten dauerte ewig,dauernd keine Rückmeldung von Lunascape,keine Reaktion auf anklicken,ganz oft keinen Mausanzeiger mehr,Seiten wurden nur in Bruchstücken angezeigt,Text markieren oder eingeben unmöglich.Das Wash and Go Programm hat 71 Fenster angezeigt.Und : seltsame Geräusche aus dem Pc, ein Mittelding aus Knattern und Brummen.

Klingt nicht gut. Wollte mir schon länger das Windows Programm Fix It runterladen weil es mir die häufigsten Windows Fehler beseitigen kann, aber es tritt immer wieder ein Fehler beim Set up auf. Nun habe ich gelesen dies könne an den Proxyeinstellungen liegen, die müßten dann geändert werden. Wie macht man das ?

Lg,mädchen

schrauber 15.11.2013 18:49

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)




So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

mädchen 15.11.2013 20:30

Hallo Schrauber,
ja....wenn alles richtig ist.
danke für deine Mühe die du dir mit mir machst.


FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-11-2013
Ran by pc (administrator) on PC-PC on 15-11-2013 20:06:45
Running from C:\Users\pc\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\system32\PrintCtrl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\system32\PrintDisp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
() C:\Program Files\Mobile Partner\Mobile Partner.exe
(Uniblue Systems Limited) C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
(Microsoft) C:\Program Files\WashAndGo\WashAndGo.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Lunascape Corporation) C:\Program Files\Lunascape\Lunascape6\Luna.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor)
HKLM\...\Run: [PrintDisp] - C:\Windows\System32\PrintDisp.exe [830464 2012-05-30] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-07-17] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2009-05-25] ()
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - DefaultScope {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 193.189.244.225 193.189.244.206
Tcpip\..\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: [NameServer]132.252.3.10,132.252.1.7

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-17] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-09] (Avira Operations GmbH & Co. KG)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] ()
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [77824 2012-01-20] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
S2 vToolbarUpdater13.0.0;

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [57944 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-08-22] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [26984 2012-10-07] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-07-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-08-19] (Emsisoft GmbH)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; No ImagePath
S3 IpInIp; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-15 20:06 - 2013-11-15 20:08 - 00008390 _____ C:\Users\pc\Desktop\FRST.txt
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-15 20:01 - 2013-11-15 20:02 - 01090529 _____ (Farbar) C:\Users\pc\Desktop\FRST.exe
2013-11-14 17:42 - 2013-10-13 11:42 - 12344832 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 17:42 - 2013-10-13 11:08 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 17:42 - 2013-10-13 10:48 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 17:42 - 2013-10-13 10:37 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 17:42 - 2013-10-13 10:35 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-14 17:42 - 2013-10-13 10:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 17:42 - 2013-10-13 10:33 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-14 17:42 - 2013-10-13 10:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-14 17:42 - 2013-10-13 10:29 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 17:42 - 2013-10-13 10:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-14 17:42 - 2013-10-13 10:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 17:42 - 2013-10-13 10:20 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 16:15 - 2013-10-11 03:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 16:15 - 2013-10-11 03:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 16:15 - 2013-10-11 01:39 - 00218228 _____ C:\Windows\system32\WFP.TMF
2013-11-14 16:15 - 2013-10-03 13:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 16:15 - 2013-10-03 13:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-14 16:04 - 2013-11-15 20:03 - 00096927 _____ C:\Windows\WindowsUpdate.log
2013-11-14 15:59 - 2013-11-14 15:59 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-14 15:59 - 2013-11-14 15:59 - 00001360 _____ C:\Windows\PFRO.log
2013-11-14 07:54 - 2013-11-14 07:54 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-13 11:55 - 2013-11-13 11:55 - 00002397 _____ C:\Users\pc\Desktop\FSS.txt
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 19:05 - 2013-11-12 19:11 - 00000000 ____D C:\AdwCleaner
2013-11-12 17:03 - 2013-11-12 17:04 - 00586560 _____ C:\EamClean.log
2013-11-11 04:06 - 2013-11-11 04:06 - 00000858 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-11-11 04:05 - 2013-11-15 20:04 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 18:02 - 2013-11-12 14:17 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-06 18:02 - 2013-11-11 09:42 - 00000000 ____D C:\ProgramData\Skype
2013-11-06 07:22 - 2013-11-06 07:22 - 00001638 _____ C:\Users\pc\Desktop\AbAlarm.lnk
2013-10-29 09:29 - 2013-11-15 19:48 - 00000294 _____ C:\Windows\Tasks\RegistryBooster.job
2013-10-29 09:29 - 2013-11-15 19:47 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-29 04:57 - 2013-11-12 19:37 - 00000000 ____D C:\Program Files\OXXOGames
2013-10-28 10:48 - 2013-11-13 17:18 - 00000000 ____D C:\Users\pc\Desktop\Neuer Ordner
2013-10-27 19:21 - 2013-10-27 19:21 - 00001862 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 17:06 - 2013-11-15 05:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:30 - 2013-10-27 12:29 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-24 09:44 - 2013-10-30 09:35 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-17 18:48 - 2012-01-23 06:34 - 00905216 _____ (ActMask hxxp://www.all2pdf.com) C:\Windows\system32\SaveTo.dll
2013-10-17 18:48 - 2011-11-13 18:03 - 04067736 _____ (DynaForms GmbH) C:\Windows\system32\CPDF3.dll

==================== One Month Modified Files and Folders =======

2013-11-15 20:08 - 2013-11-15 20:06 - 00008390 _____ C:\Users\pc\Desktop\FRST.txt
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-15 20:04 - 2013-11-11 04:05 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-15 20:03 - 2013-11-14 16:04 - 00096927 _____ C:\Windows\WindowsUpdate.log
2013-11-15 20:02 - 2013-11-15 20:01 - 01090529 _____ (Farbar) C:\Users\pc\Desktop\FRST.exe
2013-11-15 19:50 - 2012-06-07 22:26 - 00000332 _____ C:\Windows\Tasks\HP Photo Creations Communicator.job
2013-11-15 19:48 - 2013-10-29 09:29 - 00000294 _____ C:\Windows\Tasks\RegistryBooster.job
2013-11-15 19:48 - 2012-09-01 19:03 - 00000260 _____ C:\Windows\Tasks\AbelssoftPreloader.job
2013-11-15 19:47 - 2013-10-29 09:29 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-11-15 19:47 - 2013-10-11 11:41 - 00000254 _____ C:\Windows\Tasks\WashAndGoNGBackground.job
2013-11-15 19:47 - 2012-08-17 10:27 - 00000270 _____ C:\Windows\Tasks\CheckDriveBackgroundGuard.job
2013-11-15 19:44 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-15 19:44 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-15 19:44 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-15 19:44 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-11-15 05:48 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-15 05:24 - 2013-10-27 17:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-14 18:08 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-11-14 17:48 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 17:33 - 2013-10-11 10:50 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 17:28 - 2006-11-02 11:24 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-11-14 16:04 - 2006-11-02 11:23 - 00000179 _____ C:\Windows\win.ini
2013-11-14 15:59 - 2013-11-14 15:59 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-14 15:59 - 2013-11-14 15:59 - 00001360 _____ C:\Windows\PFRO.log
2013-11-14 07:54 - 2013-11-14 07:54 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-14 07:18 - 2006-11-02 11:33 - 01559288 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-13 17:18 - 2013-10-28 10:48 - 00000000 ____D C:\Users\pc\Desktop\Neuer Ordner
2013-11-13 11:55 - 2013-11-13 11:55 - 00002397 _____ C:\Users\pc\Desktop\FSS.txt
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Program Files\Google
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 21:20 - 2011-02-25 15:30 - 00000000 ____D C:\Users\pc\AppData\Local\Adobe
2013-11-12 19:37 - 2013-10-29 04:57 - 00000000 ____D C:\Program Files\OXXOGames
2013-11-12 19:11 - 2013-11-12 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-12 19:11 - 2012-07-11 09:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-12 19:10 - 2011-09-16 13:45 - 00000000 ____D C:\ProgramData\Uniblue
2013-11-12 17:04 - 2013-11-12 17:03 - 00586560 _____ C:\EamClean.log
2013-11-12 14:17 - 2013-11-06 18:02 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-11 09:42 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\Skype
2013-11-11 04:06 - 2013-11-11 04:06 - 00000858 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:44 - 2011-05-07 02:20 - 00000000 ____D C:\Users\pc\AppData\Roaming\Dropbox
2013-11-09 17:42 - 2011-05-07 02:25 - 00000000 ___RD C:\Users\pc\Dropbox
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 07:22 - 2013-11-06 07:22 - 00001638 _____ C:\Users\pc\Desktop\AbAlarm.lnk
2013-11-03 20:30 - 2010-10-15 17:12 - 00000000 ____D C:\Users\pc
2013-11-02 08:14 - 2011-10-29 19:03 - 00000000 ____D C:\Windows\CleverPrint
2013-11-02 08:12 - 2011-07-08 16:12 - 00000000 ____D C:\Program Files\MailXXL.com Tools
2013-11-02 08:11 - 2011-07-08 10:51 - 01095982 _____ C:\ndsvc.log
2013-11-02 08:07 - 2012-08-16 09:16 - 00000000 ____D C:\Program Files\Panda Security
2013-10-31 20:33 - 2011-02-05 09:46 - 00000000 ____D C:\Users\pc\Desktop\diverse
2013-10-30 09:35 - 2013-10-24 09:44 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-28 23:09 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public
2013-10-27 19:21 - 2013-10-27 19:21 - 00001862 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 19:20 - 2011-06-29 19:12 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-10-27 19:20 - 2011-02-25 14:50 - 00000000 ____D C:\ProgramData\Adobe
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:29 - 2013-10-27 12:30 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-27 12:29 - 2011-07-02 15:35 - 00000000 ____D C:\Program Files\Java
2013-10-25 20:25 - 2012-07-22 08:55 - 00000000 ____D C:\Users\pc\AppData\Local\Paint.NET
2013-10-24 20:04 - 2011-05-07 02:21 - 00000000 ____D C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-21 00:01 - 2011-05-07 02:25 - 00000920 _____ C:\Users\pc\Desktop\Dropbox.lnk
2013-10-20 23:22 - 2010-10-19 02:53 - 00000000 ____D C:\Users\pc\AppData\Local\Microsoft Games
2013-10-16 21:17 - 2011-04-04 20:27 - 00000000 ____D C:\Users\pc\AppData\Roaming\HpUpdate

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-15 19:52

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-11-2013
Ran by pc (administrator) on PC-PC on 15-11-2013 20:06:45
Running from C:\Users\pc\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\system32\PrintCtrl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\system32\PrintDisp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
() C:\Program Files\Mobile Partner\Mobile Partner.exe
(Uniblue Systems Limited) C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
(Microsoft) C:\Program Files\WashAndGo\WashAndGo.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Lunascape Corporation) C:\Program Files\Lunascape\Lunascape6\Luna.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor)
HKLM\...\Run: [PrintDisp] - C:\Windows\System32\PrintDisp.exe [830464 2012-05-30] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-07-17] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2009-05-25] ()
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - DefaultScope {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 193.189.244.225 193.189.244.206
Tcpip\..\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: [NameServer]132.252.3.10,132.252.1.7

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-17] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-09] (Avira Operations GmbH & Co. KG)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] ()
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [77824 2012-01-20] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
S2 vToolbarUpdater13.0.0;

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [57944 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-08-22] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [26984 2012-10-07] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-07-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-08-19] (Emsisoft GmbH)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; No ImagePath
S3 IpInIp; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-15 20:06 - 2013-11-15 20:08 - 00008390 _____ C:\Users\pc\Desktop\FRST.txt
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-15 20:01 - 2013-11-15 20:02 - 01090529 _____ (Farbar) C:\Users\pc\Desktop\FRST.exe
2013-11-14 17:42 - 2013-10-13 11:42 - 12344832 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 17:42 - 2013-10-13 11:08 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 17:42 - 2013-10-13 10:48 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 17:42 - 2013-10-13 10:37 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 17:42 - 2013-10-13 10:35 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-14 17:42 - 2013-10-13 10:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 17:42 - 2013-10-13 10:33 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-14 17:42 - 2013-10-13 10:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-14 17:42 - 2013-10-13 10:29 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 17:42 - 2013-10-13 10:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-14 17:42 - 2013-10-13 10:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 17:42 - 2013-10-13 10:20 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 16:15 - 2013-10-11 03:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 16:15 - 2013-10-11 03:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 16:15 - 2013-10-11 01:39 - 00218228 _____ C:\Windows\system32\WFP.TMF
2013-11-14 16:15 - 2013-10-03 13:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 16:15 - 2013-10-03 13:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-14 16:04 - 2013-11-15 20:03 - 00096927 _____ C:\Windows\WindowsUpdate.log
2013-11-14 15:59 - 2013-11-14 15:59 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-14 15:59 - 2013-11-14 15:59 - 00001360 _____ C:\Windows\PFRO.log
2013-11-14 07:54 - 2013-11-14 07:54 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-13 11:55 - 2013-11-13 11:55 - 00002397 _____ C:\Users\pc\Desktop\FSS.txt
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 19:05 - 2013-11-12 19:11 - 00000000 ____D C:\AdwCleaner
2013-11-12 17:03 - 2013-11-12 17:04 - 00586560 _____ C:\EamClean.log
2013-11-11 04:06 - 2013-11-11 04:06 - 00000858 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-11-11 04:05 - 2013-11-15 20:04 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 18:02 - 2013-11-12 14:17 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-06 18:02 - 2013-11-11 09:42 - 00000000 ____D C:\ProgramData\Skype
2013-11-06 07:22 - 2013-11-06 07:22 - 00001638 _____ C:\Users\pc\Desktop\AbAlarm.lnk
2013-10-29 09:29 - 2013-11-15 19:48 - 00000294 _____ C:\Windows\Tasks\RegistryBooster.job
2013-10-29 09:29 - 2013-11-15 19:47 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-29 04:57 - 2013-11-12 19:37 - 00000000 ____D C:\Program Files\OXXOGames
2013-10-28 10:48 - 2013-11-13 17:18 - 00000000 ____D C:\Users\pc\Desktop\Neuer Ordner
2013-10-27 19:21 - 2013-10-27 19:21 - 00001862 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 17:06 - 2013-11-15 05:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:30 - 2013-10-27 12:29 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-24 09:44 - 2013-10-30 09:35 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-17 18:48 - 2012-01-23 06:34 - 00905216 _____ (ActMask hxxp://www.all2pdf.com) C:\Windows\system32\SaveTo.dll
2013-10-17 18:48 - 2011-11-13 18:03 - 04067736 _____ (DynaForms GmbH) C:\Windows\system32\CPDF3.dll

==================== One Month Modified Files and Folders =======

2013-11-15 20:08 - 2013-11-15 20:06 - 00008390 _____ C:\Users\pc\Desktop\FRST.txt
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-15 20:04 - 2013-11-11 04:05 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-15 20:03 - 2013-11-14 16:04 - 00096927 _____ C:\Windows\WindowsUpdate.log
2013-11-15 20:02 - 2013-11-15 20:01 - 01090529 _____ (Farbar) C:\Users\pc\Desktop\FRST.exe
2013-11-15 19:50 - 2012-06-07 22:26 - 00000332 _____ C:\Windows\Tasks\HP Photo Creations Communicator.job
2013-11-15 19:48 - 2013-10-29 09:29 - 00000294 _____ C:\Windows\Tasks\RegistryBooster.job
2013-11-15 19:48 - 2012-09-01 19:03 - 00000260 _____ C:\Windows\Tasks\AbelssoftPreloader.job
2013-11-15 19:47 - 2013-10-29 09:29 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-11-15 19:47 - 2013-10-11 11:41 - 00000254 _____ C:\Windows\Tasks\WashAndGoNGBackground.job
2013-11-15 19:47 - 2012-08-17 10:27 - 00000270 _____ C:\Windows\Tasks\CheckDriveBackgroundGuard.job
2013-11-15 19:44 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-15 19:44 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-15 19:44 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-15 19:44 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-11-15 05:48 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-15 05:24 - 2013-10-27 17:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-14 18:08 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-11-14 17:48 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 17:33 - 2013-10-11 10:50 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 17:28 - 2006-11-02 11:24 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-11-14 16:04 - 2006-11-02 11:23 - 00000179 _____ C:\Windows\win.ini
2013-11-14 15:59 - 2013-11-14 15:59 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-14 15:59 - 2013-11-14 15:59 - 00001360 _____ C:\Windows\PFRO.log
2013-11-14 07:54 - 2013-11-14 07:54 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-14 07:18 - 2006-11-02 11:33 - 01559288 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-13 17:18 - 2013-10-28 10:48 - 00000000 ____D C:\Users\pc\Desktop\Neuer Ordner
2013-11-13 11:55 - 2013-11-13 11:55 - 00002397 _____ C:\Users\pc\Desktop\FSS.txt
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Program Files\Google
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 21:20 - 2011-02-25 15:30 - 00000000 ____D C:\Users\pc\AppData\Local\Adobe
2013-11-12 19:37 - 2013-10-29 04:57 - 00000000 ____D C:\Program Files\OXXOGames
2013-11-12 19:11 - 2013-11-12 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-12 19:11 - 2012-07-11 09:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-12 19:10 - 2011-09-16 13:45 - 00000000 ____D C:\ProgramData\Uniblue
2013-11-12 17:04 - 2013-11-12 17:03 - 00586560 _____ C:\EamClean.log
2013-11-12 14:17 - 2013-11-06 18:02 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-11 09:42 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\Skype
2013-11-11 04:06 - 2013-11-11 04:06 - 00000858 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:44 - 2011-05-07 02:20 - 00000000 ____D C:\Users\pc\AppData\Roaming\Dropbox
2013-11-09 17:42 - 2011-05-07 02:25 - 00000000 ___RD C:\Users\pc\Dropbox
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 07:22 - 2013-11-06 07:22 - 00001638 _____ C:\Users\pc\Desktop\AbAlarm.lnk
2013-11-03 20:30 - 2010-10-15 17:12 - 00000000 ____D C:\Users\pc
2013-11-02 08:14 - 2011-10-29 19:03 - 00000000 ____D C:\Windows\CleverPrint
2013-11-02 08:12 - 2011-07-08 16:12 - 00000000 ____D C:\Program Files\MailXXL.com Tools
2013-11-02 08:11 - 2011-07-08 10:51 - 01095982 _____ C:\ndsvc.log
2013-11-02 08:07 - 2012-08-16 09:16 - 00000000 ____D C:\Program Files\Panda Security
2013-10-31 20:33 - 2011-02-05 09:46 - 00000000 ____D C:\Users\pc\Desktop\diverse
2013-10-30 09:35 - 2013-10-24 09:44 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-28 23:09 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public
2013-10-27 19:21 - 2013-10-27 19:21 - 00001862 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 19:20 - 2011-06-29 19:12 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-10-27 19:20 - 2011-02-25 14:50 - 00000000 ____D C:\ProgramData\Adobe
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:29 - 2013-10-27 12:30 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-27 12:29 - 2011-07-02 15:35 - 00000000 ____D C:\Program Files\Java
2013-10-25 20:25 - 2012-07-22 08:55 - 00000000 ____D C:\Users\pc\AppData\Local\Paint.NET
2013-10-24 20:04 - 2011-05-07 02:21 - 00000000 ____D C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-21 00:01 - 2011-05-07 02:25 - 00000920 _____ C:\Users\pc\Desktop\Dropbox.lnk
2013-10-20 23:22 - 2010-10-19 02:53 - 00000000 ____D C:\Users\pc\AppData\Local\Microsoft Games
2013-10-16 21:17 - 2011-04-04 20:27 - 00000000 ____D C:\Users\pc\AppData\Roaming\HpUpdate

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-15 19:52

==================== End Of Log ============================

--- --- ---

--- --- ---




--- --- ---
Das andere Ding kommt gleich noch.
lg

Code:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 14-11-2013
Ran by pc at 2013-11-15 20:09:22
Running from C:\Users\pc\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Emsisoft Anti-Malware (Enabled - Out of date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Anti-Malware (Enabled - Out of date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}

==================== Installed Programs ======================

32 Bit HP CIO Components Installer (Version: 1.0.0)
AbAlarm (Version: 6.2)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8)
AIO_CDB_ProductContext (Version: 82.0.242.000)
AIO_CDB_Software (Version: 82.0.242.000)
AIO_Scan (Version: 82.0.173.000)
Atheros Client Installation Program (Version: 7.0)
Avira Free Antivirus (Version: 13.0.0.4052)
BufferChm (Version: 82.0.173.000)
Cisco EAP-FAST Module (Version: 2.1.6)
Cisco LEAP Module (Version: 1.0.12)
Cisco PEAP Module (Version: 1.0.13)
Copy (Version: 82.0.188.000)
CustomerResearchQFolder (Version: 1.00.0000)
Destinations (Version: 82.0.173.000)
DeviceManagementQFolder (Version: 1.00.0000)
DocProc (Version: 8.1.0.0)
DocProcQFolder (Version: 1.00.0000)
Dropbox (HKCU Version: 2.0.22)
Emsisoft Anti-Malware (Version: 8.1)
ESET Online Scanner v3
eSupportQFolder (Version: 1.00.0000)
F300 (Version: 82.0.242.000)
F300_Help (Version: 82.0.242.000)
F300Trb (Version: 82.0.242.000)
Fax (Version: 82.0.188.000)
Google Earth (Version: 6.2.2.6613)
HP Customer Participation Program 8.0 (Version: 8.0)
HP Imaging Device Functions 8.0 (Version: 8.0)
HP OCR Software 8.0 (Version: 8.0)
HP Photo Creations (Version: 1.0.0.7702)
HP Photosmart Essential (Version: 1.12.0.46)
HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B (Version: 8.0)
HP Solution Center 8.0 (Version: 8.0)
HP Update (Version: 5.002.007.004)
HPProductAssistant (Version: 82.0.173.000)
HPSSupply (Version: 2.1.3.0000)
Intel(R) Graphics Media Accelerator Driver
Java 7 Update 45 (Version: 7.0.450)
Java Auto Updater (Version: 2.1.9.8)
Lunascape6 (All Users) (Version: 6.8.9.27075)
MarketResearch (Version: 82.0.174.000)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mobile Partner (Version: 11.302.09.04.382)
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MyKeyFinder (Version: 2012)
Paint.NET v3.5.10 (Version: 3.60.0)
Realtek 8169 8168 8101E 8102E Ethernet Driver (Version: 1.00.0000)
Realtek High Definition Audio Driver (Version: 6.0.1.5618)
Scan (Version: 8.1.0.0)
SolutionCenter (Version: 82.0.188.000)
Status (Version: 82.0.173.000)
Toolbox (Version: 82.0.173.000)
TrayApp (Version: 82.0.188.000)
Uniblue RegistryBooster (Version: 6.1.1.3)
UnloadSupport (Version: 1.00.0000)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (Version: 3)
Visual C++ 9.0 CRT (x86) WinSXS MSM (Version: 9.0)
WashAndGo (Version: 17.7)
WebReg (Version: 82.0.173.000)
YouTube Song Downloader (Version: 8.2)

==================== Restore Points  =========================

13-11-2013 08:36:23 Removed Apple Software Update
13-11-2013 08:48:09 Removed Bonjour
13-11-2013 10:21:05 Removed Safari
13-11-2013 10:23:53 Removed Apple Application Support
13-11-2013 10:31:48 Removed Apple Application Support
14-11-2013 16:26:44 Windows Update

==================== Hosts content: ==========================

2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost
::1            localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0AD797DB-679C-4254-BF1F-187451269FBE} - System32\Tasks\RunAsStdUser Task => C:\Program Files\NetDrive\netdrive.exe
Task: {0B923855-EFEC-4D6E-BF2C-25DC4D5D10FF} - System32\Tasks\WebReg Deskjet F300 series => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe [2006-12-10] (Hewlett-Packard Co.)
Task: {139DBA5E-5972-4876-81F7-3862E17F0935} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2008-01-21] (Microsoft Corporation)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {2A4342E7-3E82-45C5-A530-C547532D3E76} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - pc => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {2DE1ED62-3B3F-4610-86ED-E838057F6213} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {47CC68FF-DD27-4AC9-BD10-1206F7305F4A} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {51C71A63-7357-4492-80C2-B8A4B3E96899} - System32\Tasks\AbelssoftPreloader => C:\Program Files\WashAndGo\AbelssoftPreloader.exe [2012-09-24] (Microsoft)
Task: {5DF25F26-1DD4-42AF-A7D5-8AF413AA526D} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => C:\Program Files\Windows Defender\MpCmdRun.exe [2008-01-21] (Microsoft Corporation)
Task: {724DD079-074D-48F7-84FC-129CAE9457D2} - System32\Tasks\rbmonitor => C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe [2013-08-21] (Uniblue Systems Limited)
Task: {75C473BC-8CAD-499B-8316-EFD367B24770} - System32\Tasks\WashAndGoNGBackground => C:\Program Files\WashAndGo\WashAndGo.exe [2012-09-24] (Microsoft)
Task: {793C7D04-E0F7-41B2-9376-BCB3BC77411B} - System32\Tasks\CheckDriveBackgroundGuard => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: {8CFE559A-52BC-433E-B3B9-E2296815C970} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-27] (Adobe Systems Incorporated)
Task: {99982336-9432-499D-A415-B1D0E9EE6E6A} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [2006-12-10] (Hewlett-Packard Co.)
Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => C:\Windows\System32\pla.dll [2008-01-21] (Microsoft Corporation)
Task: {A7F9AF08-9C24-4D9D-A77B-6C6A29823CB3} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-12] (Microsoft Corporation)
Task: {CC5A7CB0-4962-4392-8465-2DA2116D2672} - System32\Tasks\RegistryBooster => C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe [2013-08-21] (Uniblue Systems Limited)
Task: {DC45E898-AF81-4A07-ABC9-73FCDB16504C} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-03-02] ()
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: C:\Windows\Tasks\AbelssoftPreloader.job => C:\Program Files\WashAndGo\AbelssoftPreloader.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\CheckDriveBackgroundGuard.job => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe
Task: C:\Windows\Tasks\rbmonitor.job => C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
Task: C:\Windows\Tasks\RegistryBooster.job => C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
Task: C:\Windows\Tasks\WashAndGoNGBackground.job => C:\Program Files\WashAndGo\WashAndGo.exe
Task: C:\Windows\Tasks\WebReg Deskjet F300 series.job => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe

==================== Loaded Modules (whitelisted) =============

2011-06-27 15:24 - 2007-08-23 15:39 - 00014848 _____ () C:\Program Files\Mobile Partner\isaputrace.dll
2011-06-27 15:24 - 2009-12-10 10:51 - 00114688 _____ () C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll
2011-06-27 15:24 - 2009-09-19 10:21 - 00139264 _____ () C:\Program Files\Mobile Partner\NetInfoPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:48 - 00090112 _____ () C:\Program Files\Mobile Partner\DialUpPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:54 - 00057344 _____ () C:\Program Files\Mobile Partner\ConfigFilePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:40 - 00991232 _____ () C:\Program Files\Mobile Partner\NDISAPI.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00155648 _____ () C:\Program Files\Mobile Partner\DetectDev.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00557056 _____ () C:\Program Files\Mobile Partner\atcomm.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\XCodec.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\DeviceOperate.dll
2011-06-27 15:24 - 2009-06-18 09:56 - 00032768 _____ () C:\Program Files\Mobile Partner\NotifyServicePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:52 - 00192512 _____ () C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00143360 _____ () C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll
2011-06-27 15:24 - 2007-07-31 14:50 - 00090112 _____ () C:\Program Files\Mobile Partner\FileManager.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00159744 _____ () C:\Program Files\Mobile Partner\SMSPlugin.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00201640 _____ () C:\Program Files\Java\jre7\bin\jp2iexp.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00016808 _____ () C:\Program Files\Java\jre7\bin\jp2native.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service) (User: )
Description: Die Anwendung kann nicht initialisiert werden.

Kontext: Windows Anwendung


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service) (User: )
Description: Das Gatherer-Objekt kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service) (User: )
Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Element nicht gefunden.  (0x80070490)

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service) (User: )
Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service) (User: )
Description: Die Eigenschaftenspeicherdaten können vom Windows-Suchdienst nicht geladen werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        0x%08x (0xc0041800 - Der Inhaltsindex kann nicht gelesen werden.  )

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service) (User: )
Description: Der Suchdienst hat beschädigte Datendateien im Index erkannt. Der Dienst versucht, dieses Problem durch Neuerstellung des Index automatisch zu beheben.


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:04 PM) (Source: Windows Search Service) (User: )
Description: Der Jet-Eigenschaftenspeicher kann vom Windows-Suchdienst nicht geöffnet werden.


Details:
        Der Inhaltsindex kann nicht gelesen werden.  (0xc0041800)

Error: (11/14/2013 04:00:04 PM) (Source: ESENT) (User: )
Description: Windows (2112) Windows: Fehler -1811 (0xfffff8ed) beim Öffnen von Protokolldatei C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.


System errors:
=============
Error: (11/15/2013 07:48:14 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (11/15/2013 07:45:40 PM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (11/15/2013 07:45:40 PM) (Source: Service Control Manager) (User: )
Description: Net.Tcp-ListeneradapterNet.Tcp-Portfreigabedienst%%1058

Error: (11/15/2013 07:45:40 PM) (Source: Service Control Manager) (User: )
Description: Net.Pipe-Listeneradapterwas

Error: (11/15/2013 07:45:40 PM) (Source: Service Control Manager) (User: )
Description: Net.Msmq-Listeneradaptermsmq

Error: (11/15/2013 05:15:53 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (11/15/2013 05:12:31 AM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (11/15/2013 05:12:31 AM) (Source: Service Control Manager) (User: )
Description: Net.Tcp-ListeneradapterNet.Tcp-Portfreigabedienst%%1058

Error: (11/15/2013 05:12:31 AM) (Source: Service Control Manager) (User: )
Description: Net.Pipe-Listeneradapterwas

Error: (11/15/2013 05:12:31 AM) (Source: Service Control Manager) (User: )
Description: Net.Msmq-Listeneradaptermsmq


Microsoft Office Sessions:
=========================
Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Element nicht gefunden.  (0x80070490)
Search.TripoliIndexer

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)
Search.JetPropStore

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        0x%08x (0xc0041800 - Der Inhaltsindex kann nicht gelesen werden.  )

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service)(User: )
Description:
Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:04 PM) (Source: Windows Search Service)(User: )
Description:
Details:
        Der Inhaltsindex kann nicht gelesen werden.  (0xc0041800)

Error: (11/14/2013 04:00:04 PM) (Source: ESENT)(User: )
Description: Windows2112Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log-1811 (0xfffff8ed)


CodeIntegrity Errors:
===================================
  Date: 2012-10-20 17:13:05.162
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:04.538
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:03.883
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:03.259
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:02.635
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:02.011
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:01.324
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_b38d4a937f96be60\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:00.700
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_b38d4a937f96be60\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:00.061
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_b38d4a937f96be60\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:12:59.437
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_b38d4a937f96be60\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 51%
Total physical RAM: 2038.64 MB
Available physical RAM: 997.35 MB
Total Pagefile: 4326.32 MB
Available Pagefile: 2293.53 MB
Total Virtual: 2047.88 MB
Available Virtual: 1911.21 MB

==================== Drives ================================

Drive c: (OS_Install) (Fixed) (Total:63.48 GB) (Free:33.84 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Mobile Partner) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS
Drive e: (Data) (Fixed) (Total:387.63 GB) (Free:359 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 9AC9B968)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=63 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=388 GB) - (Type=07 NTFS)

==================== End Of Log ============================Additional scan result of Farbar Recovery Scan Tool (x86) Version: 14-11-2013
Ran by pc at 2013-11-15 20:09:22
Running from C:\Users\pc\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Emsisoft Anti-Malware (Enabled - Out of date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Anti-Malware (Enabled - Out of date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}

==================== Installed Programs ======================

32 Bit HP CIO Components Installer (Version: 1.0.0)
AbAlarm (Version: 6.2)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8)
AIO_CDB_ProductContext (Version: 82.0.242.000)
AIO_CDB_Software (Version: 82.0.242.000)
AIO_Scan (Version: 82.0.173.000)
Atheros Client Installation Program (Version: 7.0)
Avira Free Antivirus (Version: 13.0.0.4052)
BufferChm (Version: 82.0.173.000)
Cisco EAP-FAST Module (Version: 2.1.6)
Cisco LEAP Module (Version: 1.0.12)
Cisco PEAP Module (Version: 1.0.13)
Copy (Version: 82.0.188.000)
CustomerResearchQFolder (Version: 1.00.0000)
Destinations (Version: 82.0.173.000)
DeviceManagementQFolder (Version: 1.00.0000)
DocProc (Version: 8.1.0.0)
DocProcQFolder (Version: 1.00.0000)
Dropbox (HKCU Version: 2.0.22)
Emsisoft Anti-Malware (Version: 8.1)
ESET Online Scanner v3
eSupportQFolder (Version: 1.00.0000)
F300 (Version: 82.0.242.000)
F300_Help (Version: 82.0.242.000)
F300Trb (Version: 82.0.242.000)
Fax (Version: 82.0.188.000)
Google Earth (Version: 6.2.2.6613)
HP Customer Participation Program 8.0 (Version: 8.0)
HP Imaging Device Functions 8.0 (Version: 8.0)
HP OCR Software 8.0 (Version: 8.0)
HP Photo Creations (Version: 1.0.0.7702)
HP Photosmart Essential (Version: 1.12.0.46)
HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B (Version: 8.0)
HP Solution Center 8.0 (Version: 8.0)
HP Update (Version: 5.002.007.004)
HPProductAssistant (Version: 82.0.173.000)
HPSSupply (Version: 2.1.3.0000)
Intel(R) Graphics Media Accelerator Driver
Java 7 Update 45 (Version: 7.0.450)
Java Auto Updater (Version: 2.1.9.8)
Lunascape6 (All Users) (Version: 6.8.9.27075)
MarketResearch (Version: 82.0.174.000)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mobile Partner (Version: 11.302.09.04.382)
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MyKeyFinder (Version: 2012)
Paint.NET v3.5.10 (Version: 3.60.0)
Realtek 8169 8168 8101E 8102E Ethernet Driver (Version: 1.00.0000)
Realtek High Definition Audio Driver (Version: 6.0.1.5618)
Scan (Version: 8.1.0.0)
SolutionCenter (Version: 82.0.188.000)
Status (Version: 82.0.173.000)
Toolbox (Version: 82.0.173.000)
TrayApp (Version: 82.0.188.000)
Uniblue RegistryBooster (Version: 6.1.1.3)
UnloadSupport (Version: 1.00.0000)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (Version: 3)
Visual C++ 9.0 CRT (x86) WinSXS MSM (Version: 9.0)
WashAndGo (Version: 17.7)
WebReg (Version: 82.0.173.000)
YouTube Song Downloader (Version: 8.2)

==================== Restore Points  =========================

13-11-2013 08:36:23 Removed Apple Software Update
13-11-2013 08:48:09 Removed Bonjour
13-11-2013 10:21:05 Removed Safari
13-11-2013 10:23:53 Removed Apple Application Support
13-11-2013 10:31:48 Removed Apple Application Support
14-11-2013 16:26:44 Windows Update

==================== Hosts content: ==========================

2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost
::1            localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0AD797DB-679C-4254-BF1F-187451269FBE} - System32\Tasks\RunAsStdUser Task => C:\Program Files\NetDrive\netdrive.exe
Task: {0B923855-EFEC-4D6E-BF2C-25DC4D5D10FF} - System32\Tasks\WebReg Deskjet F300 series => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe [2006-12-10] (Hewlett-Packard Co.)
Task: {139DBA5E-5972-4876-81F7-3862E17F0935} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2008-01-21] (Microsoft Corporation)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {2A4342E7-3E82-45C5-A530-C547532D3E76} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - pc => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {2DE1ED62-3B3F-4610-86ED-E838057F6213} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {47CC68FF-DD27-4AC9-BD10-1206F7305F4A} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {51C71A63-7357-4492-80C2-B8A4B3E96899} - System32\Tasks\AbelssoftPreloader => C:\Program Files\WashAndGo\AbelssoftPreloader.exe [2012-09-24] (Microsoft)
Task: {5DF25F26-1DD4-42AF-A7D5-8AF413AA526D} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => C:\Program Files\Windows Defender\MpCmdRun.exe [2008-01-21] (Microsoft Corporation)
Task: {724DD079-074D-48F7-84FC-129CAE9457D2} - System32\Tasks\rbmonitor => C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe [2013-08-21] (Uniblue Systems Limited)
Task: {75C473BC-8CAD-499B-8316-EFD367B24770} - System32\Tasks\WashAndGoNGBackground => C:\Program Files\WashAndGo\WashAndGo.exe [2012-09-24] (Microsoft)
Task: {793C7D04-E0F7-41B2-9376-BCB3BC77411B} - System32\Tasks\CheckDriveBackgroundGuard => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: {8CFE559A-52BC-433E-B3B9-E2296815C970} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-27] (Adobe Systems Incorporated)
Task: {99982336-9432-499D-A415-B1D0E9EE6E6A} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [2006-12-10] (Hewlett-Packard Co.)
Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => C:\Windows\System32\pla.dll [2008-01-21] (Microsoft Corporation)
Task: {A7F9AF08-9C24-4D9D-A77B-6C6A29823CB3} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-12] (Microsoft Corporation)
Task: {CC5A7CB0-4962-4392-8465-2DA2116D2672} - System32\Tasks\RegistryBooster => C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe [2013-08-21] (Uniblue Systems Limited)
Task: {DC45E898-AF81-4A07-ABC9-73FCDB16504C} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-03-02] ()
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: C:\Windows\Tasks\AbelssoftPreloader.job => C:\Program Files\WashAndGo\AbelssoftPreloader.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\CheckDriveBackgroundGuard.job => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe
Task: C:\Windows\Tasks\rbmonitor.job => C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
Task: C:\Windows\Tasks\RegistryBooster.job => C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
Task: C:\Windows\Tasks\WashAndGoNGBackground.job => C:\Program Files\WashAndGo\WashAndGo.exe
Task: C:\Windows\Tasks\WebReg Deskjet F300 series.job => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe

==================== Loaded Modules (whitelisted) =============

2011-06-27 15:24 - 2007-08-23 15:39 - 00014848 _____ () C:\Program Files\Mobile Partner\isaputrace.dll
2011-06-27 15:24 - 2009-12-10 10:51 - 00114688 _____ () C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll
2011-06-27 15:24 - 2009-09-19 10:21 - 00139264 _____ () C:\Program Files\Mobile Partner\NetInfoPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:48 - 00090112 _____ () C:\Program Files\Mobile Partner\DialUpPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:54 - 00057344 _____ () C:\Program Files\Mobile Partner\ConfigFilePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:40 - 00991232 _____ () C:\Program Files\Mobile Partner\NDISAPI.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00155648 _____ () C:\Program Files\Mobile Partner\DetectDev.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00557056 _____ () C:\Program Files\Mobile Partner\atcomm.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\XCodec.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\DeviceOperate.dll
2011-06-27 15:24 - 2009-06-18 09:56 - 00032768 _____ () C:\Program Files\Mobile Partner\NotifyServicePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:52 - 00192512 _____ () C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00143360 _____ () C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll
2011-06-27 15:24 - 2007-07-31 14:50 - 00090112 _____ () C:\Program Files\Mobile Partner\FileManager.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00159744 _____ () C:\Program Files\Mobile Partner\SMSPlugin.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00201640 _____ () C:\Program Files\Java\jre7\bin\jp2iexp.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00016808 _____ () C:\Program Files\Java\jre7\bin\jp2native.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service) (User: )
Description: Die Anwendung kann nicht initialisiert werden.

Kontext: Windows Anwendung


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service) (User: )
Description: Das Gatherer-Objekt kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service) (User: )
Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Element nicht gefunden.  (0x80070490)

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service) (User: )
Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service) (User: )
Description: Die Eigenschaftenspeicherdaten können vom Windows-Suchdienst nicht geladen werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        0x%08x (0xc0041800 - Der Inhaltsindex kann nicht gelesen werden.  )

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service) (User: )
Description: Der Suchdienst hat beschädigte Datendateien im Index erkannt. Der Dienst versucht, dieses Problem durch Neuerstellung des Index automatisch zu beheben.


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:04 PM) (Source: Windows Search Service) (User: )
Description: Der Jet-Eigenschaftenspeicher kann vom Windows-Suchdienst nicht geöffnet werden.


Details:
        Der Inhaltsindex kann nicht gelesen werden.  (0xc0041800)

Error: (11/14/2013 04:00:04 PM) (Source: ESENT) (User: )
Description: Windows (2112) Windows: Fehler -1811 (0xfffff8ed) beim Öffnen von Protokolldatei C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.


System errors:
=============
Error: (11/15/2013 07:48:14 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (11/15/2013 07:45:40 PM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (11/15/2013 07:45:40 PM) (Source: Service Control Manager) (User: )
Description: Net.Tcp-ListeneradapterNet.Tcp-Portfreigabedienst%%1058

Error: (11/15/2013 07:45:40 PM) (Source: Service Control Manager) (User: )
Description: Net.Pipe-Listeneradapterwas

Error: (11/15/2013 07:45:40 PM) (Source: Service Control Manager) (User: )
Description: Net.Msmq-Listeneradaptermsmq

Error: (11/15/2013 05:15:53 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (11/15/2013 05:12:31 AM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (11/15/2013 05:12:31 AM) (Source: Service Control Manager) (User: )
Description: Net.Tcp-ListeneradapterNet.Tcp-Portfreigabedienst%%1058

Error: (11/15/2013 05:12:31 AM) (Source: Service Control Manager) (User: )
Description: Net.Pipe-Listeneradapterwas

Error: (11/15/2013 05:12:31 AM) (Source: Service Control Manager) (User: )
Description: Net.Msmq-Listeneradaptermsmq


Microsoft Office Sessions:
=========================
Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Element nicht gefunden.  (0x80070490)
Search.TripoliIndexer

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)
Search.JetPropStore

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        0x%08x (0xc0041800 - Der Inhaltsindex kann nicht gelesen werden.  )

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service)(User: )
Description:
Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:04 PM) (Source: Windows Search Service)(User: )
Description:
Details:
        Der Inhaltsindex kann nicht gelesen werden.  (0xc0041800)

Error: (11/14/2013 04:00:04 PM) (Source: ESENT)(User: )
Description: Windows2112Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log-1811 (0xfffff8ed)


CodeIntegrity Errors:
===================================
  Date: 2012-10-20 17:13:05.162
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:04.538
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:03.883
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:03.259
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:02.635
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:02.011
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:01.324
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_b38d4a937f96be60\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:00.700
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_b38d4a937f96be60\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:00.061
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_b38d4a937f96be60\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:12:59.437
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_b38d4a937f96be60\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 51%
Total physical RAM: 2038.64 MB
Available physical RAM: 997.35 MB
Total Pagefile: 4326.32 MB
Available Pagefile: 2293.53 MB
Total Virtual: 2047.88 MB
Available Virtual: 1911.21 MB

==================== Drives ================================

Drive c: (OS_Install) (Fixed) (Total:63.48 GB) (Free:33.84 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Mobile Partner) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS
Drive e: (Data) (Fixed) (Total:387.63 GB) (Free:359 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 9AC9B968)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=63 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=388 GB) - (Type=07 NTFS)

==================== End Of Log ============================Additional scan result of Farbar Recovery Scan Tool (x86) Version: 14-11-2013
Ran by pc at 2013-11-15 20:09:22
Running from C:\Users\pc\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Emsisoft Anti-Malware (Enabled - Out of date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Anti-Malware (Enabled - Out of date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}

==================== Installed Programs ======================

32 Bit HP CIO Components Installer (Version: 1.0.0)
AbAlarm (Version: 6.2)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8)
AIO_CDB_ProductContext (Version: 82.0.242.000)
AIO_CDB_Software (Version: 82.0.242.000)
AIO_Scan (Version: 82.0.173.000)
Atheros Client Installation Program (Version: 7.0)
Avira Free Antivirus (Version: 13.0.0.4052)
BufferChm (Version: 82.0.173.000)
Cisco EAP-FAST Module (Version: 2.1.6)
Cisco LEAP Module (Version: 1.0.12)
Cisco PEAP Module (Version: 1.0.13)
Copy (Version: 82.0.188.000)
CustomerResearchQFolder (Version: 1.00.0000)
Destinations (Version: 82.0.173.000)
DeviceManagementQFolder (Version: 1.00.0000)
DocProc (Version: 8.1.0.0)
DocProcQFolder (Version: 1.00.0000)
Dropbox (HKCU Version: 2.0.22)
Emsisoft Anti-Malware (Version: 8.1)
ESET Online Scanner v3
eSupportQFolder (Version: 1.00.0000)
F300 (Version: 82.0.242.000)
F300_Help (Version: 82.0.242.000)
F300Trb (Version: 82.0.242.000)
Fax (Version: 82.0.188.000)
Google Earth (Version: 6.2.2.6613)
HP Customer Participation Program 8.0 (Version: 8.0)
HP Imaging Device Functions 8.0 (Version: 8.0)
HP OCR Software 8.0 (Version: 8.0)
HP Photo Creations (Version: 1.0.0.7702)
HP Photosmart Essential (Version: 1.12.0.46)
HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B (Version: 8.0)
HP Solution Center 8.0 (Version: 8.0)
HP Update (Version: 5.002.007.004)
HPProductAssistant (Version: 82.0.173.000)
HPSSupply (Version: 2.1.3.0000)
Intel(R) Graphics Media Accelerator Driver
Java 7 Update 45 (Version: 7.0.450)
Java Auto Updater (Version: 2.1.9.8)
Lunascape6 (All Users) (Version: 6.8.9.27075)
MarketResearch (Version: 82.0.174.000)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mobile Partner (Version: 11.302.09.04.382)
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MyKeyFinder (Version: 2012)
Paint.NET v3.5.10 (Version: 3.60.0)
Realtek 8169 8168 8101E 8102E Ethernet Driver (Version: 1.00.0000)
Realtek High Definition Audio Driver (Version: 6.0.1.5618)
Scan (Version: 8.1.0.0)
SolutionCenter (Version: 82.0.188.000)
Status (Version: 82.0.173.000)
Toolbox (Version: 82.0.173.000)
TrayApp (Version: 82.0.188.000)
Uniblue RegistryBooster (Version: 6.1.1.3)
UnloadSupport (Version: 1.00.0000)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (Version: 3)
Visual C++ 9.0 CRT (x86) WinSXS MSM (Version: 9.0)
WashAndGo (Version: 17.7)
WebReg (Version: 82.0.173.000)
YouTube Song Downloader (Version: 8.2)

==================== Restore Points  =========================

13-11-2013 08:36:23 Removed Apple Software Update
13-11-2013 08:48:09 Removed Bonjour
13-11-2013 10:21:05 Removed Safari
13-11-2013 10:23:53 Removed Apple Application Support
13-11-2013 10:31:48 Removed Apple Application Support
14-11-2013 16:26:44 Windows Update

==================== Hosts content: ==========================

2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost
::1            localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0AD797DB-679C-4254-BF1F-187451269FBE} - System32\Tasks\RunAsStdUser Task => C:\Program Files\NetDrive\netdrive.exe
Task: {0B923855-EFEC-4D6E-BF2C-25DC4D5D10FF} - System32\Tasks\WebReg Deskjet F300 series => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe [2006-12-10] (Hewlett-Packard Co.)
Task: {139DBA5E-5972-4876-81F7-3862E17F0935} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2008-01-21] (Microsoft Corporation)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {2A4342E7-3E82-45C5-A530-C547532D3E76} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - pc => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {2DE1ED62-3B3F-4610-86ED-E838057F6213} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {47CC68FF-DD27-4AC9-BD10-1206F7305F4A} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {51C71A63-7357-4492-80C2-B8A4B3E96899} - System32\Tasks\AbelssoftPreloader => C:\Program Files\WashAndGo\AbelssoftPreloader.exe [2012-09-24] (Microsoft)
Task: {5DF25F26-1DD4-42AF-A7D5-8AF413AA526D} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => C:\Program Files\Windows Defender\MpCmdRun.exe [2008-01-21] (Microsoft Corporation)
Task: {724DD079-074D-48F7-84FC-129CAE9457D2} - System32\Tasks\rbmonitor => C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe [2013-08-21] (Uniblue Systems Limited)
Task: {75C473BC-8CAD-499B-8316-EFD367B24770} - System32\Tasks\WashAndGoNGBackground => C:\Program Files\WashAndGo\WashAndGo.exe [2012-09-24] (Microsoft)
Task: {793C7D04-E0F7-41B2-9376-BCB3BC77411B} - System32\Tasks\CheckDriveBackgroundGuard => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: {8CFE559A-52BC-433E-B3B9-E2296815C970} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-27] (Adobe Systems Incorporated)
Task: {99982336-9432-499D-A415-B1D0E9EE6E6A} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [2006-12-10] (Hewlett-Packard Co.)
Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => C:\Windows\System32\pla.dll [2008-01-21] (Microsoft Corporation)
Task: {A7F9AF08-9C24-4D9D-A77B-6C6A29823CB3} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-12] (Microsoft Corporation)
Task: {CC5A7CB0-4962-4392-8465-2DA2116D2672} - System32\Tasks\RegistryBooster => C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe [2013-08-21] (Uniblue Systems Limited)
Task: {DC45E898-AF81-4A07-ABC9-73FCDB16504C} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-03-02] ()
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: C:\Windows\Tasks\AbelssoftPreloader.job => C:\Program Files\WashAndGo\AbelssoftPreloader.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\CheckDriveBackgroundGuard.job => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe
Task: C:\Windows\Tasks\rbmonitor.job => C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
Task: C:\Windows\Tasks\RegistryBooster.job => C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
Task: C:\Windows\Tasks\WashAndGoNGBackground.job => C:\Program Files\WashAndGo\WashAndGo.exe
Task: C:\Windows\Tasks\WebReg Deskjet F300 series.job => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe

==================== Loaded Modules (whitelisted) =============

2011-06-27 15:24 - 2007-08-23 15:39 - 00014848 _____ () C:\Program Files\Mobile Partner\isaputrace.dll
2011-06-27 15:24 - 2009-12-10 10:51 - 00114688 _____ () C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll
2011-06-27 15:24 - 2009-09-19 10:21 - 00139264 _____ () C:\Program Files\Mobile Partner\NetInfoPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:48 - 00090112 _____ () C:\Program Files\Mobile Partner\DialUpPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:54 - 00057344 _____ () C:\Program Files\Mobile Partner\ConfigFilePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:40 - 00991232 _____ () C:\Program Files\Mobile Partner\NDISAPI.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00155648 _____ () C:\Program Files\Mobile Partner\DetectDev.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00557056 _____ () C:\Program Files\Mobile Partner\atcomm.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\XCodec.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\DeviceOperate.dll
2011-06-27 15:24 - 2009-06-18 09:56 - 00032768 _____ () C:\Program Files\Mobile Partner\NotifyServicePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:52 - 00192512 _____ () C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00143360 _____ () C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll
2011-06-27 15:24 - 2007-07-31 14:50 - 00090112 _____ () C:\Program Files\Mobile Partner\FileManager.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00159744 _____ () C:\Program Files\Mobile Partner\SMSPlugin.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00201640 _____ () C:\Program Files\Java\jre7\bin\jp2iexp.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00016808 _____ () C:\Program Files\Java\jre7\bin\jp2native.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service) (User: )
Description: Die Anwendung kann nicht initialisiert werden.

Kontext: Windows Anwendung


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service) (User: )
Description: Das Gatherer-Objekt kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service) (User: )
Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Element nicht gefunden.  (0x80070490)

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service) (User: )
Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service) (User: )
Description: Die Eigenschaftenspeicherdaten können vom Windows-Suchdienst nicht geladen werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        0x%08x (0xc0041800 - Der Inhaltsindex kann nicht gelesen werden.  )

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service) (User: )
Description: Der Suchdienst hat beschädigte Datendateien im Index erkannt. Der Dienst versucht, dieses Problem durch Neuerstellung des Index automatisch zu beheben.


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:04 PM) (Source: Windows Search Service) (User: )
Description: Der Jet-Eigenschaftenspeicher kann vom Windows-Suchdienst nicht geöffnet werden.


Details:
        Der Inhaltsindex kann nicht gelesen werden.  (0xc0041800)

Error: (11/14/2013 04:00:04 PM) (Source: ESENT) (User: )
Description: Windows (2112) Windows: Fehler -1811 (0xfffff8ed) beim Öffnen von Protokolldatei C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.


System errors:
=============
Error: (11/15/2013 07:48:14 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (11/15/2013 07:45:40 PM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (11/15/2013 07:45:40 PM) (Source: Service Control Manager) (User: )
Description: Net.Tcp-ListeneradapterNet.Tcp-Portfreigabedienst%%1058

Error: (11/15/2013 07:45:40 PM) (Source: Service Control Manager) (User: )
Description: Net.Pipe-Listeneradapterwas

Error: (11/15/2013 07:45:40 PM) (Source: Service Control Manager) (User: )
Description: Net.Msmq-Listeneradaptermsmq

Error: (11/15/2013 05:15:53 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (11/15/2013 05:12:31 AM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (11/15/2013 05:12:31 AM) (Source: Service Control Manager) (User: )
Description: Net.Tcp-ListeneradapterNet.Tcp-Portfreigabedienst%%1058

Error: (11/15/2013 05:12:31 AM) (Source: Service Control Manager) (User: )
Description: Net.Pipe-Listeneradapterwas

Error: (11/15/2013 05:12:31 AM) (Source: Service Control Manager) (User: )
Description: Net.Msmq-Listeneradaptermsmq


Microsoft Office Sessions:
=========================
Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:06 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Element nicht gefunden.  (0x80070490)
Search.TripoliIndexer

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)
Search.JetPropStore

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        0x%08x (0xc0041800 - Der Inhaltsindex kann nicht gelesen werden.  )

Error: (11/14/2013 04:00:05 PM) (Source: Windows Search Service)(User: )
Description:
Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/14/2013 04:00:04 PM) (Source: Windows Search Service)(User: )
Description:
Details:
        Der Inhaltsindex kann nicht gelesen werden.  (0xc0041800)

Error: (11/14/2013 04:00:04 PM) (Source: ESENT)(User: )
Description: Windows2112Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log-1811 (0xfffff8ed)


CodeIntegrity Errors:
===================================
  Date: 2012-10-20 17:13:05.162
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:04.538
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:03.883
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:03.259
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:02.635
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:02.011
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:01.324
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_b38d4a937f96be60\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:00.700
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_b38d4a937f96be60\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:13:00.061
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_b38d4a937f96be60\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-20 17:12:59.437
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_b38d4a937f96be60\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 51%
Total physical RAM: 2038.64 MB
Available physical RAM: 997.35 MB
Total Pagefile: 4326.32 MB
Available Pagefile: 2293.53 MB
Total Virtual: 2047.88 MB
Available Virtual: 1911.21 MB

==================== Drives ================================

Drive c: (OS_Install) (Fixed) (Total:63.48 GB) (Free:33.84 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Mobile Partner) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS
Drive e: (Data) (Fixed) (Total:387.63 GB) (Free:359 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 9AC9B968)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=63 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=388 GB) - (Type=07 NTFS)

==================== End Of Log ============================


schrauber 16.11.2013 15:32

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.

mädchen 16.11.2013 21:58

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows Vista (TM) Home Premium x86
Ran by pc on 16.11.2013 at 20:31:58,51
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1085966804-1864869585-2381995735-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1085966804-1864869585-2381995735-1000\Software\web assistant



~~~ Files

Successfully deleted: [File] C:\Windows\Tasks\registrybooster.job



~~~ Folders

Successfully deleted: [Folder] "C:\Users\pc\appdata\locallow\datamngr"
Successfully deleted: [Folder] "C:\Program Files\bearshare applications"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\uniblue"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.11.2013 at 20:58:00,06
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows Vista (TM) Home Premium x86
Ran by pc on 16.11.2013 at 20:31:58,51
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1085966804-1864869585-2381995735-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1085966804-1864869585-2381995735-1000\Software\web assistant



~~~ Files

Successfully deleted: [File] C:\Windows\Tasks\registrybooster.job



~~~ Folders

Successfully deleted: [Folder] "C:\Users\pc\appdata\locallow\datamngr"
Successfully deleted: [Folder] "C:\Program Files\bearshare applications"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\uniblue"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.11.2013 at 20:58:00,06
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows Vista (TM) Home Premium x86
Ran by pc on 16.11.2013 at 20:31:58,51
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1085966804-1864869585-2381995735-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1085966804-1864869585-2381995735-1000\Software\web assistant



~~~ Files

Successfully deleted: [File] C:\Windows\Tasks\registrybooster.job



~~~ Folders

Successfully deleted: [Folder] "C:\Users\pc\appdata\locallow\datamngr"
Successfully deleted: [Folder] "C:\Program Files\bearshare applications"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\uniblue"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.11.2013 at 20:58:00,06
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

AdwCleaner Logfile:
Code:

# AdwCleaner v2.005 - Datei am 16/11/2013 um 20:26:48 erstellt
# Aktualisiert am 14/10/2012 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : pc - PC-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\pc\Desktop\diverse\programme u dergl\trojaner board\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Die Registrierungsdatenbank ist sauber.

*************************

AdwCleaner[R1].txt - [24977 octets] - [18/10/2012 18:46:52]
AdwCleaner[S1].txt - [24145 octets] - [18/10/2012 18:57:40]
AdwCleaner[R2].txt - [970 octets] - [16/11/2013 20:26:02]
AdwCleaner[R3].txt - [902 octets] - [16/11/2013 20:26:48]

########## EOF - C:\AdwCleaner[R3].txt - [961 octets] ##########

--- --- ---
AdwCleaner Logfile:
Code:

# AdwCleaner v2.005 - Datei am 16/11/2013 um 20:26:48 erstellt
# Aktualisiert am 14/10/2012 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : pc - PC-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\pc\Desktop\diverse\programme u dergl\trojaner board\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Die Registrierungsdatenbank ist sauber.

*************************

AdwCleaner[R1].txt - [24977 octets] - [18/10/2012 18:46:52]
AdwCleaner[S1].txt - [24145 octets] - [18/10/2012 18:57:40]
AdwCleaner[R2].txt - [970 octets] - [16/11/2013 20:26:02]
AdwCleaner[R3].txt - [902 octets] - [16/11/2013 20:26:48]

########## EOF - C:\AdwCleaner[R3].txt - [961 octets] ##########

--- --- ---
AdwCleaner Logfile:
Code:

# AdwCleaner v2.005 - Datei am 16/11/2013 um 20:26:48 erstellt
# Aktualisiert am 14/10/2012 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : pc - PC-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\pc\Desktop\diverse\programme u dergl\trojaner board\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Die Registrierungsdatenbank ist sauber.

*************************

AdwCleaner[R1].txt - [24977 octets] - [18/10/2012 18:46:52]
AdwCleaner[S1].txt - [24145 octets] - [18/10/2012 18:57:40]
AdwCleaner[R2].txt - [970 octets] - [16/11/2013 20:26:02]
AdwCleaner[R3].txt - [902 octets] - [16/11/2013 20:26:48]

########## EOF - C:\AdwCleaner[R3].txt - [961 octets] ##########

--- --- ---
Code:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.11.16.04

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
pc :: PC-PC [Administrator]

16.11.2013 18:32:37
mbam-log-2013-11-16 (18-32-37).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 305646
Laufzeit: 1 Stunde(n), 22 Minute(n),

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 46
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Communicator\mgcommon.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Communicator\mgcommunication.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Communicator\mgsimcommon.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Communicator\mgxml_wrapper.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Communicator\resources\sqlite\mgSqlite3.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mghooking.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\ContentPackagesActivationHandler.exe.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgAdaptersProxy.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgArchive.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgcommon.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgcommunication.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgconfig.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgFlashPlayer.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgICQAuto.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgICQMessengerAdapter.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mglogger.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgMediaPlayer.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgMsnAuto.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgMsnMessengerAdapter.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgsimcommon.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgSweetIM.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgUpdateSupport.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgxml_wrapper.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgYahooAuto.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\mgYahooMessengerAdapter.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\SweetIM.exe.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Messenger\resources\sqlite\mgSqlite3.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Toolbars\Internet Explorer\ClearHist.exe.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Toolbars\Internet Explorer\mgcommon.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Toolbars\Internet Explorer\mgconfig.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Toolbars\Internet Explorer\mghooking.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Toolbars\Internet Explorer\mglogger.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll.vir (PUP.Optional.SweetPacks) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.1.0.1_0\mgHelperGCFB.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.2.0.0_0\mgHelperGCFB.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.0.0.1_0\mgHelperGC.dll.vir (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\Installer\1350f2.msi (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\Installer\1350f8.msi (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\Installer\1350fe.msi (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3CKKLBE\WSSetup[4].exe (PUP.Optional.InstallBrain.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-11-2013
Ran by pc (administrator) on PC-PC on 16-11-2013 21:46:08
Running from C:\Users\pc\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\system32\PrintCtrl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\system32\PrintDisp.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Mobile Partner\Mobile Partner.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Lunascape Corporation) C:\Program Files\Lunascape\Lunascape6\Luna.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor)
HKLM\...\Run: [PrintDisp] - C:\Windows\System32\PrintDisp.exe [830464 2012-05-30] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-07-17] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2009-05-25] ()
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 193.189.244.206 193.189.244.225
Tcpip\..\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: [NameServer]132.252.3.10,132.252.1.7

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-17] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-09] (Avira Operations GmbH & Co. KG)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] ()
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [77824 2012-01-20] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
S2 vToolbarUpdater13.0.0;

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [57944 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-08-22] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [26984 2012-10-07] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-07-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-08-19] (Emsisoft GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; No ImagePath
S3 IpInIp; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-16 20:58 - 2013-11-16 20:58 - 00001327 _____ C:\Users\pc\Desktop\JRT.txt
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:30 - 2013-11-16 20:30 - 01034531 _____ (Thisisu) C:\Users\pc\Desktop\JRT.exe
2013-11-16 20:27 - 2013-11-16 20:27 - 00001029 _____ C:\Users\pc\Desktop\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:27 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 18:32 - 2013-11-16 18:32 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-16 18:27 - 2013-11-16 18:27 - 00000876 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-16 18:26 - 2013-11-16 18:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-16 18:26 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-16 18:24 - 2013-11-16 18:25 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\pc\Desktop\mbam-setup-1.75.0.1300.exe
2013-11-16 12:31 - 2013-11-16 20:23 - 00026607 _____ C:\Windows\WindowsUpdate.log
2013-11-16 12:26 - 2013-11-16 20:01 - 00016010 _____ C:\Windows\PFRO.log
2013-11-16 12:26 - 2013-11-16 12:26 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-15 20:09 - 2013-11-15 20:11 - 00022034 _____ C:\Users\pc\Desktop\Addition.txt
2013-11-15 20:06 - 2013-11-16 21:46 - 00008659 _____ C:\Users\pc\Desktop\FRST.txt
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-15 20:01 - 2013-11-15 20:02 - 01090529 _____ (Farbar) C:\Users\pc\Desktop\FRST.exe
2013-11-14 17:42 - 2013-10-13 11:42 - 12344832 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 17:42 - 2013-10-13 11:08 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 17:42 - 2013-10-13 10:48 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 17:42 - 2013-10-13 10:37 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 17:42 - 2013-10-13 10:35 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-14 17:42 - 2013-10-13 10:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 17:42 - 2013-10-13 10:33 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-14 17:42 - 2013-10-13 10:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-14 17:42 - 2013-10-13 10:29 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 17:42 - 2013-10-13 10:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-14 17:42 - 2013-10-13 10:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 17:42 - 2013-10-13 10:20 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 16:15 - 2013-10-11 03:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 16:15 - 2013-10-11 03:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 16:15 - 2013-10-11 01:39 - 00218228 _____ C:\Windows\system32\WFP.TMF
2013-11-14 16:15 - 2013-10-03 13:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 16:15 - 2013-10-03 13:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-13 11:55 - 2013-11-13 11:55 - 00002397 _____ C:\Users\pc\Desktop\FSS.txt
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 19:05 - 2013-11-16 20:14 - 00000000 ____D C:\AdwCleaner
2013-11-12 17:03 - 2013-11-12 17:04 - 00586560 _____ C:\EamClean.log
2013-11-11 04:06 - 2013-11-11 04:06 - 00000858 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-11-11 04:05 - 2013-11-16 20:19 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 18:02 - 2013-11-12 14:17 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-06 18:02 - 2013-11-11 09:42 - 00000000 ____D C:\ProgramData\Skype
2013-11-06 07:22 - 2013-11-06 07:22 - 00001638 _____ C:\Users\pc\Desktop\AbAlarm.lnk
2013-10-29 09:29 - 2013-11-16 20:35 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-29 04:57 - 2013-11-12 19:37 - 00000000 ____D C:\Program Files\OXXOGames
2013-10-28 10:48 - 2013-11-13 17:18 - 00000000 ____D C:\Users\pc\Desktop\Neuer Ordner
2013-10-27 19:21 - 2013-10-27 19:21 - 00001862 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 17:06 - 2013-11-16 21:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:30 - 2013-10-27 12:29 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-24 09:44 - 2013-10-30 09:35 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-17 18:48 - 2012-01-23 06:34 - 00905216 _____ (ActMask hxxp://www.all2pdf.com) C:\Windows\system32\SaveTo.dll
2013-10-17 18:48 - 2011-11-13 18:03 - 04067736 _____ (DynaForms GmbH) C:\Windows\system32\CPDF3.dll

==================== One Month Modified Files and Folders =======

2013-11-16 21:47 - 2013-11-15 20:06 - 00008659 _____ C:\Users\pc\Desktop\FRST.txt
2013-11-16 21:24 - 2013-10-27 17:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-16 20:58 - 2013-11-16 20:58 - 00001327 _____ C:\Users\pc\Desktop\JRT.txt
2013-11-16 20:51 - 2013-11-16 12:31 - 00026607 _____ C:\Windows\WindowsUpdate.log
2013-11-16 20:50 - 2012-06-07 22:26 - 00000332 _____ C:\Windows\Tasks\HP Photo Creations Communicator.job
2013-11-16 20:35 - 2013-10-29 09:29 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:30 - 2013-11-16 20:30 - 01034531 _____ (Thisisu) C:\Users\pc\Desktop\JRT.exe
2013-11-16 20:27 - 2013-11-16 20:27 - 00001029 _____ C:\Users\pc\Desktop\AdwCleaner[R3].txt
2013-11-16 20:27 - 2013-11-16 20:26 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 20:22 - 2013-10-11 11:41 - 00000254 _____ C:\Windows\Tasks\WashAndGoNGBackground.job
2013-11-16 20:19 - 2013-11-11 04:05 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-16 20:17 - 2012-09-01 19:03 - 00000260 _____ C:\Windows\Tasks\AbelssoftPreloader.job
2013-11-16 20:17 - 2012-08-17 10:27 - 00000270 _____ C:\Windows\Tasks\CheckDriveBackgroundGuard.job
2013-11-16 20:17 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-16 20:17 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-16 20:17 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-16 20:17 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-11-16 20:15 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-16 20:14 - 2013-11-12 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-16 20:09 - 2006-11-02 11:23 - 00000179 _____ C:\Windows\win.ini
2013-11-16 20:01 - 2013-11-16 12:26 - 00016010 _____ C:\Windows\PFRO.log
2013-11-16 18:32 - 2013-11-16 18:32 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-16 18:27 - 2013-11-16 18:27 - 00000876 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-16 18:27 - 2013-11-16 18:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-16 18:25 - 2013-11-16 18:24 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\pc\Desktop\mbam-setup-1.75.0.1300.exe
2013-11-16 12:26 - 2013-11-16 12:26 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-15 20:11 - 2013-11-15 20:09 - 00022034 _____ C:\Users\pc\Desktop\Addition.txt
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-15 20:02 - 2013-11-15 20:01 - 01090529 _____ (Farbar) C:\Users\pc\Desktop\FRST.exe
2013-11-14 18:08 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-11-14 17:48 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 17:33 - 2013-10-11 10:50 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 17:28 - 2006-11-02 11:24 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-11-14 07:18 - 2006-11-02 11:33 - 01559288 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-13 17:18 - 2013-10-28 10:48 - 00000000 ____D C:\Users\pc\Desktop\Neuer Ordner
2013-11-13 11:55 - 2013-11-13 11:55 - 00002397 _____ C:\Users\pc\Desktop\FSS.txt
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Program Files\Google
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 21:20 - 2011-02-25 15:30 - 00000000 ____D C:\Users\pc\AppData\Local\Adobe
2013-11-12 19:37 - 2013-10-29 04:57 - 00000000 ____D C:\Program Files\OXXOGames
2013-11-12 19:11 - 2012-07-11 09:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-12 19:10 - 2011-09-16 13:45 - 00000000 ____D C:\ProgramData\Uniblue
2013-11-12 17:04 - 2013-11-12 17:03 - 00586560 _____ C:\EamClean.log
2013-11-12 14:17 - 2013-11-06 18:02 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-11 09:42 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\Skype
2013-11-11 04:06 - 2013-11-11 04:06 - 00000858 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:44 - 2011-05-07 02:20 - 00000000 ____D C:\Users\pc\AppData\Roaming\Dropbox
2013-11-09 17:42 - 2011-05-07 02:25 - 00000000 ___RD C:\Users\pc\Dropbox
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 07:22 - 2013-11-06 07:22 - 00001638 _____ C:\Users\pc\Desktop\AbAlarm.lnk
2013-11-03 20:30 - 2010-10-15 17:12 - 00000000 ____D C:\Users\pc
2013-11-02 08:14 - 2011-10-29 19:03 - 00000000 ____D C:\Windows\CleverPrint
2013-11-02 08:12 - 2011-07-08 16:12 - 00000000 ____D C:\Program Files\MailXXL.com Tools
2013-11-02 08:11 - 2011-07-08 10:51 - 01095982 _____ C:\ndsvc.log
2013-11-02 08:07 - 2012-08-16 09:16 - 00000000 ____D C:\Program Files\Panda Security
2013-10-31 20:33 - 2011-02-05 09:46 - 00000000 ____D C:\Users\pc\Desktop\diverse
2013-10-30 09:35 - 2013-10-24 09:44 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-28 23:09 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public
2013-10-27 19:21 - 2013-10-27 19:21 - 00001862 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 19:20 - 2011-06-29 19:12 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-10-27 19:20 - 2011-02-25 14:50 - 00000000 ____D C:\ProgramData\Adobe
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:29 - 2013-10-27 12:30 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-27 12:29 - 2011-07-02 15:35 - 00000000 ____D C:\Program Files\Java
2013-10-25 20:25 - 2012-07-22 08:55 - 00000000 ____D C:\Users\pc\AppData\Local\Paint.NET
2013-10-24 20:04 - 2011-05-07 02:21 - 00000000 ____D C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-21 00:01 - 2011-05-07 02:25 - 00000920 _____ C:\Users\pc\Desktop\Dropbox.lnk
2013-10-20 23:22 - 2010-10-19 02:53 - 00000000 ____D C:\Users\pc\AppData\Local\Microsoft Games

Some content of TEMP:
====================
C:\Users\pc\AppData\Local\temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-16 20:24

==================== End Of Log ============================

--- --- ---

--- --- ---

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-11-2013
Ran by pc (administrator) on PC-PC on 16-11-2013 21:46:08
Running from C:\Users\pc\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\system32\PrintCtrl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\system32\PrintDisp.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Mobile Partner\Mobile Partner.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Lunascape Corporation) C:\Program Files\Lunascape\Lunascape6\Luna.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor)
HKLM\...\Run: [PrintDisp] - C:\Windows\System32\PrintDisp.exe [830464 2012-05-30] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-07-17] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2009-05-25] ()
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 193.189.244.206 193.189.244.225
Tcpip\..\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: [NameServer]132.252.3.10,132.252.1.7

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-17] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-09] (Avira Operations GmbH & Co. KG)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] ()
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [77824 2012-01-20] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
S2 vToolbarUpdater13.0.0;

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [57944 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-08-22] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [26984 2012-10-07] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-07-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-08-19] (Emsisoft GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; No ImagePath
S3 IpInIp; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-16 20:58 - 2013-11-16 20:58 - 00001327 _____ C:\Users\pc\Desktop\JRT.txt
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:30 - 2013-11-16 20:30 - 01034531 _____ (Thisisu) C:\Users\pc\Desktop\JRT.exe
2013-11-16 20:27 - 2013-11-16 20:27 - 00001029 _____ C:\Users\pc\Desktop\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:27 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 18:32 - 2013-11-16 18:32 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-16 18:27 - 2013-11-16 18:27 - 00000876 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-16 18:26 - 2013-11-16 18:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-16 18:26 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-16 18:24 - 2013-11-16 18:25 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\pc\Desktop\mbam-setup-1.75.0.1300.exe
2013-11-16 12:31 - 2013-11-16 20:23 - 00026607 _____ C:\Windows\WindowsUpdate.log
2013-11-16 12:26 - 2013-11-16 20:01 - 00016010 _____ C:\Windows\PFRO.log
2013-11-16 12:26 - 2013-11-16 12:26 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-15 20:09 - 2013-11-15 20:11 - 00022034 _____ C:\Users\pc\Desktop\Addition.txt
2013-11-15 20:06 - 2013-11-16 21:46 - 00008659 _____ C:\Users\pc\Desktop\FRST.txt
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-15 20:01 - 2013-11-15 20:02 - 01090529 _____ (Farbar) C:\Users\pc\Desktop\FRST.exe
2013-11-14 17:42 - 2013-10-13 11:42 - 12344832 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 17:42 - 2013-10-13 11:08 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 17:42 - 2013-10-13 10:48 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 17:42 - 2013-10-13 10:37 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 17:42 - 2013-10-13 10:35 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-14 17:42 - 2013-10-13 10:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 17:42 - 2013-10-13 10:33 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-14 17:42 - 2013-10-13 10:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-14 17:42 - 2013-10-13 10:29 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 17:42 - 2013-10-13 10:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-14 17:42 - 2013-10-13 10:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 17:42 - 2013-10-13 10:20 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 16:15 - 2013-10-11 03:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 16:15 - 2013-10-11 03:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 16:15 - 2013-10-11 01:39 - 00218228 _____ C:\Windows\system32\WFP.TMF
2013-11-14 16:15 - 2013-10-03 13:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 16:15 - 2013-10-03 13:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-13 11:55 - 2013-11-13 11:55 - 00002397 _____ C:\Users\pc\Desktop\FSS.txt
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 19:05 - 2013-11-16 20:14 - 00000000 ____D C:\AdwCleaner
2013-11-12 17:03 - 2013-11-12 17:04 - 00586560 _____ C:\EamClean.log
2013-11-11 04:06 - 2013-11-11 04:06 - 00000858 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-11-11 04:05 - 2013-11-16 20:19 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 18:02 - 2013-11-12 14:17 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-06 18:02 - 2013-11-11 09:42 - 00000000 ____D C:\ProgramData\Skype
2013-11-06 07:22 - 2013-11-06 07:22 - 00001638 _____ C:\Users\pc\Desktop\AbAlarm.lnk
2013-10-29 09:29 - 2013-11-16 20:35 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-29 04:57 - 2013-11-12 19:37 - 00000000 ____D C:\Program Files\OXXOGames
2013-10-28 10:48 - 2013-11-13 17:18 - 00000000 ____D C:\Users\pc\Desktop\Neuer Ordner
2013-10-27 19:21 - 2013-10-27 19:21 - 00001862 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 17:06 - 2013-11-16 21:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:30 - 2013-10-27 12:29 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-24 09:44 - 2013-10-30 09:35 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-17 18:48 - 2012-01-23 06:34 - 00905216 _____ (ActMask hxxp://www.all2pdf.com) C:\Windows\system32\SaveTo.dll
2013-10-17 18:48 - 2011-11-13 18:03 - 04067736 _____ (DynaForms GmbH) C:\Windows\system32\CPDF3.dll

==================== One Month Modified Files and Folders =======

2013-11-16 21:47 - 2013-11-15 20:06 - 00008659 _____ C:\Users\pc\Desktop\FRST.txt
2013-11-16 21:24 - 2013-10-27 17:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-16 20:58 - 2013-11-16 20:58 - 00001327 _____ C:\Users\pc\Desktop\JRT.txt
2013-11-16 20:51 - 2013-11-16 12:31 - 00026607 _____ C:\Windows\WindowsUpdate.log
2013-11-16 20:50 - 2012-06-07 22:26 - 00000332 _____ C:\Windows\Tasks\HP Photo Creations Communicator.job
2013-11-16 20:35 - 2013-10-29 09:29 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:30 - 2013-11-16 20:30 - 01034531 _____ (Thisisu) C:\Users\pc\Desktop\JRT.exe
2013-11-16 20:27 - 2013-11-16 20:27 - 00001029 _____ C:\Users\pc\Desktop\AdwCleaner[R3].txt
2013-11-16 20:27 - 2013-11-16 20:26 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 20:22 - 2013-10-11 11:41 - 00000254 _____ C:\Windows\Tasks\WashAndGoNGBackground.job
2013-11-16 20:19 - 2013-11-11 04:05 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-16 20:17 - 2012-09-01 19:03 - 00000260 _____ C:\Windows\Tasks\AbelssoftPreloader.job
2013-11-16 20:17 - 2012-08-17 10:27 - 00000270 _____ C:\Windows\Tasks\CheckDriveBackgroundGuard.job
2013-11-16 20:17 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-16 20:17 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-16 20:17 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-16 20:17 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-11-16 20:15 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-16 20:14 - 2013-11-12 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-16 20:09 - 2006-11-02 11:23 - 00000179 _____ C:\Windows\win.ini
2013-11-16 20:01 - 2013-11-16 12:26 - 00016010 _____ C:\Windows\PFRO.log
2013-11-16 18:32 - 2013-11-16 18:32 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-16 18:27 - 2013-11-16 18:27 - 00000876 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-16 18:27 - 2013-11-16 18:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-16 18:25 - 2013-11-16 18:24 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\pc\Desktop\mbam-setup-1.75.0.1300.exe
2013-11-16 12:26 - 2013-11-16 12:26 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-15 20:11 - 2013-11-15 20:09 - 00022034 _____ C:\Users\pc\Desktop\Addition.txt
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-15 20:02 - 2013-11-15 20:01 - 01090529 _____ (Farbar) C:\Users\pc\Desktop\FRST.exe
2013-11-14 18:08 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-11-14 17:48 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 17:33 - 2013-10-11 10:50 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 17:28 - 2006-11-02 11:24 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-11-14 07:18 - 2006-11-02 11:33 - 01559288 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-13 17:18 - 2013-10-28 10:48 - 00000000 ____D C:\Users\pc\Desktop\Neuer Ordner
2013-11-13 11:55 - 2013-11-13 11:55 - 00002397 _____ C:\Users\pc\Desktop\FSS.txt
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Program Files\Google
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 21:20 - 2011-02-25 15:30 - 00000000 ____D C:\Users\pc\AppData\Local\Adobe
2013-11-12 19:37 - 2013-10-29 04:57 - 00000000 ____D C:\Program Files\OXXOGames
2013-11-12 19:11 - 2012-07-11 09:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-12 19:10 - 2011-09-16 13:45 - 00000000 ____D C:\ProgramData\Uniblue
2013-11-12 17:04 - 2013-11-12 17:03 - 00586560 _____ C:\EamClean.log
2013-11-12 14:17 - 2013-11-06 18:02 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-11 09:42 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\Skype
2013-11-11 04:06 - 2013-11-11 04:06 - 00000858 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:44 - 2011-05-07 02:20 - 00000000 ____D C:\Users\pc\AppData\Roaming\Dropbox
2013-11-09 17:42 - 2011-05-07 02:25 - 00000000 ___RD C:\Users\pc\Dropbox
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 07:22 - 2013-11-06 07:22 - 00001638 _____ C:\Users\pc\Desktop\AbAlarm.lnk
2013-11-03 20:30 - 2010-10-15 17:12 - 00000000 ____D C:\Users\pc
2013-11-02 08:14 - 2011-10-29 19:03 - 00000000 ____D C:\Windows\CleverPrint
2013-11-02 08:12 - 2011-07-08 16:12 - 00000000 ____D C:\Program Files\MailXXL.com Tools
2013-11-02 08:11 - 2011-07-08 10:51 - 01095982 _____ C:\ndsvc.log
2013-11-02 08:07 - 2012-08-16 09:16 - 00000000 ____D C:\Program Files\Panda Security
2013-10-31 20:33 - 2011-02-05 09:46 - 00000000 ____D C:\Users\pc\Desktop\diverse
2013-10-30 09:35 - 2013-10-24 09:44 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-28 23:09 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public
2013-10-27 19:21 - 2013-10-27 19:21 - 00001862 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 19:20 - 2011-06-29 19:12 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-10-27 19:20 - 2011-02-25 14:50 - 00000000 ____D C:\ProgramData\Adobe
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:29 - 2013-10-27 12:30 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-27 12:29 - 2011-07-02 15:35 - 00000000 ____D C:\Program Files\Java
2013-10-25 20:25 - 2012-07-22 08:55 - 00000000 ____D C:\Users\pc\AppData\Local\Paint.NET
2013-10-24 20:04 - 2011-05-07 02:21 - 00000000 ____D C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-21 00:01 - 2011-05-07 02:25 - 00000920 _____ C:\Users\pc\Desktop\Dropbox.lnk
2013-10-20 23:22 - 2010-10-19 02:53 - 00000000 ____D C:\Users\pc\AppData\Local\Microsoft Games

Some content of TEMP:
====================
C:\Users\pc\AppData\Local\temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-16 20:24

==================== End Of Log ============================

--- --- ---

--- --- ---

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-11-2013
Ran by pc (administrator) on PC-PC on 16-11-2013 21:46:08
Running from C:\Users\pc\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\system32\PrintCtrl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\system32\PrintDisp.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Mobile Partner\Mobile Partner.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Lunascape Corporation) C:\Program Files\Lunascape\Lunascape6\Luna.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor)
HKLM\...\Run: [PrintDisp] - C:\Windows\System32\PrintDisp.exe [830464 2012-05-30] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-07-17] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2009-05-25] ()
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 193.189.244.206 193.189.244.225
Tcpip\..\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: [NameServer]132.252.3.10,132.252.1.7

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-17] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-09] (Avira Operations GmbH & Co. KG)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] ()
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [77824 2012-01-20] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
S2 vToolbarUpdater13.0.0;

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [57944 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-08-22] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [26984 2012-10-07] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-07-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-08-19] (Emsisoft GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; No ImagePath
S3 IpInIp; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-16 20:58 - 2013-11-16 20:58 - 00001327 _____ C:\Users\pc\Desktop\JRT.txt
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:30 - 2013-11-16 20:30 - 01034531 _____ (Thisisu) C:\Users\pc\Desktop\JRT.exe
2013-11-16 20:27 - 2013-11-16 20:27 - 00001029 _____ C:\Users\pc\Desktop\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:27 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 18:32 - 2013-11-16 18:32 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-16 18:27 - 2013-11-16 18:27 - 00000876 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-16 18:26 - 2013-11-16 18:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-16 18:26 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-16 18:24 - 2013-11-16 18:25 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\pc\Desktop\mbam-setup-1.75.0.1300.exe
2013-11-16 12:31 - 2013-11-16 20:23 - 00026607 _____ C:\Windows\WindowsUpdate.log
2013-11-16 12:26 - 2013-11-16 20:01 - 00016010 _____ C:\Windows\PFRO.log
2013-11-16 12:26 - 2013-11-16 12:26 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-15 20:09 - 2013-11-15 20:11 - 00022034 _____ C:\Users\pc\Desktop\Addition.txt
2013-11-15 20:06 - 2013-11-16 21:46 - 00008659 _____ C:\Users\pc\Desktop\FRST.txt
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-15 20:01 - 2013-11-15 20:02 - 01090529 _____ (Farbar) C:\Users\pc\Desktop\FRST.exe
2013-11-14 17:42 - 2013-10-13 11:42 - 12344832 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 17:42 - 2013-10-13 11:08 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 17:42 - 2013-10-13 10:48 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 17:42 - 2013-10-13 10:37 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 17:42 - 2013-10-13 10:35 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-14 17:42 - 2013-10-13 10:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 17:42 - 2013-10-13 10:33 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-14 17:42 - 2013-10-13 10:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-14 17:42 - 2013-10-13 10:29 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 17:42 - 2013-10-13 10:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-14 17:42 - 2013-10-13 10:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 17:42 - 2013-10-13 10:20 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 16:15 - 2013-10-11 03:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 16:15 - 2013-10-11 03:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 16:15 - 2013-10-11 01:39 - 00218228 _____ C:\Windows\system32\WFP.TMF
2013-11-14 16:15 - 2013-10-03 13:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 16:15 - 2013-10-03 13:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-13 11:55 - 2013-11-13 11:55 - 00002397 _____ C:\Users\pc\Desktop\FSS.txt
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 19:05 - 2013-11-16 20:14 - 00000000 ____D C:\AdwCleaner
2013-11-12 17:03 - 2013-11-12 17:04 - 00586560 _____ C:\EamClean.log
2013-11-11 04:06 - 2013-11-11 04:06 - 00000858 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-11-11 04:05 - 2013-11-16 20:19 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 18:02 - 2013-11-12 14:17 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-06 18:02 - 2013-11-11 09:42 - 00000000 ____D C:\ProgramData\Skype
2013-11-06 07:22 - 2013-11-06 07:22 - 00001638 _____ C:\Users\pc\Desktop\AbAlarm.lnk
2013-10-29 09:29 - 2013-11-16 20:35 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-29 04:57 - 2013-11-12 19:37 - 00000000 ____D C:\Program Files\OXXOGames
2013-10-28 10:48 - 2013-11-13 17:18 - 00000000 ____D C:\Users\pc\Desktop\Neuer Ordner
2013-10-27 19:21 - 2013-10-27 19:21 - 00001862 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 17:06 - 2013-11-16 21:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:30 - 2013-10-27 12:29 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-24 09:44 - 2013-10-30 09:35 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-17 18:48 - 2012-01-23 06:34 - 00905216 _____ (ActMask hxxp://www.all2pdf.com) C:\Windows\system32\SaveTo.dll
2013-10-17 18:48 - 2011-11-13 18:03 - 04067736 _____ (DynaForms GmbH) C:\Windows\system32\CPDF3.dll

==================== One Month Modified Files and Folders =======

2013-11-16 21:47 - 2013-11-15 20:06 - 00008659 _____ C:\Users\pc\Desktop\FRST.txt
2013-11-16 21:24 - 2013-10-27 17:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-16 20:58 - 2013-11-16 20:58 - 00001327 _____ C:\Users\pc\Desktop\JRT.txt
2013-11-16 20:51 - 2013-11-16 12:31 - 00026607 _____ C:\Windows\WindowsUpdate.log
2013-11-16 20:50 - 2012-06-07 22:26 - 00000332 _____ C:\Windows\Tasks\HP Photo Creations Communicator.job
2013-11-16 20:35 - 2013-10-29 09:29 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:30 - 2013-11-16 20:30 - 01034531 _____ (Thisisu) C:\Users\pc\Desktop\JRT.exe
2013-11-16 20:27 - 2013-11-16 20:27 - 00001029 _____ C:\Users\pc\Desktop\AdwCleaner[R3].txt
2013-11-16 20:27 - 2013-11-16 20:26 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 20:22 - 2013-10-11 11:41 - 00000254 _____ C:\Windows\Tasks\WashAndGoNGBackground.job
2013-11-16 20:19 - 2013-11-11 04:05 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-16 20:17 - 2012-09-01 19:03 - 00000260 _____ C:\Windows\Tasks\AbelssoftPreloader.job
2013-11-16 20:17 - 2012-08-17 10:27 - 00000270 _____ C:\Windows\Tasks\CheckDriveBackgroundGuard.job
2013-11-16 20:17 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-16 20:17 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-16 20:17 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-16 20:17 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-11-16 20:15 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-16 20:14 - 2013-11-12 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-16 20:09 - 2006-11-02 11:23 - 00000179 _____ C:\Windows\win.ini
2013-11-16 20:01 - 2013-11-16 12:26 - 00016010 _____ C:\Windows\PFRO.log
2013-11-16 18:32 - 2013-11-16 18:32 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-16 18:27 - 2013-11-16 18:27 - 00000876 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-16 18:27 - 2013-11-16 18:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-16 18:25 - 2013-11-16 18:24 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\pc\Desktop\mbam-setup-1.75.0.1300.exe
2013-11-16 12:26 - 2013-11-16 12:26 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-15 20:11 - 2013-11-15 20:09 - 00022034 _____ C:\Users\pc\Desktop\Addition.txt
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-15 20:02 - 2013-11-15 20:01 - 01090529 _____ (Farbar) C:\Users\pc\Desktop\FRST.exe
2013-11-14 18:08 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-11-14 17:48 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 17:33 - 2013-10-11 10:50 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 17:28 - 2006-11-02 11:24 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-11-14 07:18 - 2006-11-02 11:33 - 01559288 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-13 17:18 - 2013-10-28 10:48 - 00000000 ____D C:\Users\pc\Desktop\Neuer Ordner
2013-11-13 11:55 - 2013-11-13 11:55 - 00002397 _____ C:\Users\pc\Desktop\FSS.txt
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Program Files\Google
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 21:20 - 2011-02-25 15:30 - 00000000 ____D C:\Users\pc\AppData\Local\Adobe
2013-11-12 19:37 - 2013-10-29 04:57 - 00000000 ____D C:\Program Files\OXXOGames
2013-11-12 19:11 - 2012-07-11 09:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-12 19:10 - 2011-09-16 13:45 - 00000000 ____D C:\ProgramData\Uniblue
2013-11-12 17:04 - 2013-11-12 17:03 - 00586560 _____ C:\EamClean.log
2013-11-12 14:17 - 2013-11-06 18:02 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-11 09:42 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\Skype
2013-11-11 04:06 - 2013-11-11 04:06 - 00000858 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:44 - 2011-05-07 02:20 - 00000000 ____D C:\Users\pc\AppData\Roaming\Dropbox
2013-11-09 17:42 - 2011-05-07 02:25 - 00000000 ___RD C:\Users\pc\Dropbox
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 07:22 - 2013-11-06 07:22 - 00001638 _____ C:\Users\pc\Desktop\AbAlarm.lnk
2013-11-03 20:30 - 2010-10-15 17:12 - 00000000 ____D C:\Users\pc
2013-11-02 08:14 - 2011-10-29 19:03 - 00000000 ____D C:\Windows\CleverPrint
2013-11-02 08:12 - 2011-07-08 16:12 - 00000000 ____D C:\Program Files\MailXXL.com Tools
2013-11-02 08:11 - 2011-07-08 10:51 - 01095982 _____ C:\ndsvc.log
2013-11-02 08:07 - 2012-08-16 09:16 - 00000000 ____D C:\Program Files\Panda Security
2013-10-31 20:33 - 2011-02-05 09:46 - 00000000 ____D C:\Users\pc\Desktop\diverse
2013-10-30 09:35 - 2013-10-24 09:44 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-28 23:09 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public
2013-10-27 19:21 - 2013-10-27 19:21 - 00001862 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 19:20 - 2011-06-29 19:12 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-10-27 19:20 - 2011-02-25 14:50 - 00000000 ____D C:\ProgramData\Adobe
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:29 - 2013-10-27 12:30 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-27 12:29 - 2011-07-02 15:35 - 00000000 ____D C:\Program Files\Java
2013-10-25 20:25 - 2012-07-22 08:55 - 00000000 ____D C:\Users\pc\AppData\Local\Paint.NET
2013-10-24 20:04 - 2011-05-07 02:21 - 00000000 ____D C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-21 00:01 - 2011-05-07 02:25 - 00000920 _____ C:\Users\pc\Desktop\Dropbox.lnk
2013-10-20 23:22 - 2010-10-19 02:53 - 00000000 ____D C:\Users\pc\AppData\Local\Microsoft Games

Some content of TEMP:
====================
C:\Users\pc\AppData\Local\temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-16 20:24

==================== End Of Log ============================

--- --- ---

--- --- ---

schrauber 17.11.2013 07:37


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme? :)

mädchen 17.11.2013 18:29

Guten Abend Schrauber,


ich habe Eset log txt nicht finden können,macht aber nix denke ich weil Eset nichts festgestellt hat.


Results of screen317's Security Check version 0.99.76
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Emsisoft Anti-Malware
Avira Desktop
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````

Das ist ja echt viel Arbeit einen PC zu säubern,Mann on Mann.
Schönen Abend noch!

mädchen
Malwarebytes Anti-Malware Version 1.75.0.1300
Java 7 Update 45
Adobe Reader 10.1.8 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Emsisoft Anti-Malware a2service.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
Emsisoft Anti-Malware a2guard.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````





FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-11-2013 02
Ran by pc (administrator) on PC-PC on 17-11-2013 18:20:18
Running from C:\Users\pc\Downloads
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\system32\PrintCtrl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\system32\PrintDisp.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Uniblue Systems Limited) C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
() C:\Program Files\Mobile Partner\Mobile Partner.exe
(Lunascape Corporation) C:\Program Files\Lunascape\Lunascape6\Luna.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor)
HKLM\...\Run: [PrintDisp] - C:\Windows\System32\PrintDisp.exe [830464 2012-05-30] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-07-17] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2009-05-25] ()
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - DefaultScope {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 193.189.244.225 193.189.244.206
Tcpip\..\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: [NameServer]132.252.3.10,132.252.1.7

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-17] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-09] (Avira Operations GmbH & Co. KG)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] ()
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [77824 2012-01-20] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
S2 vToolbarUpdater13.0.0;

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [57944 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-08-22] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [26984 2012-10-07] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-07-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-08-19] (Emsisoft GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; No ImagePath
S3 IpInIp; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-17 18:20 - 2013-11-17 18:20 - 00009062 _____ C:\Users\pc\Downloads\FRST.txt
2013-11-17 18:19 - 2013-11-17 18:19 - 01090935 _____ (Farbar) C:\Users\pc\Downloads\FRST.exe
2013-11-17 18:16 - 2013-11-17 18:16 - 00001085 _____ C:\Users\pc\Desktop\checkup.txt
2013-11-17 18:08 - 2013-11-17 18:10 - 00891184 _____ C:\Users\pc\Desktop\SecurityCheck.exe
2013-11-17 14:44 - 2013-11-17 14:45 - 02347384 _____ (ESET) C:\Users\pc\Desktop\esetsmartinstaller_enu.exe
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-17 11:37 - 2013-11-17 11:37 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-17 11:31 - 2013-11-17 14:36 - 00005632 _____ C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-11-17 08:25 - 2013-11-17 18:17 - 00019176 _____ C:\Windows\WindowsUpdate.log
2013-11-17 08:21 - 2013-11-17 08:21 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-17 08:21 - 2013-11-17 08:21 - 00000812 _____ C:\Windows\PFRO.log
2013-11-16 22:44 - 2013-11-17 18:18 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:26 - 2013-11-16 20:27 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 18:26 - 2013-11-16 18:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-16 18:26 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 17:42 - 2013-10-13 11:42 - 12344832 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 17:42 - 2013-10-13 11:08 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 17:42 - 2013-10-13 10:48 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 17:42 - 2013-10-13 10:37 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 17:42 - 2013-10-13 10:35 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-14 17:42 - 2013-10-13 10:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 17:42 - 2013-10-13 10:33 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-14 17:42 - 2013-10-13 10:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-14 17:42 - 2013-10-13 10:29 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 17:42 - 2013-10-13 10:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-14 17:42 - 2013-10-13 10:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 17:42 - 2013-10-13 10:20 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 16:15 - 2013-10-11 03:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 16:15 - 2013-10-11 03:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 16:15 - 2013-10-11 01:39 - 00218228 _____ C:\Windows\system32\WFP.TMF
2013-11-14 16:15 - 2013-10-03 13:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 16:15 - 2013-10-03 13:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 19:05 - 2013-11-16 20:14 - 00000000 ____D C:\AdwCleaner
2013-11-12 17:03 - 2013-11-12 17:04 - 00586560 _____ C:\EamClean.log
2013-11-11 04:05 - 2013-11-17 17:22 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 18:02 - 2013-11-12 14:17 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-06 18:02 - 2013-11-11 09:42 - 00000000 ____D C:\ProgramData\Skype
2013-10-29 09:29 - 2013-11-17 14:13 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-29 04:57 - 2013-11-12 19:37 - 00000000 ____D C:\Program Files\OXXOGames
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 17:06 - 2013-11-17 17:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:30 - 2013-10-27 12:29 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-24 09:44 - 2013-10-30 09:35 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-20 23:55 - 2013-11-16 23:52 - 00000000 ____D C:\Users\pc\Desktop\lookin back

==================== One Month Modified Files and Folders =======

2013-11-17 18:21 - 2013-11-17 18:20 - 00009062 _____ C:\Users\pc\Downloads\FRST.txt
2013-11-17 18:19 - 2013-11-17 18:19 - 01090935 _____ (Farbar) C:\Users\pc\Downloads\FRST.exe
2013-11-17 18:18 - 2013-11-16 22:44 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-11-17 18:17 - 2013-11-17 08:25 - 00019176 _____ C:\Windows\WindowsUpdate.log
2013-11-17 18:16 - 2013-11-17 18:16 - 00001085 _____ C:\Users\pc\Desktop\checkup.txt
2013-11-17 18:12 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-17 18:12 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-17 18:10 - 2013-11-17 18:08 - 00891184 _____ C:\Users\pc\Desktop\SecurityCheck.exe
2013-11-17 17:50 - 2012-06-07 22:26 - 00000332 _____ C:\Windows\Tasks\HP Photo Creations Communicator.job
2013-11-17 17:24 - 2013-10-27 17:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-17 17:22 - 2013-11-11 04:05 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-17 14:45 - 2013-11-17 14:44 - 02347384 _____ (ESET) C:\Users\pc\Desktop\esetsmartinstaller_enu.exe
2013-11-17 14:39 - 2006-11-02 11:33 - 01559288 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-17 14:36 - 2013-11-17 11:31 - 00005632 _____ C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-11-17 14:14 - 2012-09-01 19:03 - 00000260 _____ C:\Windows\Tasks\AbelssoftPreloader.job
2013-11-17 14:13 - 2013-10-29 09:29 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-11-17 14:13 - 2012-08-17 10:27 - 00000270 _____ C:\Windows\Tasks\CheckDriveBackgroundGuard.job
2013-11-17 14:12 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-17 14:12 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-11-17 12:04 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-17 11:48 - 2011-02-05 09:46 - 00000000 ____D C:\Users\pc\Desktop\diverse
2013-11-17 11:37 - 2013-11-17 11:37 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-17 08:21 - 2013-11-17 08:21 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-17 08:21 - 2013-11-17 08:21 - 00000812 _____ C:\Windows\PFRO.log
2013-11-16 23:52 - 2013-10-20 23:55 - 00000000 ____D C:\Users\pc\Desktop\lookin back
2013-11-16 22:26 - 2010-10-15 17:12 - 00000000 ____D C:\Users\pc
2013-11-16 22:24 - 2011-05-07 02:25 - 00000000 ___RD C:\Users\pc\Dropbox
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:27 - 2013-11-16 20:26 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 20:14 - 2013-11-12 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-16 20:09 - 2006-11-02 11:23 - 00000179 _____ C:\Windows\win.ini
2013-11-16 18:27 - 2013-11-16 18:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 18:08 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-11-14 17:48 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 17:33 - 2013-10-11 10:50 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 17:28 - 2006-11-02 11:24 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Program Files\Google
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 21:20 - 2011-02-25 15:30 - 00000000 ____D C:\Users\pc\AppData\Local\Adobe
2013-11-12 19:37 - 2013-10-29 04:57 - 00000000 ____D C:\Program Files\OXXOGames
2013-11-12 19:11 - 2012-07-11 09:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-12 19:10 - 2011-09-16 13:45 - 00000000 ____D C:\ProgramData\Uniblue
2013-11-12 17:04 - 2013-11-12 17:03 - 00586560 _____ C:\EamClean.log
2013-11-12 14:17 - 2013-11-06 18:02 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-11 09:42 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\Skype
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:44 - 2011-05-07 02:20 - 00000000 ____D C:\Users\pc\AppData\Roaming\Dropbox
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-02 08:14 - 2011-10-29 19:03 - 00000000 ____D C:\Windows\CleverPrint
2013-11-02 08:12 - 2011-07-08 16:12 - 00000000 ____D C:\Program Files\MailXXL.com Tools
2013-11-02 08:11 - 2011-07-08 10:51 - 01095982 _____ C:\ndsvc.log
2013-11-02 08:07 - 2012-08-16 09:16 - 00000000 ____D C:\Program Files\Panda Security
2013-10-30 09:35 - 2013-10-24 09:44 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-28 23:09 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 19:20 - 2011-06-29 19:12 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-10-27 19:20 - 2011-02-25 14:50 - 00000000 ____D C:\ProgramData\Adobe
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:29 - 2013-10-27 12:30 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-27 12:29 - 2011-07-02 15:35 - 00000000 ____D C:\Program Files\Java
2013-10-25 20:25 - 2012-07-22 08:55 - 00000000 ____D C:\Users\pc\AppData\Local\Paint.NET
2013-10-24 20:04 - 2011-05-07 02:21 - 00000000 ____D C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-21 00:01 - 2011-05-07 02:25 - 00000920 _____ C:\Users\pc\Desktop\Dropbox.lnk
2013-10-20 23:22 - 2010-10-19 02:53 - 00000000 ____D C:\Users\pc\AppData\Local\Microsoft Games

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-17 14:20

==================== End Of Log ============================

--- --- ---

--- --- ---

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-11-2013 02
Ran by pc (administrator) on PC-PC on 17-11-2013 18:20:18
Running from C:\Users\pc\Downloads
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\system32\PrintCtrl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\system32\PrintDisp.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Uniblue Systems Limited) C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
() C:\Program Files\Mobile Partner\Mobile Partner.exe
(Lunascape Corporation) C:\Program Files\Lunascape\Lunascape6\Luna.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor)
HKLM\...\Run: [PrintDisp] - C:\Windows\System32\PrintDisp.exe [830464 2012-05-30] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-07-17] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2009-05-25] ()
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - DefaultScope {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 193.189.244.225 193.189.244.206
Tcpip\..\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: [NameServer]132.252.3.10,132.252.1.7

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-17] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-09] (Avira Operations GmbH & Co. KG)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] ()
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [77824 2012-01-20] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
S2 vToolbarUpdater13.0.0;

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [57944 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-08-22] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [26984 2012-10-07] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-07-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-08-19] (Emsisoft GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; No ImagePath
S3 IpInIp; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-17 18:20 - 2013-11-17 18:20 - 00009062 _____ C:\Users\pc\Downloads\FRST.txt
2013-11-17 18:19 - 2013-11-17 18:19 - 01090935 _____ (Farbar) C:\Users\pc\Downloads\FRST.exe
2013-11-17 18:16 - 2013-11-17 18:16 - 00001085 _____ C:\Users\pc\Desktop\checkup.txt
2013-11-17 18:08 - 2013-11-17 18:10 - 00891184 _____ C:\Users\pc\Desktop\SecurityCheck.exe
2013-11-17 14:44 - 2013-11-17 14:45 - 02347384 _____ (ESET) C:\Users\pc\Desktop\esetsmartinstaller_enu.exe
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-17 11:37 - 2013-11-17 11:37 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-17 11:31 - 2013-11-17 14:36 - 00005632 _____ C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-11-17 08:25 - 2013-11-17 18:17 - 00019176 _____ C:\Windows\WindowsUpdate.log
2013-11-17 08:21 - 2013-11-17 08:21 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-17 08:21 - 2013-11-17 08:21 - 00000812 _____ C:\Windows\PFRO.log
2013-11-16 22:44 - 2013-11-17 18:18 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:26 - 2013-11-16 20:27 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 18:26 - 2013-11-16 18:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-16 18:26 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 17:42 - 2013-10-13 11:42 - 12344832 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 17:42 - 2013-10-13 11:08 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 17:42 - 2013-10-13 10:48 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 17:42 - 2013-10-13 10:37 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 17:42 - 2013-10-13 10:35 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-14 17:42 - 2013-10-13 10:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 17:42 - 2013-10-13 10:33 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-14 17:42 - 2013-10-13 10:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-14 17:42 - 2013-10-13 10:29 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 17:42 - 2013-10-13 10:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-14 17:42 - 2013-10-13 10:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 17:42 - 2013-10-13 10:20 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 16:15 - 2013-10-11 03:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 16:15 - 2013-10-11 03:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 16:15 - 2013-10-11 01:39 - 00218228 _____ C:\Windows\system32\WFP.TMF
2013-11-14 16:15 - 2013-10-03 13:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 16:15 - 2013-10-03 13:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 19:05 - 2013-11-16 20:14 - 00000000 ____D C:\AdwCleaner
2013-11-12 17:03 - 2013-11-12 17:04 - 00586560 _____ C:\EamClean.log
2013-11-11 04:05 - 2013-11-17 17:22 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 18:02 - 2013-11-12 14:17 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-06 18:02 - 2013-11-11 09:42 - 00000000 ____D C:\ProgramData\Skype
2013-10-29 09:29 - 2013-11-17 14:13 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-29 04:57 - 2013-11-12 19:37 - 00000000 ____D C:\Program Files\OXXOGames
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 17:06 - 2013-11-17 17:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:30 - 2013-10-27 12:29 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-24 09:44 - 2013-10-30 09:35 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-20 23:55 - 2013-11-16 23:52 - 00000000 ____D C:\Users\pc\Desktop\lookin back

==================== One Month Modified Files and Folders =======

2013-11-17 18:21 - 2013-11-17 18:20 - 00009062 _____ C:\Users\pc\Downloads\FRST.txt
2013-11-17 18:19 - 2013-11-17 18:19 - 01090935 _____ (Farbar) C:\Users\pc\Downloads\FRST.exe
2013-11-17 18:18 - 2013-11-16 22:44 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-11-17 18:17 - 2013-11-17 08:25 - 00019176 _____ C:\Windows\WindowsUpdate.log
2013-11-17 18:16 - 2013-11-17 18:16 - 00001085 _____ C:\Users\pc\Desktop\checkup.txt
2013-11-17 18:12 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-17 18:12 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-17 18:10 - 2013-11-17 18:08 - 00891184 _____ C:\Users\pc\Desktop\SecurityCheck.exe
2013-11-17 17:50 - 2012-06-07 22:26 - 00000332 _____ C:\Windows\Tasks\HP Photo Creations Communicator.job
2013-11-17 17:24 - 2013-10-27 17:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-17 17:22 - 2013-11-11 04:05 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-17 14:45 - 2013-11-17 14:44 - 02347384 _____ (ESET) C:\Users\pc\Desktop\esetsmartinstaller_enu.exe
2013-11-17 14:39 - 2006-11-02 11:33 - 01559288 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-17 14:36 - 2013-11-17 11:31 - 00005632 _____ C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-11-17 14:14 - 2012-09-01 19:03 - 00000260 _____ C:\Windows\Tasks\AbelssoftPreloader.job
2013-11-17 14:13 - 2013-10-29 09:29 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-11-17 14:13 - 2012-08-17 10:27 - 00000270 _____ C:\Windows\Tasks\CheckDriveBackgroundGuard.job
2013-11-17 14:12 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-17 14:12 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-11-17 12:04 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-17 11:48 - 2011-02-05 09:46 - 00000000 ____D C:\Users\pc\Desktop\diverse
2013-11-17 11:37 - 2013-11-17 11:37 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-17 08:21 - 2013-11-17 08:21 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-17 08:21 - 2013-11-17 08:21 - 00000812 _____ C:\Windows\PFRO.log
2013-11-16 23:52 - 2013-10-20 23:55 - 00000000 ____D C:\Users\pc\Desktop\lookin back
2013-11-16 22:26 - 2010-10-15 17:12 - 00000000 ____D C:\Users\pc
2013-11-16 22:24 - 2011-05-07 02:25 - 00000000 ___RD C:\Users\pc\Dropbox
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:27 - 2013-11-16 20:26 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 20:14 - 2013-11-12 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-16 20:09 - 2006-11-02 11:23 - 00000179 _____ C:\Windows\win.ini
2013-11-16 18:27 - 2013-11-16 18:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 18:08 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-11-14 17:48 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 17:33 - 2013-10-11 10:50 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 17:28 - 2006-11-02 11:24 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Program Files\Google
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 21:20 - 2011-02-25 15:30 - 00000000 ____D C:\Users\pc\AppData\Local\Adobe
2013-11-12 19:37 - 2013-10-29 04:57 - 00000000 ____D C:\Program Files\OXXOGames
2013-11-12 19:11 - 2012-07-11 09:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-12 19:10 - 2011-09-16 13:45 - 00000000 ____D C:\ProgramData\Uniblue
2013-11-12 17:04 - 2013-11-12 17:03 - 00586560 _____ C:\EamClean.log
2013-11-12 14:17 - 2013-11-06 18:02 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-11 09:42 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\Skype
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:44 - 2011-05-07 02:20 - 00000000 ____D C:\Users\pc\AppData\Roaming\Dropbox
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-02 08:14 - 2011-10-29 19:03 - 00000000 ____D C:\Windows\CleverPrint
2013-11-02 08:12 - 2011-07-08 16:12 - 00000000 ____D C:\Program Files\MailXXL.com Tools
2013-11-02 08:11 - 2011-07-08 10:51 - 01095982 _____ C:\ndsvc.log
2013-11-02 08:07 - 2012-08-16 09:16 - 00000000 ____D C:\Program Files\Panda Security
2013-10-30 09:35 - 2013-10-24 09:44 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-28 23:09 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 19:20 - 2011-06-29 19:12 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-10-27 19:20 - 2011-02-25 14:50 - 00000000 ____D C:\ProgramData\Adobe
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:29 - 2013-10-27 12:30 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-27 12:29 - 2011-07-02 15:35 - 00000000 ____D C:\Program Files\Java
2013-10-25 20:25 - 2012-07-22 08:55 - 00000000 ____D C:\Users\pc\AppData\Local\Paint.NET
2013-10-24 20:04 - 2011-05-07 02:21 - 00000000 ____D C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-21 00:01 - 2011-05-07 02:25 - 00000920 _____ C:\Users\pc\Desktop\Dropbox.lnk
2013-10-20 23:22 - 2010-10-19 02:53 - 00000000 ____D C:\Users\pc\AppData\Local\Microsoft Games

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-17 14:20

==================== End Of Log ============================

--- --- ---

--- --- ---

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-11-2013 02
Ran by pc (administrator) on PC-PC on 17-11-2013 18:20:18
Running from C:\Users\pc\Downloads
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\system32\PrintCtrl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\system32\PrintDisp.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Uniblue Systems Limited) C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
() C:\Program Files\Mobile Partner\Mobile Partner.exe
(Lunascape Corporation) C:\Program Files\Lunascape\Lunascape6\Luna.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor)
HKLM\...\Run: [PrintDisp] - C:\Windows\System32\PrintDisp.exe [830464 2012-05-30] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-07-17] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2009-05-25] ()
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - DefaultScope {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 193.189.244.225 193.189.244.206
Tcpip\..\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: [NameServer]132.252.3.10,132.252.1.7

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-17] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-09] (Avira Operations GmbH & Co. KG)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] ()
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [77824 2012-01-20] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
S2 vToolbarUpdater13.0.0;

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [57944 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-08-22] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [26984 2012-10-07] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-07-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-08-19] (Emsisoft GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; No ImagePath
S3 IpInIp; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-17 18:20 - 2013-11-17 18:20 - 00009062 _____ C:\Users\pc\Downloads\FRST.txt
2013-11-17 18:19 - 2013-11-17 18:19 - 01090935 _____ (Farbar) C:\Users\pc\Downloads\FRST.exe
2013-11-17 18:16 - 2013-11-17 18:16 - 00001085 _____ C:\Users\pc\Desktop\checkup.txt
2013-11-17 18:08 - 2013-11-17 18:10 - 00891184 _____ C:\Users\pc\Desktop\SecurityCheck.exe
2013-11-17 14:44 - 2013-11-17 14:45 - 02347384 _____ (ESET) C:\Users\pc\Desktop\esetsmartinstaller_enu.exe
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-17 11:37 - 2013-11-17 11:37 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-17 11:31 - 2013-11-17 14:36 - 00005632 _____ C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-11-17 08:25 - 2013-11-17 18:17 - 00019176 _____ C:\Windows\WindowsUpdate.log
2013-11-17 08:21 - 2013-11-17 08:21 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-17 08:21 - 2013-11-17 08:21 - 00000812 _____ C:\Windows\PFRO.log
2013-11-16 22:44 - 2013-11-17 18:18 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:26 - 2013-11-16 20:27 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 18:26 - 2013-11-16 18:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-16 18:26 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 17:42 - 2013-10-13 11:42 - 12344832 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 17:42 - 2013-10-13 11:08 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 17:42 - 2013-10-13 10:48 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 17:42 - 2013-10-13 10:37 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 17:42 - 2013-10-13 10:35 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-14 17:42 - 2013-10-13 10:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 17:42 - 2013-10-13 10:33 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-14 17:42 - 2013-10-13 10:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-14 17:42 - 2013-10-13 10:29 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 17:42 - 2013-10-13 10:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-14 17:42 - 2013-10-13 10:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 17:42 - 2013-10-13 10:20 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 16:15 - 2013-10-11 03:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 16:15 - 2013-10-11 03:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 16:15 - 2013-10-11 01:39 - 00218228 _____ C:\Windows\system32\WFP.TMF
2013-11-14 16:15 - 2013-10-03 13:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 16:15 - 2013-10-03 13:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 19:05 - 2013-11-16 20:14 - 00000000 ____D C:\AdwCleaner
2013-11-12 17:03 - 2013-11-12 17:04 - 00586560 _____ C:\EamClean.log
2013-11-11 04:05 - 2013-11-17 17:22 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 18:02 - 2013-11-12 14:17 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-06 18:02 - 2013-11-11 09:42 - 00000000 ____D C:\ProgramData\Skype
2013-10-29 09:29 - 2013-11-17 14:13 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-29 04:57 - 2013-11-12 19:37 - 00000000 ____D C:\Program Files\OXXOGames
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 17:06 - 2013-11-17 17:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:30 - 2013-10-27 12:29 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-24 09:44 - 2013-10-30 09:35 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-20 23:55 - 2013-11-16 23:52 - 00000000 ____D C:\Users\pc\Desktop\lookin back

==================== One Month Modified Files and Folders =======

2013-11-17 18:21 - 2013-11-17 18:20 - 00009062 _____ C:\Users\pc\Downloads\FRST.txt
2013-11-17 18:19 - 2013-11-17 18:19 - 01090935 _____ (Farbar) C:\Users\pc\Downloads\FRST.exe
2013-11-17 18:18 - 2013-11-16 22:44 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-11-17 18:17 - 2013-11-17 08:25 - 00019176 _____ C:\Windows\WindowsUpdate.log
2013-11-17 18:16 - 2013-11-17 18:16 - 00001085 _____ C:\Users\pc\Desktop\checkup.txt
2013-11-17 18:12 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-17 18:12 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-17 18:10 - 2013-11-17 18:08 - 00891184 _____ C:\Users\pc\Desktop\SecurityCheck.exe
2013-11-17 17:50 - 2012-06-07 22:26 - 00000332 _____ C:\Windows\Tasks\HP Photo Creations Communicator.job
2013-11-17 17:24 - 2013-10-27 17:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-17 17:22 - 2013-11-11 04:05 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-17 14:45 - 2013-11-17 14:44 - 02347384 _____ (ESET) C:\Users\pc\Desktop\esetsmartinstaller_enu.exe
2013-11-17 14:39 - 2006-11-02 11:33 - 01559288 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-17 14:36 - 2013-11-17 11:31 - 00005632 _____ C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-11-17 14:14 - 2012-09-01 19:03 - 00000260 _____ C:\Windows\Tasks\AbelssoftPreloader.job
2013-11-17 14:13 - 2013-10-29 09:29 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-11-17 14:13 - 2012-08-17 10:27 - 00000270 _____ C:\Windows\Tasks\CheckDriveBackgroundGuard.job
2013-11-17 14:12 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-17 14:12 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-11-17 12:04 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-17 11:48 - 2011-02-05 09:46 - 00000000 ____D C:\Users\pc\Desktop\diverse
2013-11-17 11:37 - 2013-11-17 11:37 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-17 08:21 - 2013-11-17 08:21 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-17 08:21 - 2013-11-17 08:21 - 00000812 _____ C:\Windows\PFRO.log
2013-11-16 23:52 - 2013-10-20 23:55 - 00000000 ____D C:\Users\pc\Desktop\lookin back
2013-11-16 22:26 - 2010-10-15 17:12 - 00000000 ____D C:\Users\pc
2013-11-16 22:24 - 2011-05-07 02:25 - 00000000 ___RD C:\Users\pc\Dropbox
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:27 - 2013-11-16 20:26 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 20:14 - 2013-11-12 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-16 20:09 - 2006-11-02 11:23 - 00000179 _____ C:\Windows\win.ini
2013-11-16 18:27 - 2013-11-16 18:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 18:08 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-11-14 17:48 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 17:33 - 2013-10-11 10:50 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 17:28 - 2006-11-02 11:24 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Program Files\Google
2013-11-12 21:37 - 2013-11-12 21:37 - 00000000 ____D C:\Program Files\ESET
2013-11-12 21:20 - 2011-02-25 15:30 - 00000000 ____D C:\Users\pc\AppData\Local\Adobe
2013-11-12 19:37 - 2013-10-29 04:57 - 00000000 ____D C:\Program Files\OXXOGames
2013-11-12 19:11 - 2012-07-11 09:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-12 19:10 - 2011-09-16 13:45 - 00000000 ____D C:\ProgramData\Uniblue
2013-11-12 17:04 - 2013-11-12 17:03 - 00586560 _____ C:\EamClean.log
2013-11-12 14:17 - 2013-11-06 18:02 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-11 09:42 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\Skype
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:44 - 2011-05-07 02:20 - 00000000 ____D C:\Users\pc\AppData\Roaming\Dropbox
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-02 08:14 - 2011-10-29 19:03 - 00000000 ____D C:\Windows\CleverPrint
2013-11-02 08:12 - 2011-07-08 16:12 - 00000000 ____D C:\Program Files\MailXXL.com Tools
2013-11-02 08:11 - 2011-07-08 10:51 - 01095982 _____ C:\ndsvc.log
2013-11-02 08:07 - 2012-08-16 09:16 - 00000000 ____D C:\Program Files\Panda Security
2013-10-30 09:35 - 2013-10-24 09:44 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-28 23:09 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 19:20 - 2011-06-29 19:12 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-10-27 19:20 - 2011-02-25 14:50 - 00000000 ____D C:\ProgramData\Adobe
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:29 - 2013-10-27 12:30 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-27 12:29 - 2011-07-02 15:35 - 00000000 ____D C:\Program Files\Java
2013-10-25 20:25 - 2012-07-22 08:55 - 00000000 ____D C:\Users\pc\AppData\Local\Paint.NET
2013-10-24 20:04 - 2011-05-07 02:21 - 00000000 ____D C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-21 00:01 - 2011-05-07 02:25 - 00000920 _____ C:\Users\pc\Desktop\Dropbox.lnk
2013-10-20 23:22 - 2010-10-19 02:53 - 00000000 ____D C:\Users\pc\AppData\Local\Microsoft Games

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-17 14:20

==================== End Of Log ============================

--- --- ---

--- --- ---

schrauber 18.11.2013 10:07

Fertig :)

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.

mädchen 18.11.2013 10:41

Hi Schrauber,

halt! Bitte noch nicht löschen,ich habe nach wie vor Probleme mit dem PC. Einzelne Desktopsymbole sind nach jedem Start verschoben,oder die Icons verändert,statt des Symboles ein Blatt Papier.Text eingeben ist öfter schwierig,Cursor setzen geht manchmal nicht,manchmal kein Mausanzeiger.Darstellung mehrerer Seiten auf einmal in Bruchstücken.Verzögerte Reaktion auf anklicken.Doppelklick funktioniert öfter gar nicht.Programme hängen fest und reagieren mit Glück ein paar Minuten später.
Schluchz, you tube Videos kann ich immer noch nicht sehen.Text markieren funtioniert manchmal,manchmal aber auch nicht.Ständige Nerverei: Dieses Programm kann die Webseite nicht anzeigen.Mit jedem Start wird der Drucker automatisch neu installiert.Das Umschalten zwischen den Seiten dauert ewig,der reagiert oft gar nicht auf das anklicken.Beim eingeben von Text nimmt er oft nur die Hälfte der Buchstaben an.

Ich werde das alles beherzigen was du mir an Tipps gegeben hast.Vielen Dank .
Wenn ich mir mal wieder was einfangen sollte,kann ich dann diese ganze Anleitung einmal abarbeiten? Oder ist das je nachdem welche Störungen vorliegen auch mal anders?

LG,mädchen

schrauber 18.11.2013 14:52

Deswegen stelle ich nach jeder Anweisung die Frage "Noch Probleme" ;)

Und diese Frage hast Du sauber ignoriert ;)

Poste nochmal frische FRST Logs bitte.

mädchen 19.11.2013 15:55

Hallo Schrauber,
ich hab das nicht ignoriert sondern vergessen zu beantworten.Ich vergesse immer etwas....
Von deiner letzten Anweisung habe ich jetzt noch nichts gemacht. Hier die FRST Dinger
FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-11-2013
Ran by pc (administrator) on PC-PC on 19-11-2013 13:56:07
Running from C:\Users\pc\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\system32\PrintCtrl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\system32\PrintDisp.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
() C:\Program Files\Mobile Partner\Mobile Partner.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Uniblue Systems Limited) C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avcenter.exe
(Avira Operations GmbH & Co. KG) C:\ProgramData\Avira\AntiVir Desktop\TEMP\SELFUPDATE\update.exe
(Avira Operations GmbH & Co. KG) C:\ProgramData\Avira\AntiVir Desktop\TEMP\SELFUPDATE\updrgui.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Lunascape Corporation) C:\Program Files\Lunascape\Lunascape6\Luna.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor)
HKLM\...\Run: [PrintDisp] - C:\Windows\System32\PrintDisp.exe [830464 2012-05-30] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-07-17] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2009-05-25] ()
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - DefaultScope {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 193.189.244.225 193.189.244.206
Tcpip\..\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: [NameServer]132.252.3.10,132.252.1.7

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-17] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-09] (Avira Operations GmbH & Co. KG)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] ()
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [77824 2012-01-20] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
S2 vToolbarUpdater13.0.0;

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [57944 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-08-22] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [26984 2012-10-07] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-07-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-08-19] (Emsisoft GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; No ImagePath
S3 IpInIp; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-19 13:51 - 2013-11-19 13:56 - 00009218 _____ C:\Users\pc\Desktop\FRST.txt
2013-11-19 13:39 - 2013-11-19 13:39 - 01090881 _____ (Farbar) C:\Users\pc\Desktop\FRST.exe
2013-11-17 18:20 - 2013-11-17 18:22 - 00022634 _____ C:\Users\pc\Downloads\FRST.txt
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-17 11:37 - 2013-11-17 11:37 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-17 11:31 - 2013-11-17 14:36 - 00005632 _____ C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-11-17 08:25 - 2013-11-19 13:50 - 00058125 _____ C:\Windows\WindowsUpdate.log
2013-11-17 08:21 - 2013-11-17 08:21 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-17 08:21 - 2013-11-17 08:21 - 00000812 _____ C:\Windows\PFRO.log
2013-11-16 22:44 - 2013-11-18 10:15 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:26 - 2013-11-16 20:27 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 18:26 - 2013-11-16 18:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-16 18:26 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 17:42 - 2013-10-13 11:42 - 12344832 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 17:42 - 2013-10-13 11:08 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 17:42 - 2013-10-13 10:48 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 17:42 - 2013-10-13 10:37 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 17:42 - 2013-10-13 10:35 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-14 17:42 - 2013-10-13 10:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 17:42 - 2013-10-13 10:33 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-14 17:42 - 2013-10-13 10:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-14 17:42 - 2013-10-13 10:29 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 17:42 - 2013-10-13 10:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-14 17:42 - 2013-10-13 10:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 17:42 - 2013-10-13 10:20 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 16:15 - 2013-10-11 03:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 16:15 - 2013-10-11 03:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 16:15 - 2013-10-11 01:39 - 00218228 _____ C:\Windows\system32\WFP.TMF
2013-11-14 16:15 - 2013-10-03 13:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 16:15 - 2013-10-03 13:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-12 19:05 - 2013-11-16 20:14 - 00000000 ____D C:\AdwCleaner
2013-11-12 17:03 - 2013-11-12 17:04 - 00586560 _____ C:\EamClean.log
2013-11-11 04:05 - 2013-11-19 13:51 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 18:02 - 2013-11-12 14:17 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-06 18:02 - 2013-11-11 09:42 - 00000000 ____D C:\ProgramData\Skype
2013-10-29 09:29 - 2013-11-19 13:30 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-29 04:57 - 2013-11-12 19:37 - 00000000 ____D C:\Program Files\OXXOGames
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 17:06 - 2013-11-18 10:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:30 - 2013-10-27 12:29 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-24 09:44 - 2013-10-30 09:35 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-20 23:55 - 2013-11-16 23:52 - 00000000 ____D C:\Users\pc\Desktop\lookin back

==================== One Month Modified Files and Folders =======

2013-11-19 13:56 - 2013-11-19 13:51 - 00009218 _____ C:\Users\pc\Desktop\FRST.txt
2013-11-19 13:51 - 2013-11-11 04:05 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-19 13:50 - 2013-11-17 08:25 - 00058125 _____ C:\Windows\WindowsUpdate.log
2013-11-19 13:50 - 2012-06-07 22:26 - 00000332 _____ C:\Windows\Tasks\HP Photo Creations Communicator.job
2013-11-19 13:39 - 2013-11-19 13:39 - 01090881 _____ (Farbar) C:\Users\pc\Desktop\FRST.exe
2013-11-19 13:30 - 2013-10-29 09:29 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-11-19 13:30 - 2012-09-01 19:03 - 00000260 _____ C:\Windows\Tasks\AbelssoftPreloader.job
2013-11-19 13:30 - 2012-08-17 10:27 - 00000270 _____ C:\Windows\Tasks\CheckDriveBackgroundGuard.job
2013-11-19 13:30 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-19 13:30 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-19 13:30 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-11-19 13:29 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-18 10:52 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-18 10:24 - 2013-10-27 17:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-18 10:15 - 2013-11-16 22:44 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-11-17 18:22 - 2013-11-17 18:20 - 00022634 _____ C:\Users\pc\Downloads\FRST.txt
2013-11-17 14:39 - 2006-11-02 11:33 - 01559288 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-17 14:36 - 2013-11-17 11:31 - 00005632 _____ C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-17 11:48 - 2011-02-05 09:46 - 00000000 ____D C:\Users\pc\Desktop\diverse
2013-11-17 11:37 - 2013-11-17 11:37 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-17 08:21 - 2013-11-17 08:21 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-17 08:21 - 2013-11-17 08:21 - 00000812 _____ C:\Windows\PFRO.log
2013-11-16 23:52 - 2013-10-20 23:55 - 00000000 ____D C:\Users\pc\Desktop\lookin back
2013-11-16 22:26 - 2010-10-15 17:12 - 00000000 ____D C:\Users\pc
2013-11-16 22:24 - 2011-05-07 02:25 - 00000000 ___RD C:\Users\pc\Dropbox
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:27 - 2013-11-16 20:26 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 20:14 - 2013-11-12 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-16 20:09 - 2006-11-02 11:23 - 00000179 _____ C:\Windows\win.ini
2013-11-16 18:27 - 2013-11-16 18:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 18:08 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-11-14 17:48 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 17:33 - 2013-10-11 10:50 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 17:28 - 2006-11-02 11:24 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Program Files\Google
2013-11-12 21:20 - 2011-02-25 15:30 - 00000000 ____D C:\Users\pc\AppData\Local\Adobe
2013-11-12 19:37 - 2013-10-29 04:57 - 00000000 ____D C:\Program Files\OXXOGames
2013-11-12 19:11 - 2012-07-11 09:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-12 19:10 - 2011-09-16 13:45 - 00000000 ____D C:\ProgramData\Uniblue
2013-11-12 17:04 - 2013-11-12 17:03 - 00586560 _____ C:\EamClean.log
2013-11-12 14:17 - 2013-11-06 18:02 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-11 09:42 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\Skype
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:44 - 2011-05-07 02:20 - 00000000 ____D C:\Users\pc\AppData\Roaming\Dropbox
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-02 08:14 - 2011-10-29 19:03 - 00000000 ____D C:\Windows\CleverPrint
2013-11-02 08:12 - 2011-07-08 16:12 - 00000000 ____D C:\Program Files\MailXXL.com Tools
2013-11-02 08:11 - 2011-07-08 10:51 - 01095982 _____ C:\ndsvc.log
2013-11-02 08:07 - 2012-08-16 09:16 - 00000000 ____D C:\Program Files\Panda Security
2013-10-30 09:35 - 2013-10-24 09:44 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-28 23:09 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 19:20 - 2011-06-29 19:12 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-10-27 19:20 - 2011-02-25 14:50 - 00000000 ____D C:\ProgramData\Adobe
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:29 - 2013-10-27 12:30 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-27 12:29 - 2011-07-02 15:35 - 00000000 ____D C:\Program Files\Java
2013-10-25 20:25 - 2012-07-22 08:55 - 00000000 ____D C:\Users\pc\AppData\Local\Paint.NET
2013-10-24 20:04 - 2011-05-07 02:21 - 00000000 ____D C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-21 00:01 - 2011-05-07 02:25 - 00000920 _____ C:\Users\pc\Desktop\Dropbox.lnk
2013-10-20 23:22 - 2010-10-19 02:53 - 00000000 ____D C:\Users\pc\AppData\Local\Microsoft Games

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-19 13:38

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-11-2013
Ran by pc (administrator) on PC-PC on 19-11-2013 13:56:07
Running from C:\Users\pc\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\system32\PrintCtrl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\system32\PrintDisp.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
() C:\Program Files\Mobile Partner\Mobile Partner.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Uniblue Systems Limited) C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avcenter.exe
(Avira Operations GmbH & Co. KG) C:\ProgramData\Avira\AntiVir Desktop\TEMP\SELFUPDATE\update.exe
(Avira Operations GmbH & Co. KG) C:\ProgramData\Avira\AntiVir Desktop\TEMP\SELFUPDATE\updrgui.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Lunascape Corporation) C:\Program Files\Lunascape\Lunascape6\Luna.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor)
HKLM\...\Run: [PrintDisp] - C:\Windows\System32\PrintDisp.exe [830464 2012-05-30] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-07-17] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2009-05-25] ()
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - DefaultScope {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - {7C788BE1-99B0-40CD-B58C-788705E205E2} URL = hxxp://www.bing.com/search?q={searchTerms}&amp;amp;amp;form=MSITDF&amp;amp;amp;pc=MAMI&amp;amp;amp;src=IE-SearchBox
SearchScopes: HKCU - {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 193.189.244.225 193.189.244.206
Tcpip\..\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: [NameServer]132.252.3.10,132.252.1.7

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-17] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-09] (Avira Operations GmbH & Co. KG)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] ()
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [77824 2012-01-20] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
S2 vToolbarUpdater13.0.0;

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [57944 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-08-22] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [26984 2012-10-07] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-07-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-08-19] (Emsisoft GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; No ImagePath
S3 IpInIp; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-19 13:51 - 2013-11-19 13:56 - 00009218 _____ C:\Users\pc\Desktop\FRST.txt
2013-11-19 13:39 - 2013-11-19 13:39 - 01090881 _____ (Farbar) C:\Users\pc\Desktop\FRST.exe
2013-11-17 18:20 - 2013-11-17 18:22 - 00022634 _____ C:\Users\pc\Downloads\FRST.txt
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-17 11:37 - 2013-11-17 11:37 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-17 11:31 - 2013-11-17 14:36 - 00005632 _____ C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-11-17 08:25 - 2013-11-19 13:50 - 00058125 _____ C:\Windows\WindowsUpdate.log
2013-11-17 08:21 - 2013-11-17 08:21 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-17 08:21 - 2013-11-17 08:21 - 00000812 _____ C:\Windows\PFRO.log
2013-11-16 22:44 - 2013-11-18 10:15 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:26 - 2013-11-16 20:27 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 18:26 - 2013-11-16 18:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-16 18:26 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 17:42 - 2013-10-13 11:42 - 12344832 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 17:42 - 2013-10-13 11:08 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 17:42 - 2013-10-13 10:48 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 17:42 - 2013-10-13 10:37 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 17:42 - 2013-10-13 10:35 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-14 17:42 - 2013-10-13 10:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 17:42 - 2013-10-13 10:33 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-14 17:42 - 2013-10-13 10:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-14 17:42 - 2013-10-13 10:29 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 17:42 - 2013-10-13 10:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-14 17:42 - 2013-10-13 10:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 17:42 - 2013-10-13 10:20 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 16:15 - 2013-10-11 03:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 16:15 - 2013-10-11 03:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 16:15 - 2013-10-11 01:39 - 00218228 _____ C:\Windows\system32\WFP.TMF
2013-11-14 16:15 - 2013-10-03 13:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 16:15 - 2013-10-03 13:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-12 19:05 - 2013-11-16 20:14 - 00000000 ____D C:\AdwCleaner
2013-11-12 17:03 - 2013-11-12 17:04 - 00586560 _____ C:\EamClean.log
2013-11-11 04:05 - 2013-11-19 13:51 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 18:02 - 2013-11-12 14:17 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-06 18:02 - 2013-11-11 09:42 - 00000000 ____D C:\ProgramData\Skype
2013-10-29 09:29 - 2013-11-19 13:30 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-29 04:57 - 2013-11-12 19:37 - 00000000 ____D C:\Program Files\OXXOGames
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 17:06 - 2013-11-18 10:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:30 - 2013-10-27 12:29 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-24 09:44 - 2013-10-30 09:35 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-20 23:55 - 2013-11-16 23:52 - 00000000 ____D C:\Users\pc\Desktop\lookin back

==================== One Month Modified Files and Folders =======

2013-11-19 13:56 - 2013-11-19 13:51 - 00009218 _____ C:\Users\pc\Desktop\FRST.txt
2013-11-19 13:51 - 2013-11-11 04:05 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-19 13:50 - 2013-11-17 08:25 - 00058125 _____ C:\Windows\WindowsUpdate.log
2013-11-19 13:50 - 2012-06-07 22:26 - 00000332 _____ C:\Windows\Tasks\HP Photo Creations Communicator.job
2013-11-19 13:39 - 2013-11-19 13:39 - 01090881 _____ (Farbar) C:\Users\pc\Desktop\FRST.exe
2013-11-19 13:30 - 2013-10-29 09:29 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-11-19 13:30 - 2012-09-01 19:03 - 00000260 _____ C:\Windows\Tasks\AbelssoftPreloader.job
2013-11-19 13:30 - 2012-08-17 10:27 - 00000270 _____ C:\Windows\Tasks\CheckDriveBackgroundGuard.job
2013-11-19 13:30 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-19 13:30 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-19 13:30 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-11-19 13:29 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-18 10:52 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-18 10:24 - 2013-10-27 17:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-18 10:15 - 2013-11-16 22:44 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-11-17 18:22 - 2013-11-17 18:20 - 00022634 _____ C:\Users\pc\Downloads\FRST.txt
2013-11-17 14:39 - 2006-11-02 11:33 - 01559288 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-17 14:36 - 2013-11-17 11:31 - 00005632 _____ C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-17 11:48 - 2011-02-05 09:46 - 00000000 ____D C:\Users\pc\Desktop\diverse
2013-11-17 11:37 - 2013-11-17 11:37 - 00060640 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-17 08:21 - 2013-11-17 08:21 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-17 08:21 - 2013-11-17 08:21 - 00000812 _____ C:\Windows\PFRO.log
2013-11-16 23:52 - 2013-10-20 23:55 - 00000000 ____D C:\Users\pc\Desktop\lookin back
2013-11-16 22:26 - 2010-10-15 17:12 - 00000000 ____D C:\Users\pc
2013-11-16 22:24 - 2011-05-07 02:25 - 00000000 ___RD C:\Users\pc\Dropbox
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:27 - 2013-11-16 20:26 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 20:14 - 2013-11-12 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-16 20:09 - 2006-11-02 11:23 - 00000179 _____ C:\Windows\win.ini
2013-11-16 18:27 - 2013-11-16 18:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 18:08 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-11-14 17:48 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 17:33 - 2013-10-11 10:50 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 17:28 - 2006-11-02 11:24 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Program Files\Google
2013-11-12 21:20 - 2011-02-25 15:30 - 00000000 ____D C:\Users\pc\AppData\Local\Adobe
2013-11-12 19:37 - 2013-10-29 04:57 - 00000000 ____D C:\Program Files\OXXOGames
2013-11-12 19:11 - 2012-07-11 09:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-12 19:10 - 2011-09-16 13:45 - 00000000 ____D C:\ProgramData\Uniblue
2013-11-12 17:04 - 2013-11-12 17:03 - 00586560 _____ C:\EamClean.log
2013-11-12 14:17 - 2013-11-06 18:02 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-11 09:42 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\Skype
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:44 - 2011-05-07 02:20 - 00000000 ____D C:\Users\pc\AppData\Roaming\Dropbox
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-02 08:14 - 2011-10-29 19:03 - 00000000 ____D C:\Windows\CleverPrint
2013-11-02 08:12 - 2011-07-08 16:12 - 00000000 ____D C:\Program Files\MailXXL.com Tools
2013-11-02 08:11 - 2011-07-08 10:51 - 01095982 _____ C:\ndsvc.log
2013-11-02 08:07 - 2012-08-16 09:16 - 00000000 ____D C:\Program Files\Panda Security
2013-10-30 09:35 - 2013-10-24 09:44 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-28 23:09 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 19:20 - 2011-06-29 19:12 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-10-27 19:20 - 2011-02-25 14:50 - 00000000 ____D C:\ProgramData\Adobe
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:29 - 2013-10-27 12:30 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-27 12:29 - 2011-07-02 15:35 - 00000000 ____D C:\Program Files\Java
2013-10-25 20:25 - 2012-07-22 08:55 - 00000000 ____D C:\Users\pc\AppData\Local\Paint.NET
2013-10-24 20:04 - 2011-05-07 02:21 - 00000000 ____D C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-22 19:41 - 2013-10-22 19:41 - 00000212 _____ C:\Users\pc\Desktop\drucker.lnk
2013-10-21 00:01 - 2011-05-07 02:25 - 00000920 _____ C:\Users\pc\Desktop\Dropbox.lnk
2013-10-20 23:22 - 2010-10-19 02:53 - 00000000 ____D C:\Users\pc\AppData\Local\Microsoft Games

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-19 13:38

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---



Code:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 18-11-2013
Ran by pc at 2013-11-19 13:57:48
Running from C:\Users\pc\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Emsisoft Anti-Malware (Enabled - Out of date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Anti-Malware (Enabled - Out of date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}

==================== Installed Programs ======================

32 Bit HP CIO Components Installer (Version: 1.0.0)
AbAlarm (Version: 6.2)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8)
AIO_CDB_ProductContext (Version: 82.0.242.000)
AIO_CDB_Software (Version: 82.0.242.000)
AIO_Scan (Version: 82.0.173.000)
Atheros Client Installation Program (Version: 7.0)
Avira Free Antivirus (Version: 13.0.0.4052)
BufferChm (Version: 82.0.173.000)
Copy (Version: 82.0.188.000)
CustomerResearchQFolder (Version: 1.00.0000)
Destinations (Version: 82.0.173.000)
DeviceManagementQFolder (Version: 1.00.0000)
DocProc (Version: 8.1.0.0)
DocProcQFolder (Version: 1.00.0000)
Dropbox (HKCU Version: 2.0.22)
Emsisoft Anti-Malware (Version: 8.1)
eSupportQFolder (Version: 1.00.0000)
F300 (Version: 82.0.242.000)
F300_Help (Version: 82.0.242.000)
F300Trb (Version: 82.0.242.000)
Fax (Version: 82.0.188.000)
Google Earth (Version: 6.2.2.6613)
HP Customer Participation Program 8.0 (Version: 8.0)
HP Imaging Device Functions 8.0 (Version: 8.0)
HP OCR Software 8.0 (Version: 8.0)
HP Photo Creations (Version: 1.0.0.7702)
HP Photosmart Essential (Version: 1.12.0.46)
HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B (Version: 8.0)
HP Solution Center 8.0 (Version: 8.0)
HP Update (Version: 5.002.007.004)
HPProductAssistant (Version: 82.0.173.000)
HPSSupply (Version: 2.1.3.0000)
Intel(R) Graphics Media Accelerator Driver
Java 7 Update 45 (Version: 7.0.450)
Java Auto Updater (Version: 2.1.9.8)
Lunascape6 (All Users) (Version: 6.8.9.27075)
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300)
MarketResearch (Version: 82.0.174.000)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mobile Partner (Version: 11.302.09.04.382)
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MyKeyFinder (Version: 2012)
Paint.NET v3.5.10 (Version: 3.60.0)
Realtek 8169 8168 8101E 8102E Ethernet Driver (Version: 1.00.0000)
Realtek High Definition Audio Driver (Version: 6.0.1.5618)
Scan (Version: 8.1.0.0)
SolutionCenter (Version: 82.0.188.000)
Status (Version: 82.0.173.000)
Toolbox (Version: 82.0.173.000)
TrayApp (Version: 82.0.188.000)
Uniblue RegistryBooster (Version: 6.1.1.3)
UnloadSupport (Version: 1.00.0000)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (Version: 3)
Visual C++ 9.0 CRT (x86) WinSXS MSM (Version: 9.0)
WashAndGo (Version: 17.7)
WebReg (Version: 82.0.173.000)
YouTube Song Downloader (Version: 8.2)

==================== Restore Points  =========================

13-11-2013 08:48:09 Removed Bonjour
13-11-2013 10:21:05 Removed Safari
13-11-2013 10:23:53 Removed Apple Application Support
13-11-2013 10:31:48 Removed Apple Application Support
14-11-2013 16:26:44 Windows Update
17-11-2013 13:20:18 Removed Cisco EAP-FAST Module
17-11-2013 13:21:31 Removed Cisco LEAP Module
17-11-2013 13:22:09 Removed Cisco PEAP Module
19-11-2013 12:39:01 Windows Update

==================== Hosts content: ==========================

2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost
::1            localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0AD797DB-679C-4254-BF1F-187451269FBE} - System32\Tasks\RunAsStdUser Task => C:\Program Files\NetDrive\netdrive.exe
Task: {0B923855-EFEC-4D6E-BF2C-25DC4D5D10FF} - System32\Tasks\WebReg Deskjet F300 series => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe [2006-12-10] (Hewlett-Packard Co.)
Task: {139DBA5E-5972-4876-81F7-3862E17F0935} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2008-01-21] (Microsoft Corporation)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {2A4342E7-3E82-45C5-A530-C547532D3E76} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - pc => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {2DE1ED62-3B3F-4610-86ED-E838057F6213} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {47CC68FF-DD27-4AC9-BD10-1206F7305F4A} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {51C71A63-7357-4492-80C2-B8A4B3E96899} - System32\Tasks\AbelssoftPreloader => C:\Program Files\WashAndGo\AbelssoftPreloader.exe [2012-09-24] (Microsoft)
Task: {724DD079-074D-48F7-84FC-129CAE9457D2} - System32\Tasks\rbmonitor => C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe [2013-08-21] (Uniblue Systems Limited)
Task: {793C7D04-E0F7-41B2-9376-BCB3BC77411B} - System32\Tasks\CheckDriveBackgroundGuard => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: {8CFE559A-52BC-433E-B3B9-E2296815C970} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-27] (Adobe Systems Incorporated)
Task: {99982336-9432-499D-A415-B1D0E9EE6E6A} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [2006-12-10] (Hewlett-Packard Co.)
Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => C:\Windows\System32\pla.dll [2008-01-21] (Microsoft Corporation)
Task: {A7F9AF08-9C24-4D9D-A77B-6C6A29823CB3} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-12] (Microsoft Corporation)
Task: {DAF2E711-606C-4F65-B3F5-7E91ED398167} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => C:\Program Files\Windows Defender\MpCmdRun.exe [2008-01-21] (Microsoft Corporation)
Task: {DC45E898-AF81-4A07-ABC9-73FCDB16504C} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-03-02] ()
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: C:\Windows\Tasks\AbelssoftPreloader.job => C:\Program Files\WashAndGo\AbelssoftPreloader.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\CheckDriveBackgroundGuard.job => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe
Task: C:\Windows\Tasks\rbmonitor.job => C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
Task: C:\Windows\Tasks\WebReg Deskjet F300 series.job => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe

==================== Loaded Modules (whitelisted) =============

2013-10-11 12:15 - 2013-07-31 20:54 - 00394824 _____ () C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
2011-06-27 15:24 - 2007-08-23 15:39 - 00014848 _____ () C:\Program Files\Mobile Partner\isaputrace.dll
2011-06-27 15:24 - 2009-12-10 10:51 - 00114688 _____ () C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll
2011-06-27 15:24 - 2009-09-19 10:21 - 00139264 _____ () C:\Program Files\Mobile Partner\NetInfoPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:48 - 00090112 _____ () C:\Program Files\Mobile Partner\DialUpPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:54 - 00057344 _____ () C:\Program Files\Mobile Partner\ConfigFilePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:40 - 00991232 _____ () C:\Program Files\Mobile Partner\NDISAPI.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00155648 _____ () C:\Program Files\Mobile Partner\DetectDev.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00557056 _____ () C:\Program Files\Mobile Partner\atcomm.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\XCodec.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\DeviceOperate.dll
2011-06-27 15:24 - 2009-06-18 09:56 - 00032768 _____ () C:\Program Files\Mobile Partner\NotifyServicePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:52 - 00192512 _____ () C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00143360 _____ () C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll
2011-06-27 15:24 - 2007-07-31 14:50 - 00090112 _____ () C:\Program Files\Mobile Partner\FileManager.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00159744 _____ () C:\Program Files\Mobile Partner\SMSPlugin.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00201640 _____ () C:\Program Files\Java\jre7\bin\jp2iexp.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00016808 _____ () C:\Program Files\Java\jre7\bin\jp2native.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/17/2013 08:22:01 AM) (Source: Windows Search Service) (User: )
Description: Die Anwendung kann nicht initialisiert werden.

Kontext: Windows Anwendung


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/17/2013 08:22:01 AM) (Source: Windows Search Service) (User: )
Description: Das Gatherer-Objekt kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/17/2013 08:22:01 AM) (Source: Windows Search Service) (User: )
Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Element nicht gefunden.  (0x80070490)

Error: (11/17/2013 08:22:00 AM) (Source: Windows Search Service) (User: )
Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/17/2013 08:22:00 AM) (Source: Windows Search Service) (User: )
Description: Die Eigenschaftenspeicherdaten können vom Windows-Suchdienst nicht geladen werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        0x%08x (0xc0041800 - Der Inhaltsindex kann nicht gelesen werden.  )

Error: (11/17/2013 08:22:00 AM) (Source: Windows Search Service) (User: )
Description: Der Suchdienst hat beschädigte Datendateien im Index erkannt. Der Dienst versucht, dieses Problem durch Neuerstellung des Index automatisch zu beheben.


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/17/2013 08:22:00 AM) (Source: Windows Search Service) (User: )
Description: Der Jet-Eigenschaftenspeicher kann vom Windows-Suchdienst nicht geöffnet werden.


Details:
        Der Inhaltsindex kann nicht gelesen werden.  (0xc0041800)

Error: (11/17/2013 08:21:59 AM) (Source: ESENT) (User: )
Description: Windows (2264) Windows: Fehler -1811 (0xfffff8ed) beim Öffnen von Protokolldatei C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.


System errors:
=============
Error: (11/19/2013 01:33:24 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (11/19/2013 01:30:58 PM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (11/19/2013 01:30:58 PM) (Source: Service Control Manager) (User: )
Description: Net.Tcp-ListeneradapterNet.Tcp-Portfreigabedienst%%1058

Error: (11/19/2013 01:30:58 PM) (Source: Service Control Manager) (User: )
Description: Net.Pipe-Listeneradapterwas

Error: (11/19/2013 01:30:58 PM) (Source: Service Control Manager) (User: )
Description: Net.Msmq-Listeneradaptermsmq

Error: (11/18/2013 10:51:47 AM) (Source: Tcpip) (User: )
Description: Das System hat einen Adressenkonflikt der IP-Adresse 10.40.181.185 mit dem Computer mit der
Netzwerkhardwareadresse 02-50-F3-00-00-00 ermittelt. Netzwerkvorgänge könnten daher auf diesem
System unterbrochen werden.

Error: (11/18/2013 10:51:47 AM) (Source: Dhcp) (User: )
Description: Die IP-Adresslease 10.40.181.185 für die Netzwerkkarte mit der Netzwerkadresse 001E101FAA49 wurde durch den DHCP-Server 10.32.203.37 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet).

Error: (11/18/2013 10:11:34 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (11/18/2013 10:09:38 AM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (11/18/2013 10:09:38 AM) (Source: Service Control Manager) (User: )
Description: Net.Tcp-ListeneradapterNet.Tcp-Portfreigabedienst%%1058


Microsoft Office Sessions:
=========================
Error: (11/17/2013 08:22:01 AM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/17/2013 08:22:01 AM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/17/2013 08:22:01 AM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Element nicht gefunden.  (0x80070490)
Search.TripoliIndexer

Error: (11/17/2013 08:22:00 AM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)
Search.JetPropStore

Error: (11/17/2013 08:22:00 AM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        0x%08x (0xc0041800 - Der Inhaltsindex kann nicht gelesen werden.  )

Error: (11/17/2013 08:22:00 AM) (Source: Windows Search Service)(User: )
Description:
Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (11/17/2013 08:22:00 AM) (Source: Windows Search Service)(User: )
Description:
Details:
        Der Inhaltsindex kann nicht gelesen werden.  (0xc0041800)

Error: (11/17/2013 08:21:59 AM) (Source: ESENT)(User: )
Description: Windows2264Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log-1811 (0xfffff8ed)


CodeIntegrity Errors:
===================================
  Date: 2013-11-16 19:42:13.862
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:12.565
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:11.355
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:10.079
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:08.808
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:07.537
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:59.462
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:58.202
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:56.953
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:55.763
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 51%
Total physical RAM: 2038.64 MB
Available physical RAM: 986.19 MB
Total Pagefile: 4332.32 MB
Available Pagefile: 2340.07 MB
Total Virtual: 2047.88 MB
Available Virtual: 1923.02 MB

==================== Drives ================================

Drive c: (OS_Install) (Fixed) (Total:63.48 GB) (Free:32.49 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Mobile Partner) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS
Drive e: (Data) (Fixed) (Total:387.63 GB) (Free:359 GB) NTFS
Drive i: (Lexar) (Removable) (Total:7.46 GB) (Free:5.79 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 9AC9B968)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=63 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=388 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 7 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=7 GB) - (Type=0C)

==================== End Of Log ============================


LG
mädchen

Siehste, schon wieder was vergessen,zum x-ten Mal.
Ich habe sehr oft eine Netzwerkfehlermeldung dass ein anderer Computer die gleiche IP Adresse hat wie ich und dass es deshlab einen Konflikt gibt. Ist das wichtig?

schrauber 20.11.2013 10:00

Hast du den mehrere rechner im Netz? LAN und WLAN gemischt?

Downloade dir bitte Windows Repair (All In One) von hier.

mädchen 22.11.2013 15:53

Hallo Schrauber, Tschuldigung, hat etwas gedauert. Ich mach das heute Abend.Windows Repair hatte ich schon mal installiert ( bin ich selber drauf gekommen...:) ) habe es dann aber nicht benutzt weil ich Englisch nicht mehr so gut kann und dann Bedenken hatte ob ich das auch richtig mache,ne? Kürzlich deinstalliert,aber was solls,mache ich es eben noch mal.
Habe schon wieder ein neues Problem,vielleicht habe ich Mist gemacht,weiß nicht.
In PC Zeitungen gelesen dass unter den kostenlosen Virenprogrammen Zone Alarm und Comodo die Besten sein sollen.Also weg mit Avira, weil hat ja den Trace file media pipe durchgelassen und Comodo installiert.Ja, und danach ging dann nichts mehr.Ich konnte klicken wie auch immer ich wollte,nichts hat sich mehr gerührt. Ausgemacht am Knopf nach einem halben Stündchen. Im abgesicherten Modus gestartet und das neue Virenprogramm gestartet und dann ging wieder nichts mehr.Hatte ne Meldung es wäre ein Fehler im Setup der nicht zu beheben ist.Also Comodo wieder deinstalliert. Diese Setup Fehlermeldungen habe ich häufiger,liegt das an meinem PC? Jetzt kann ich zwar wieder was machen am PC , aber ich habe oft Datei kann nicht geöffnet werden,das Programm reagiert nicht.
Stöhn.
Ich habe nur einen PC und den nutze ich mit einem Stick von Tchi*o.
Ich versuche dann heute abend mein Glück.:dankeschoen:

LG
mädchen

mädchen 22.11.2013 23:56

Liste der Anhänge anzeigen (Anzahl: 4)
Hi,
war leider nicht wie erwartet.Ich musste mehrmals irgendwelche Dateien extrahieren,hat sich bißchen schwierig gestaltet das Programm zu starten.Was mir da gemeldet wurde habe ich nicht verstanden.
Ich habe ne andere Version von Windows Repair als du, den Advance Modus gab es nicht, dafür mehr Kästchen zum Haken machen......ich hab mal den Rest mit angehakt.
Es wurden Fehler gefunden und behoben,aber nicht alle.Weil Dateien nicht geöffnet werden konnten,Pfade nicht gefunden wurden und was weiß ich was es da noch an Schwierigkeiten gab.Handles die ungültig waren (?) und skipped registry keys (?). Hätt mich auch gewundert wenn mal was klappt.Ich bin zig-mal gefragt worden ob ich die Datei ausführen will,ob das alles so richtig ist?
Nun kann ich etwas besser scrollen,der Balken rechts funktioniert besser, You tube Videos laufen deutlich besser,bleiben aber trotzdem manchmal stehen.Ansonsten kann ich keine wesentlichen Verbesserungen feststellen.Nach dem Start muckt die Kiste sofort wie bisher und das Meistgesehene ist die Eieruhr und der Grauschleier weil wieder das Programm nicht reagiert.Neuerdings trennt sich die Internetverbindung auch von selbst.
:daumenrunter: Der Drucker wird zwar jetzt beim Start nicht neu installiert,aber drucken will er nicht.

LG
mädchen

schrauber 23.11.2013 08:20

Zitat:

In PC Zeitungen gelesen dass unter den kostenlosen Virenprogrammen Zone Alarm und Comodo die Besten sein sollen
:wtf:

Poste bitte mal ein frisches FRST log.

mädchen 23.11.2013 19:05

Hi,
kicher.
Wo soll man sich denn sonst informieren wenn nicht in PC Zeitschriften?


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-11-2013 03
Ran by pc (administrator) on PC-PC on 23-11-2013 18:53:12
Running from C:\Users\pc\Downloads
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\System32\PrintCtrl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
() C:\Program Files\Mobile Partner\Mobile Partner.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Uniblue Systems Limited) C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
(Lunascape Corporation) C:\Program Files\Lunascape\Lunascape6\Luna.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor)
HKLM\...\Run: [PrintDisp] - C:\Windows\System32\PrintDisp.exe [830464 2012-05-30] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKLM\...\Run: [CIS_{15198508-521A-4D69-8E5B-B94A6CCFF805}] - "C:\Users\pc\AppData\Local\Temp\cisBB91.exe" --PostUninstall {15198508-521A-4D69-8E5B-B94A6CCFF805} <===== ATTENTION
HKLM\...\Run: [CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}] - "C:\Users\pc\AppData\Local\Temp\cisBB91.exe" --PostUninstall {81EFDD93-DBBE-415B-BE6E-49B9664E3E82} <===== ATTENTION
HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2009-05-25] ()
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Tcpip\Parameters: [DhcpNameServer] 193.189.244.225 193.189.244.206
Tcpip\..\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: [NameServer]132.252.3.10,132.252.1.7

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] ()
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [77824 2012-01-20] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
S2 vToolbarUpdater13.0.0;

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [57944 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [26984 2012-10-07] (AVG Technologies)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-08-19] (Emsisoft GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; No ImagePath
S3 IpInIp; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-23 18:51 - 2013-11-23 18:52 - 01091525 _____ (Farbar) C:\Users\pc\Downloads\FRST.exe
2013-11-22 16:47 - 2013-11-22 16:47 - 00000000 ____D C:\Users\pc\Documents\tweaking.com_windows_repair_aio[1]
2013-11-22 11:49 - 2013-11-23 17:04 - 00160528 _____ C:\Windows\WindowsUpdate.log
2013-11-22 11:46 - 2013-11-22 19:41 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-22 11:46 - 2013-11-22 19:40 - 00002930 _____ C:\Windows\PFRO.log
2013-11-20 18:21 - 2013-11-20 18:21 - 00000000 ___HD C:\VTRoot
2013-11-20 18:20 - 2013-11-20 18:20 - 00001420 _____ C:\Windows\system32\Drivers\fvstore.dat
2013-11-20 06:14 - 2013-11-20 18:14 - 00251361 _____ C:\Windows\system32\Drivers\sfi.dat
2013-11-20 06:06 - 2013-11-20 19:39 - 00000000 ____D C:\ProgramData\COMODO
2013-11-20 06:05 - 2013-11-20 06:05 - 00000000 ____D C:\Users\pc\AppData\Local\Comodo
2013-11-20 06:04 - 2013-11-20 19:41 - 00000000 ____D C:\Program Files\Comodo
2013-11-20 06:04 - 2013-11-20 06:04 - 00047368 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.dll
2013-11-20 06:04 - 2013-11-20 06:04 - 00000000 ____D C:\ProgramData\Comodo Downloader
2013-11-19 19:36 - 2013-11-19 19:36 - 00000786 _____ C:\Users\Public\Desktop\WashAndGo.lnk
2013-11-17 18:20 - 2013-11-23 18:53 - 00006860 _____ C:\Users\pc\Downloads\FRST.txt
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-16 22:44 - 2013-11-23 18:50 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:26 - 2013-11-16 20:27 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 18:26 - 2013-11-16 18:27 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-16 18:26 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 17:42 - 2013-10-13 11:42 - 12344832 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 17:42 - 2013-10-13 11:08 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 17:42 - 2013-10-13 10:48 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 17:42 - 2013-10-13 10:37 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 17:42 - 2013-10-13 10:35 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-14 17:42 - 2013-10-13 10:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 17:42 - 2013-10-13 10:33 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-14 17:42 - 2013-10-13 10:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-14 17:42 - 2013-10-13 10:29 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 17:42 - 2013-10-13 10:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-14 17:42 - 2013-10-13 10:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 17:42 - 2013-10-13 10:20 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 16:15 - 2013-10-11 03:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 16:15 - 2013-10-11 03:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 16:15 - 2013-10-11 01:39 - 00218228 _____ C:\Windows\system32\WFP.TMF
2013-11-14 16:15 - 2013-10-03 13:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 16:15 - 2013-10-03 13:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-12 19:05 - 2013-11-16 20:14 - 00000000 ____D C:\AdwCleaner
2013-11-12 17:03 - 2013-11-12 17:04 - 00586560 _____ C:\EamClean.log
2013-11-11 04:05 - 2013-11-23 18:52 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 18:02 - 2013-11-12 14:17 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-06 18:02 - 2013-11-11 09:42 - 00000000 ____D C:\ProgramData\Skype
2013-10-29 09:29 - 2013-11-23 16:49 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-29 04:57 - 2013-11-12 19:37 - 00000000 ____D C:\Program Files\OXXOGames
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 17:06 - 2013-11-23 18:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:30 - 2013-10-27 12:29 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-24 09:44 - 2013-10-30 09:35 - 00000000 ____D C:\Users\pc\Documents\Meine Scans

==================== One Month Modified Files and Folders =======

2013-11-23 18:54 - 2013-11-17 18:20 - 00006860 _____ C:\Users\pc\Downloads\FRST.txt
2013-11-23 18:52 - 2013-11-23 18:51 - 01091525 _____ (Farbar) C:\Users\pc\Downloads\FRST.exe
2013-11-23 18:52 - 2013-11-11 04:05 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-23 18:50 - 2013-11-16 22:44 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-11-23 18:50 - 2012-06-07 22:26 - 00000332 _____ C:\Windows\Tasks\HP Photo Creations Communicator.job
2013-11-23 18:46 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-23 18:46 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-23 18:24 - 2013-10-27 17:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-23 17:04 - 2013-11-22 11:49 - 00160528 _____ C:\Windows\WindowsUpdate.log
2013-11-23 16:51 - 2006-11-02 11:33 - 01559288 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-23 16:49 - 2013-10-29 09:29 - 00000326 _____ C:\Windows\Tasks\rbmonitor.job
2013-11-23 16:49 - 2012-09-01 19:03 - 00000260 _____ C:\Windows\Tasks\AbelssoftPreloader.job
2013-11-23 16:49 - 2012-08-17 10:27 - 00000270 _____ C:\Windows\Tasks\CheckDriveBackgroundGuard.job
2013-11-23 16:46 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-23 16:46 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-11-23 00:04 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-22 19:49 - 2012-10-07 20:50 - 00060640 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT
2013-11-22 19:41 - 2013-11-22 11:46 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-22 19:40 - 2013-11-22 11:46 - 00002930 _____ C:\Windows\PFRO.log
2013-11-22 19:20 - 2012-10-23 14:57 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2013-11-22 16:47 - 2013-11-22 16:47 - 00000000 ____D C:\Users\pc\Documents\tweaking.com_windows_repair_aio[1]
2013-11-20 19:41 - 2013-11-20 06:04 - 00000000 ____D C:\Program Files\Comodo
2013-11-20 19:39 - 2013-11-20 06:06 - 00000000 ____D C:\ProgramData\COMODO
2013-11-20 19:20 - 2012-03-12 20:21 - 00001356 _____ C:\Users\pc\AppData\Local\d3d9caps.dat
2013-11-20 18:21 - 2013-11-20 18:21 - 00000000 ___HD C:\VTRoot
2013-11-20 18:20 - 2013-11-20 18:20 - 00001420 _____ C:\Windows\system32\Drivers\fvstore.dat
2013-11-20 18:14 - 2013-11-20 06:14 - 00251361 _____ C:\Windows\system32\Drivers\sfi.dat
2013-11-20 06:22 - 2011-10-12 20:30 - 00000000 ____D C:\ProgramData\Avira
2013-11-20 06:05 - 2013-11-20 06:05 - 00000000 ____D C:\Users\pc\AppData\Local\Comodo
2013-11-20 06:04 - 2013-11-20 06:04 - 00047368 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.dll
2013-11-20 06:04 - 2013-11-20 06:04 - 00000000 ____D C:\ProgramData\Comodo Downloader
2013-11-19 19:37 - 2011-07-11 18:49 - 00000000 ____D C:\Program Files\WashAndGo
2013-11-19 19:36 - 2013-11-19 19:36 - 00000786 _____ C:\Users\Public\Desktop\WashAndGo.lnk
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-17 11:48 - 2011-02-05 09:46 - 00000000 ____D C:\Users\pc\Desktop\diverse
2013-11-16 23:52 - 2013-10-20 23:55 - 00000000 ____D C:\Users\pc\Desktop\lookin back
2013-11-16 22:26 - 2010-10-15 17:12 - 00000000 ____D C:\Users\pc
2013-11-16 22:24 - 2011-05-07 02:25 - 00000000 ___RD C:\Users\pc\Dropbox
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:27 - 2013-11-16 20:26 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 20:14 - 2013-11-12 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-16 20:09 - 2006-11-02 11:23 - 00000179 _____ C:\Windows\win.ini
2013-11-16 18:27 - 2013-11-16 18:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 18:08 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-11-14 17:48 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 17:33 - 2013-10-11 10:50 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 17:28 - 2006-11-02 11:24 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Program Files\Google
2013-11-12 21:20 - 2011-02-25 15:30 - 00000000 ____D C:\Users\pc\AppData\Local\Adobe
2013-11-12 19:37 - 2013-10-29 04:57 - 00000000 ____D C:\Program Files\OXXOGames
2013-11-12 19:11 - 2012-07-11 09:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-12 19:10 - 2011-09-16 13:45 - 00000000 ____D C:\ProgramData\Uniblue
2013-11-12 17:04 - 2013-11-12 17:03 - 00586560 _____ C:\EamClean.log
2013-11-12 14:17 - 2013-11-06 18:02 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-11 09:42 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\Skype
2013-11-11 05:50 - 2010-10-16 12:32 - 00230048 _____ (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:44 - 2011-05-07 02:20 - 00000000 ____D C:\Users\pc\AppData\Roaming\Dropbox
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-02 08:14 - 2011-10-29 19:03 - 00000000 ____D C:\Windows\CleverPrint
2013-11-02 08:12 - 2011-07-08 16:12 - 00000000 ____D C:\Program Files\MailXXL.com Tools
2013-11-02 08:11 - 2011-07-08 10:51 - 01095982 _____ C:\ndsvc.log
2013-11-02 08:07 - 2012-08-16 09:16 - 00000000 ____D C:\Program Files\Panda Security
2013-10-30 09:35 - 2013-10-24 09:44 - 00000000 ____D C:\Users\pc\Documents\Meine Scans
2013-10-29 04:59 - 2013-10-29 04:59 - 00000000 ____D C:\Users\pc\AppData\Roaming\NevoSoft Games
2013-10-28 23:09 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public
2013-10-27 19:20 - 2013-10-27 19:20 - 00000000 ____D C:\Program Files\Adobe
2013-10-27 19:20 - 2011-06-29 19:12 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-10-27 19:20 - 2011-02-25 14:50 - 00000000 ____D C:\ProgramData\Adobe
2013-10-27 17:06 - 2013-10-27 17:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-27 17:06 - 2013-10-27 17:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 12:30 - 2013-10-27 12:30 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-27 12:29 - 2013-10-27 12:30 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-27 12:29 - 2013-10-27 12:29 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-27 12:29 - 2011-07-02 15:35 - 00000000 ____D C:\Program Files\Java
2013-10-25 20:25 - 2012-07-22 08:55 - 00000000 ____D C:\Users\pc\AppData\Local\Paint.NET
2013-10-24 20:04 - 2011-05-07 02:21 - 00000000 ____D C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox

Some content of TEMP:
====================
C:\Users\pc\AppData\Local\temp\avgnt.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-23 16:53

==================== End Of Log ============================

--- --- ---

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 23-11-2013 03
Ran by pc at 2013-11-23 18:57:42
Running from C:\Users\pc\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Emsisoft Anti-Malware (Enabled - Up to date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Anti-Malware (Enabled - Up to date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}

==================== Installed Programs ======================

32 Bit HP CIO Components Installer (Version: 1.0.0)
AbAlarm (Version: 6.2)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8)
AIO_CDB_ProductContext (Version: 82.0.242.000)
AIO_CDB_Software (Version: 82.0.242.000)
AIO_Scan (Version: 82.0.173.000)
Atheros Client Installation Program (Version: 7.0)
BufferChm (Version: 82.0.173.000)
Copy (Version: 82.0.188.000)
CustomerResearchQFolder (Version: 1.00.0000)
Destinations (Version: 82.0.173.000)
DeviceManagementQFolder (Version: 1.00.0000)
DocProc (Version: 8.1.0.0)
DocProcQFolder (Version: 1.00.0000)
Dropbox (HKCU Version: 2.0.22)
Emsisoft Anti-Malware (Version: 8.1)
eSupportQFolder (Version: 1.00.0000)
F300 (Version: 82.0.242.000)
F300_Help (Version: 82.0.242.000)
F300Trb (Version: 82.0.242.000)
Fax (Version: 82.0.188.000)
Google Earth (Version: 6.2.2.6613)
HP Customer Participation Program 8.0 (Version: 8.0)
HP Imaging Device Functions 8.0 (Version: 8.0)
HP OCR Software 8.0 (Version: 8.0)
HP Photo Creations (Version: 1.0.0.7702)
HP Photosmart Essential (Version: 1.12.0.46)
HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B (Version: 8.0)
HP Solution Center 8.0 (Version: 8.0)
HP Update (Version: 5.002.007.004)
HPProductAssistant (Version: 82.0.173.000)
HPSSupply (Version: 2.1.3.0000)
Intel(R) Graphics Media Accelerator Driver
Java 7 Update 45 (Version: 7.0.450)
Java Auto Updater (Version: 2.1.9.8)
Lunascape6 (All Users) (Version: 6.8.9.27075)
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300)
MarketResearch (Version: 82.0.174.000)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mobile Partner (Version: 11.302.09.04.382)
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MyKeyFinder (Version: 2012)
Paint.NET v3.5.10 (Version: 3.60.0)
Realtek 8169 8168 8101E 8102E Ethernet Driver (Version: 1.00.0000)
Realtek High Definition Audio Driver (Version: 6.0.1.5618)
Scan (Version: 8.1.0.0)
SolutionCenter (Version: 82.0.188.000)
Status (Version: 82.0.173.000)
Toolbox (Version: 82.0.173.000)
TrayApp (Version: 82.0.188.000)
Uniblue RegistryBooster (Version: 6.1.1.3)
UnloadSupport (Version: 1.00.0000)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (Version: 3)
Visual C++ 9.0 CRT (x86) WinSXS MSM (Version: 9.0)
WashAndGo (Version: 17.7)
WebReg (Version: 82.0.173.000)
YouTube Song Downloader (Version: 8.2)

==================== Restore Points  =========================

14-11-2013 16:26:44 Windows Update
17-11-2013 13:20:18 Removed Cisco EAP-FAST Module
17-11-2013 13:21:31 Removed Cisco LEAP Module
17-11-2013 13:22:09 Removed Cisco PEAP Module
19-11-2013 12:39:01 Windows Update
20-11-2013 18:30:15 Removed COMODO Antivirus
20-11-2013 18:40:00 Removed GeekBuddy.
22-11-2013 16:35:15 Tweaking.com - Windows Repair
22-11-2013 16:37:08 Tweaking.com - Windows Repair

==================== Hosts content: ==========================

2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost
::1            localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0AD797DB-679C-4254-BF1F-187451269FBE} - System32\Tasks\RunAsStdUser Task => C:\Program Files\NetDrive\netdrive.exe
Task: {0B923855-EFEC-4D6E-BF2C-25DC4D5D10FF} - System32\Tasks\WebReg Deskjet F300 series => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe [2006-12-10] (Hewlett-Packard Co.)
Task: {139DBA5E-5972-4876-81F7-3862E17F0935} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2008-01-21] (Microsoft Corporation)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {1F47FD6A-612B-488C-B4FD-5ACE203907B6} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => C:\Program Files\Windows Defender\MpCmdRun.exe [2008-01-21] (Microsoft Corporation)
Task: {2DE1ED62-3B3F-4610-86ED-E838057F6213} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {47CC68FF-DD27-4AC9-BD10-1206F7305F4A} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {51C71A63-7357-4492-80C2-B8A4B3E96899} - System32\Tasks\AbelssoftPreloader => C:\Program Files\WashAndGo\AbelssoftPreloader.exe [2013-11-18] (Microsoft)
Task: {724DD079-074D-48F7-84FC-129CAE9457D2} - System32\Tasks\rbmonitor => C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe [2013-08-21] (Uniblue Systems Limited)
Task: {793C7D04-E0F7-41B2-9376-BCB3BC77411B} - System32\Tasks\CheckDriveBackgroundGuard => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: {8CFE559A-52BC-433E-B3B9-E2296815C970} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-27] (Adobe Systems Incorporated)
Task: {99982336-9432-499D-A415-B1D0E9EE6E6A} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [2006-12-10] (Hewlett-Packard Co.)
Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => C:\Windows\System32\pla.dll [2008-01-21] (Microsoft Corporation)
Task: {A7F9AF08-9C24-4D9D-A77B-6C6A29823CB3} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-12] (Microsoft Corporation)
Task: {DC45E898-AF81-4A07-ABC9-73FCDB16504C} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-03-02] ()
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {ED517805-7DBD-4C05-8D08-DCB0E27BC2C3} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - pc => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: C:\Windows\Tasks\AbelssoftPreloader.job => C:\Program Files\WashAndGo\AbelssoftPreloader.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\CheckDriveBackgroundGuard.job => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe
Task: C:\Windows\Tasks\rbmonitor.job => C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
Task: C:\Windows\Tasks\WebReg Deskjet F300 series.job => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe

==================== Loaded Modules (whitelisted) =============

2011-06-27 15:24 - 2007-08-23 15:39 - 00014848 _____ () C:\Program Files\Mobile Partner\isaputrace.dll
2011-06-27 15:24 - 2009-12-10 10:51 - 00114688 _____ () C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll
2011-06-27 15:24 - 2009-09-19 10:21 - 00139264 _____ () C:\Program Files\Mobile Partner\NetInfoPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:48 - 00090112 _____ () C:\Program Files\Mobile Partner\DialUpPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:54 - 00057344 _____ () C:\Program Files\Mobile Partner\ConfigFilePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:40 - 00991232 _____ () C:\Program Files\Mobile Partner\NDISAPI.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00155648 _____ () C:\Program Files\Mobile Partner\DetectDev.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00557056 _____ () C:\Program Files\Mobile Partner\atcomm.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\XCodec.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\DeviceOperate.dll
2011-06-27 15:24 - 2009-06-18 09:56 - 00032768 _____ () C:\Program Files\Mobile Partner\NotifyServicePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:52 - 00192512 _____ () C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00143360 _____ () C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll
2011-06-27 15:24 - 2007-07-31 14:50 - 00090112 _____ () C:\Program Files\Mobile Partner\FileManager.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00159744 _____ () C:\Program Files\Mobile Partner\SMSPlugin.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00201640 _____ () C:\Program Files\Java\jre7\bin\jp2iexp.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00016808 _____ () C:\Program Files\Java\jre7\bin\jp2native.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/22/2013 07:06:36 PM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\DFSRPROV.MFL

Error: (11/22/2013 07:06:36 PM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\WHQLPROV.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\USERPROFILEWMIPROVIDER.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\ISCSIDSC.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\ISCSIPRF.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\RSOP.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\VDS.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\VSS.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\WMIPSESS.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\WMIPDSKQ.MFL


System errors:
=============
Error: (11/23/2013 04:47:47 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (11/23/2013 04:46:34 PM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (11/22/2013 11:07:53 PM) (Source: Dhcp) (User: )
Description: Die IP-Adresslease 10.42.7.158 für die Netzwerkkarte mit der Netzwerkadresse 001E101F2500 wurde durch den DHCP-Server 10.46.78.210 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet).

Error: (11/22/2013 07:48:26 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (11/22/2013 07:46:51 PM) (Source: Service Control Manager) (User: )
Description: Windows Update

Error: (11/22/2013 07:42:25 PM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (11/22/2013 05:01:17 PM) (Source: Dhcp) (User: )
Description: Die IP-Adresslease 10.46.47.71 für die Netzwerkkarte mit der Netzwerkadresse 001E101FABDD wurde durch den DHCP-Server 10.71.134.158 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet).

Error: (11/22/2013 05:00:46 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (11/22/2013 04:59:36 PM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (11/22/2013 04:59:36 PM) (Source: Service Control Manager) (User: )
Description: Net.Tcp-ListeneradapterNet.Tcp-Portfreigabedienst%%1058


Microsoft Office Sessions:
=========================
Error: (11/22/2013 07:06:36 PM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\DFSRPROV.MFL

Error: (11/22/2013 07:06:36 PM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\WHQLPROV.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\USERPROFILEWMIPROVIDER.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\ISCSIDSC.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\ISCSIPRF.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\RSOP.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\VDS.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\VSS.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\WMIPSESS.MFL

Error: (11/22/2013 07:06:35 PM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\FR-FR\WMIPDSKQ.MFL


CodeIntegrity Errors:
===================================
  Date: 2013-11-16 19:42:13.862
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:12.565
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:11.355
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:10.079
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:08.808
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:07.537
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:59.462
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:58.202
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:56.953
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:55.763
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 43%
Total physical RAM: 2038.64 MB
Available physical RAM: 1149.43 MB
Total Pagefile: 4320.35 MB
Available Pagefile: 2422.47 MB
Total Virtual: 2047.88 MB
Available Virtual: 1921.68 MB

==================== Drives ================================

Drive c: (OS_Install) (Fixed) (Total:63.48 GB) (Free:32.17 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Mobile Partner) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS
Drive e: (Data) (Fixed) (Total:387.63 GB) (Free:359 GB) NTFS
Drive i: (Lexar) (Removable) (Total:7.46 GB) (Free:5.79 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 9AC9B968)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=63 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=388 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 7 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=7 GB) - (Type=0C)

==================== End Of Log ============================

LG,mädchen

schrauber 24.11.2013 08:50

Zitat:

Wo soll man sich denn sonst informieren wenn nicht in PC Zeitschriften?
beim schrauber deines Vertrauens :D

Na im Internet. Es gibt jeden Monat großw unabhängige Vergleichstest (die seit Monaten immer das gleiche Tool gewinnt...)

Revo Uninstaller - Download - Filepony
Damit alles deinstallieren was Du nicht willst und brauchst, Reste durch Revo entfernen lassen.

Dann bitte ein frisches FRST log und ne Aufzählung was noch an Problemen da sind :)

mädchen 24.11.2013 10:58

Guten Morgen schrauber,

wer,wie,was,wieso,weshalb,warum. Ich frag dich immer viel und bekomme keine Antwort!:dummguck: Also PC Magazin,PC Welt,Chip online usw. im Internet lesen. Und da stand das eben drin.
Du hast mir neulich geschrieben es käme auf die Reihenfolge an wie deinstalliert werden muss. Ich habe das noch nicht gemacht.Muss ich das jetzt erst so machen wie beschrieben und dann mit dem neuen Ding alles was ich sonst nicht mehr haben will deinstallieren?
Ich frag lieber zweimal bevor ich da wieder was anrichte.

Schönen Sonntag!
mädchen

schrauber 25.11.2013 07:53

Das mit dem Deinstallieren in der Reihenfolge war als die Kiste sauber war. Danach hast Du doch den ganzen Kram installiert. Also erstmal obiges machen mit REvo, dann ein frisches FRST log und mir mitteilen ob es noch Probleme gibt, dann räumen wir auf.

Zitat:

wer,wie,was,wieso,weshalb,warum. Ich frag dich immer viel und bekomme keine Antwort! Also PC Magazin,PC Welt,Chip online usw. im Internet lesen. Und da stand das eben drin.
Nochmal: :)

AV Vergleichtests, unabhängig. Sollte direkt nen Hit bei Google liefern. Zeitschriften werden bezahlt (meistens) oder sonstwie. Ich kann mir nämlich nicht erklären warum so Dreck wie Avira, Norton und McAfee sonst immer noch neue Kunden findet ;)

mädchen 26.11.2013 16:10

Hi
:killpc:
Morgen erschieße ich die Kiste.

Ich weiß nicht woran das liegt aber comodo taucht nicht in der Programm Liste in der Systemsteuerung auf.Auch nicht bei den Programmen die ich mir mit Revo anzeigen lassen kann. Wie soll ich das dann deinstallieren?? Ich krieg das nicht hin.
Ich habe ne Menge deinstalliert mit Revo,auch die ganzen HP Druckerprogramme weil ich immer wieder Probleme mit dem Ding hatte.Wollte das mal komplett neu machen.Joah,und nun lässt sich der Kram nicht installieren,geht nicht.Und abbrechen lässt es sich auch nicht,die Fenster kann ich auch nicht schließen.Es ist zum Haare ausreißen....
Jetzt wollte ich die FRST Dinger schicken.......aber der Text ist zu lang,geht auch nicht.
Ich versuchs gleich noch mal.
Probleme noch massenweise vorhanden,irgendwie habe ich das Gefühl dass sich das verschlechtert statt verbessert.
Gleich nach Eingabe des Kennworte bleibt er stehen.Wenns dann weitergeht bleibt er nach dem ersten beliebigen Klick wieder stehen.Text markieren klappt nur manchmal,wenn ich mit dem Mausanzeiger auf einen Link will verwandelt sich das Ding in einen Cursor und ich kanns nicht anklicken.Das ist aber nicht jedes Mal so.Oft beim anklicken von Links :dieses Programm kann die Webseite nicht anzeigen oder der Link wird markiert und sonst nichts.Beim einloggen in den Emailaccount bleibt die Kiste wieder stehen.HP installationsprogramm,Lunascape,Revo und andere Programme geben keine Rückmeldung,reagieren nicht.Manchmal habe ich kein Eingangssignal für kurze Zeit..Der Virenschutz (Emsisoft) und der Windows Defender sind nach jedem Start abgeschaltet.Klicke ich den Einschalten Button,bleibt wieder alles stehen.Will ich googeln,nimmt er die Buchstaben nur zum Teil an ,die Internetverbindung trennt sich von allein und der Verbindungsassistent meldet sich manchmal :Mobile Partner funKtioniert nicht mehr.
Mehr habe ich noch nicht ausprobiert, ICH HABE DIESE KISTE SOWAS VON SATT...:killpc:

entnervtes mädchen

mädchen 26.11.2013 16:18

So hier sind die Dinger als Anhang weil sie zu lang sind.

schrauber 27.11.2013 09:59

Hi,

Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen.


So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307



Hast Du beim Deinstallieren mit Revo auch die Reste durch Revo entfernen lassen?

mädchen 28.11.2013 08:02

Hi,
ich habe es mit den logfiles genau so gemacht,aber die haben zuviele Zeichen wurde mir mitgeteilt!

Mit Revo habe ich alles was in den Listen an Resten fett dargestellt war entfernt.Da stand was von aufmerksam kontrollieren........aber ich habe dem Programm vertraut und die markierten Sachen gelöscht und auch die "Beweise entfernen" Funktion benutzt,also unwiederbringlich vernichtet was je gelöscht wurde.Hat die ganze Nacht gedauert so viel war das.
Aber jetzt weiß ich immer noch nicht wie ich Comodo deinstallieren soll ? Erklär mir das doch bitte.

LG,
mädchen

Hi
noch ne Frage.
wie bekomme ich mein HP All-in-one wieder installiert???
Habe mir die Software von der HP Seite runtergeladen,aber das Ding lässt sich nicht installieren.Das Gerät wird zwar erkannt,aber die Kiste schafft das auch über Nacht nicht die Installation zu machen.Nach 9 Stunden ist es bis 67% fortgeschritten....ich habe es mehrmals versucht,weiter als bis Schritt 3 von 4 gehts nicht.

lg
mädchen

schrauber 28.11.2013 13:33

Zitat:

ich habe es mit den logfiles genau so gemacht,aber die haben zuviele Zeichen wurde mir mitgeteilt!
Deswegen steht in meinem ersten Satz Logfiles zur Not teilen und mehrere Posts nutzen ;)

mädchen 28.11.2013 18:59

Das klappt ja eben nicht.Ich kann nur den gesamten (!) Text eines logfiles markieren über die Alles markieren Funktion. Ich habe doch schon öfter geschrieben Text markieren funktioniert nicht.Aufteilen is nicht.Was soll ich machen?

lg,mädchen

schrauber 29.11.2013 15:24

Zitat:

Ich habe doch schon öfter geschrieben Text markieren funktioniert nicht.Aufteilen is nicht.
Sorry halte ich aber immer noch für ein Gerücht, ist technisch nämlich nicht möglich das es nicht geht, dann müsste schon maus, Tastatur und Mainboard im Arsch sein ;)

Da ich aber mit Grippe zu Hause bin und nicht auf Arbeit hab ich ausnahmsweise mal die Anhänge geladen.

Logs sind tadellos sauber.

Sind das normale externe Maus und Keyboard?

mädchen 30.11.2013 18:00

Hallo,
ist wirklich so.Habe eine kabellose normale Tastatur die ich zum Pc mitgeliefert bekommen habe und eine optische Mouse.Wenn da in den logs nichts zu finden ist,woran kann es denn dann liegen?

Comodo habe ich in den Papierkorb verschoben weil Revo das Installationspaket nicht finden konnte.Reste entfernt mit Revo.Ich verstehe nicht wieso Comodo nicht in der Programmliste auftauchte.Ich hoffe das is jetzt weg.
Gute Besserung!
gruß,
mädchen

Vielleicht interessiert das: ich habe den PC neu erstanden im Fachhandel,Vista war vorinstalliert.Habe schnell Probleme damit bekommen weil ich keinen zusätzlichen Virenschutz installiert hatte,dachte nämlich Defender und Firewall reichen. Hatte dann aber einen Trojaner drauf der durch eine Computertante für 80 € entfernt wurde.Wie der hieß weiß ich nicht mehr.Aber sie war ziemlich verblüfft als sie den feststellte.Sie hat mir MBAM installiert und meinte ich soll das einmal die Woche durchlaufen lassen, besseres Programm gäbe es nicht. Hatte aber bald wieder Schwierigkeiten.MyStart Incredibar hieß das glaub ich was ich mir da eingefangen hatte und habe das in einem Computerladen wegmachen lassen.Die haben mir gesagt Avira wär besser als Scutz,also MBAM wieder weg und Avira drauf.Später habe ich mir Norton gekauft (ich habe alle Programme die je drauf waren ordnungsgemäß gekauft oder die kostenlose Testversion gehabt) und mußte dann wieder von Fachleuten.......für Geld Key Loggers entfernen lassen.Die hat mir dann Kaspersky empfohlen.Hatte ich dann auch,aber gefiel mir nicht habe es nur die Testzeit gehabt.Dann hat man mir Panda empfohlen,zusammen mit Avira.Hatte beides und dann jetzt dieses Trace file media pipe Ding drauf. Ja phhhh auf wen soll man hören? Hier im Trojanerboard habe ich gelesen wie ener Zone Alarm und Comodo empfohlen hat,aber der hatte nicht so viele Sterne wie du.....

schrauber 01.12.2013 15:52

Diese ganzen Infektionen kommen nicht durch schlechte AV Programme, sondern durch dein Surf Verhalten. Genau genommen brauch man gar kein AV Programm ;)

Zitat:

Habe eine kabellose normale Tastatur die ich zum Pc mitgeliefert bekommen habe und eine optische Mouse.Wenn da in den logs nichts zu finden ist,woran kann es denn dann liegen?
Also Funk? Battereien erneuert? Ganz stupide einfach mal nen anderes Keyboard und Maus getestet?

mädchen 01.12.2013 18:30

Ich steck oft neue Batterien in die Tastatur,daran kanns nicht liegen.Mouse habe ich vor ein paar Monaten erneuert.
Schlechtes Surfverhalten.........wofür habe ich denn Internet wenn ich noch nicht mal so Sachen wie informieren über stinknormale Sachen und Zeitung lesen und ein- und verkaufen kann? Ich habe zwei-,dreimal mailanhänge geöffnet.Von Absendern die auf den ersten Blick echt aussahen.Letztens PayPal, einmal ein Versandhaus wo ich mal was gekauft hab und einmal von einer Zeitung.Die Dinger waren aber nicht echt.
Um nochmal auf meinen Drucker zurückzukommen:kannst du mir dabei helfen oder musss ich mich in ein Druckerforum begeben? Was auch elend lange dauert ist das Windows Update dass ich seit heute mittag machen,ist erst bei 90%.Dabei sind es nur 53 MB. Mit dem Drucker dauert das wahrscheinlich Wochen....
Ähm, Revo entfernt aber auch nicht alles,ne? Habe Wash and Go durchlaufen lassen und das Programm hat noch über 23000 Spuren gefunden,1799 MB Speicherplatz freigegeben nach der großen Löschaktion.Was mir da beim Scannen auffiel,ist dass da Sachen auftauchen von denen ich noch nicht mal weiß dass ich sie habe und was das eigentlich ist.Oder wo ich das finde um es zu entfernen.Oder woher es kommt.In der Programmliste taucht das nicht auf.
Als ich dieses Trace file Ding hatte haben sich manchmal von selbst irgendwelche Downloads geöffnet die ich dann abgebrochen habe,hoffe ich jedenfalls dass ich sie abgebrochen habe.
Joah,dann werde ich mir mal ne andere Tastatur besorgen.Und Eset.
So lahm wie jetzt war mein PC noch nie! Kann doch eigentlich nicht sein wo ich alles bis auf das Notwendigste entfernt habe,da müßte die Kiste doch eigentlich schneller sein. Und Musik auf YouTube geht immer noch nicht richtig.K*cke alles.
gruß,
mädchen

Noch was:
ich hatte vor nochmal das tweaking.com zu benutzen,aber dann alles anhaken in der Hoffnung was zu erwischen das mir weiterhilft.
Dann habe ich da gelesen dass ne Reparatur,wenn der Rechner infiziert ist,die Sache noch verschlechtert.Aber du hast ja gesagt da ist nichts.Trotzdem wollte ich erst scannen mit MBAM .......und wieder n Fehler beim download.Hatte ich mit Windows Fix it auch immer.Das muss doch an meinem PC liegen,verflixt.Wie kann man das denn wieder hinkriegen ????
Das Registry Booster Programm habe ich übrigens auch gelöscht.Habe es lange benutzt,war dann wohl nicht so gut.
Wollte dir ein Bildchen schicken von dem tweaking.com Fenster,aber ich kann den Button für die Anhänge klicken wie blöde,da tut sich nichts.

gruß,mädchen

schrauber 02.12.2013 11:30

Zitat:

Ich habe zwei-,dreimal mailanhänge geöffnet.Von Absendern die auf den ersten Blick echt aussahen.Letztens PayPal, einmal ein Versandhaus wo ich mal was gekauft hab und einmal von einer Zeitung.Die Dinger waren aber nicht echt.
Sowas zum Beispiel ist nicht wirklich gesund :)
Zitat:

So lahm wie jetzt war mein PC noch nie! Kann doch eigentlich nicht sein wo ich alles bis auf das Notwendigste entfernt habe,da müßte die Kiste doch eigentlich schneller sein. Und Musik auf YouTube geht immer noch nicht richtig.K*cke alles.
Manchmal, nach mehreren Infektionen in Folge, ist das System einfach verbogen. Was man machen kann ist ne Rep-Installation mit der WIndows Scheibe, oder gleich einmal Daten sichern und sauber neu aufsetzen, dann passen auch alle Einstellungen und Treiber wieder.


Ich bin für so viel Text nicht aufnahmefähig, sorry. Könnte dem Fieber und der Grippe geschuldet sein. Poste bitte mal ein frisches FRST logfile und eine kurze Auflistung aller Probleme, die momentan noch bestehen.

dann schau ich mal ob wir da was drehen können, oder ob Du besser mal sauber neuaufsetzt.

mädchen 03.12.2013 10:39

Hallo,
ab in Bett mit dir.
FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-11-2013 03
Ran by pc (administrator) on PC-PC on 03-12-2013 10:19:13
Running from C:\Users\pc\Downloads
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\System32\PrintCtrl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
() C:\Program Files\Mobile Partner\Mobile Partner.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Lunascape Corporation) C:\Program Files\Lunascape\Lunascape6\Luna.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jp2launcher.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\java.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor)
HKLM\...\Run: [PrintDisp] - C:\Windows\System32\PrintDisp.exe [830464 2012-05-30] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKLM\...\Run: [CIS_{15198508-521A-4D69-8E5B-B94A6CCFF805}] - "C:\Users\pc\AppData\Local\Temp\cisBB91.exe" --PostUninstall {15198508-521A-4D69-8E5B-B94A6CCFF805} <===== ATTENTION
HKLM\...\Run: [CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}] - "C:\Users\pc\AppData\Local\Temp\cisBB91.exe" --PostUninstall {81EFDD93-DBBE-415B-BE6E-49B9664E3E82} <===== ATTENTION
HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2009-05-25] ()
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
Startup: C:\ProgramData\3214 ()
Startup: C:\ProgramData\Adobe ()
Startup: C:\ProgramData\Apple ()
Startup: C:\ProgramData\Apple Computer ()
Startup: C:\ProgramData\Application Data ()
Startup: C:\ProgramData\Atheros ()
Startup: C:\ProgramData\Avira ()
Startup: C:\ProgramData\Caphyon ()
Startup: C:\ProgramData\Common Files ()
Startup: C:\ProgramData\COMODO ()
Startup: C:\ProgramData\Comodo Downloader ()
Startup: C:\ProgramData\DatacardService ()
Startup: C:\ProgramData\Desktop ()
Startup: C:\ProgramData\Documents ()
Startup: C:\ProgramData\Favorites ()
Startup: C:\ProgramData\freenet ()
Startup: C:\ProgramData\Google ()
Startup: C:\ProgramData\HP ()
Startup: C:\ProgramData\hpzinstall.log ()
Startup: C:\ProgramData\Malwarebytes ()
Startup: C:\ProgramData\McAfee ()
Startup: C:\ProgramData\Microsoft ()
Startup: C:\ProgramData\ntuser.pol ()
Startup: C:\ProgramData\Nutzwerk ()
Startup: C:\ProgramData\Oracle ()
Startup: C:\ProgramData\PC Drivers HeadQuarters ()
Startup: C:\ProgramData\Skype ()
Startup: C:\ProgramData\Start Menu ()
Startup: C:\ProgramData\Sun ()
Startup: C:\ProgramData\Temp ()
Startup: C:\ProgramData\Templates ()
Startup: C:\ProgramData\TuneUp Software ()
Startup: C:\ProgramData\Uniblue ()
Startup: C:\ProgramData\Visan ()
Startup: C:\ProgramData\WEBREG ()
Startup: C:\ProgramData\WindowsSearch ()
Startup: C:\ProgramData\{6AD8E59C-250C-4201-B5BA-56ADEF76FF46} ()
Startup: C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} ()
Startup: C:\Users\Default\AppData ()
Startup: C:\Users\Default\Application Data ()
Startup: C:\Users\Default\Desktop ()
Startup: C:\Users\Default\Documents ()
Startup: C:\Users\Default\Downloads ()
Startup: C:\Users\Default\Favorites ()
Startup: C:\Users\Default\Links ()
Startup: C:\Users\Default\Local Settings ()
Startup: C:\Users\Default\Music ()
Startup: C:\Users\Default\My Documents ()
Startup: C:\Users\Default\NetHood ()
Startup: C:\Users\Default\NTUSER.DAT ()
Startup: C:\Users\Default\NTUSER.DAT.LOG ()
Startup: C:\Users\Default\ntuser.dat.LOG1 ()
Startup: C:\Users\Default\ntuser.dat.LOG2 ()
Startup: C:\Users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf ()
Startup: C:\Users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\Default\Pictures ()
Startup: C:\Users\Default\PrintHood ()
Startup: C:\Users\Default\Recent ()
Startup: C:\Users\Default\Saved Games ()
Startup: C:\Users\Default\SendTo ()
Startup: C:\Users\Default\Start Menu ()
Startup: C:\Users\Default\Templates ()
Startup: C:\Users\Default\Videos ()
Startup: C:\Users\pc\Anwendungsdaten ()
Startup: C:\Users\pc\AppData ()
Startup: C:\Users\pc\Contacts ()
Startup: C:\Users\pc\Cookies ()
Startup: C:\Users\pc\defogger_reenable ()
Startup: C:\Users\pc\Desktop ()
Startup: C:\Users\pc\Documents ()
Startup: C:\Users\pc\Downloads ()
Startup: C:\Users\pc\Dropbox ()
Startup: C:\Users\pc\Druckumgebung ()
Startup: C:\Users\pc\Eigene Dateien ()
Startup: C:\Users\pc\Favorites ()
Startup: C:\Users\pc\Links ()
Startup: C:\Users\pc\Lokale Einstellungen ()
Startup: C:\Users\pc\Music ()
Startup: C:\Users\pc\Netzwerkumgebung ()
Startup: C:\Users\pc\NTUSER.DAT ()
Startup: C:\Users\pc\ntuser.dat.LOG1 ()
Startup: C:\Users\pc\ntuser.dat.LOG2 ()
Startup: C:\Users\pc\NTUSER.DAT{091a2f77-0dd4-11e1-adc2-001e101f8aaa}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{091a2f77-0dd4-11e1-adc2-001e101f8aaa}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{091a2f77-0dd4-11e1-adc2-001e101f8aaa}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{18f80df2-94f1-11e1-9b06-001e101f1f81}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{18f80df2-94f1-11e1-9b06-001e101f1f81}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{18f80df2-94f1-11e1-9b06-001e101f1f81}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{61f7e8ce-d1c0-11e1-96a3-001e101fa1f5}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{61f7e8ce-d1c0-11e1-96a3-001e101fa1f5}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{61f7e8ce-d1c0-11e1-96a3-001e101fa1f5}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{7ba2ac88-0bc1-11e2-97c1-001e101f9843}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{7ba2ac88-0bc1-11e2-97c1-001e101f9843}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{7ba2ac88-0bc1-11e2-97c1-001e101f9843}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{95798ebd-91a7-11e0-90aa-001e101f50a4}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{95798ebd-91a7-11e0-90aa-001e101f50a4}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{95798ebd-91a7-11e0-90aa-001e101f50a4}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{97e579a9-8e0d-11e0-ba11-001e101fb681}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{97e579a9-8e0d-11e0-ba11-001e101fb681}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{97e579a9-8e0d-11e0-ba11-001e101fb681}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{a0d0f7e1-0d75-11e2-a058-001e101fa1f5}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{a0d0f7e1-0d75-11e2-a058-001e101fa1f5}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{a0d0f7e1-0d75-11e2-a058-001e101fa1f5}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{a36c2ac3-3489-11e1-8118-001e101fb45e}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{a36c2ac3-3489-11e1-8118-001e101fb45e}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{a36c2ac3-3489-11e1-8118-001e101fb45e}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{b866654e-a278-11e0-a74f-001e101fb45e}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{b866654e-a278-11e0-a74f-001e101fb45e}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{b866654e-a278-11e0-a74f-001e101fb45e}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{c36f8961-4242-11e3-8163-001e101f63cf}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{c36f8961-4242-11e3-8163-001e101f63cf}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{c36f8961-4242-11e3-8163-001e101f63cf}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d2e3e37f-7961-11e1-8a42-001e101f4da1}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{d2e3e37f-7961-11e1-8a42-001e101f4da1}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d2e3e37f-7961-11e1-8a42-001e101f4da1}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d33a6edf-7819-11e0-b880-001e101f4da1}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{d33a6edf-7819-11e0-b880-001e101f4da1}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d33a6edf-7819-11e0-b880-001e101f4da1}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d88fda87-23ff-11e1-af54-001e101f50a4}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{d88fda87-23ff-11e1-af54-001e101f50a4}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d88fda87-23ff-11e1-af54-001e101f50a4}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{f106339d-fca1-11e0-a9b0-001e101f8ed0}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{f106339d-fca1-11e0-a9b0-001e101f8ed0}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{f106339d-fca1-11e0-a9b0-001e101f8ed0}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\ntuser.ini ()
Startup: C:\Users\pc\pc - Verknüpfung.lnk
ShortcutTarget: pc - Verknüpfung.lnk -> C:\Users\pc ()
Startup: C:\Users\pc\Pictures ()
Startup: C:\Users\pc\Recent ()
Startup: C:\Users\pc\Searches ()
Startup: C:\Users\pc\SendTo ()
Startup: C:\Users\pc\Startmenü ()
Startup: C:\Users\pc\Videos ()
Startup: C:\Users\pc\Vorlagen ()
Startup: C:\Users\Public\AppData ()
Startup: C:\Users\Public\Desktop ()
Startup: C:\Users\Public\Documents ()
Startup: C:\Users\Public\Downloads ()
Startup: C:\Users\Public\Favorites ()
Startup: C:\Users\Public\Music ()
Startup: C:\Users\Public\Pictures ()
Startup: C:\Users\Public\Recorded TV ()
Startup: C:\Users\Public\Videos ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Tcpip\Parameters: [DhcpNameServer] 193.189.244.206 193.189.244.225
Tcpip\..\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: [NameServer]132.252.3.10,132.252.1.7

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] ()
S3 hpqcxs08; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S2 hpqddsvc; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [77824 2012-01-20] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
S2 vToolbarUpdater13.0.0;

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [57944 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [26984 2012-10-07] (AVG Technologies)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-08-19] (Emsisoft GmbH)
R3 KMWDFILTER; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [17408 2008-10-09] (Windows (R) Codename Longhorn DDK provider)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; No ImagePath
S3 IpInIp; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-03 10:18 - 2013-12-03 10:18 - 00028277 _____ C:\Users\pc\Desktop\FRST.txt
2013-12-01 21:38 - 2013-12-03 09:48 - 00039584 _____ C:\Windows\WindowsUpdate.log
2013-12-01 21:34 - 2013-12-01 21:35 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-01 21:33 - 2013-12-01 21:33 - 00075218 _____ C:\Windows\PFRO.log
2013-12-01 21:31 - 2013-12-01 21:31 - 00001181 _____ C:\AdwCleaner[S2].txt
2013-12-01 21:30 - 2013-12-01 21:30 - 00001118 _____ C:\AdwCleaner[R5].txt
2013-12-01 21:29 - 2013-12-01 21:29 - 00001057 _____ C:\AdwCleaner[R4].txt
2013-12-01 19:14 - 2013-12-01 19:14 - 00000000 _____ C:\Windows\setuperr.log
2013-12-01 19:14 - 2013-12-01 19:14 - 00000000 _____ C:\Windows\setupact.log
2013-11-26 11:07 - 2013-11-26 16:24 - 136984476 _____ C:\Users\pc\Downloads\AIO_CDB_Full_Non-Network_deu_NB.exe.f46v1ws.partial
2013-11-25 19:14 - 2013-11-25 19:14 - 00000000 ____D C:\ProgramData\WindowsSearch
2013-11-25 14:59 - 2013-11-25 16:49 - 00000810 _____ C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Posteingang  directBOX Freemail – Cloudmail made in Germany.website
2013-11-25 10:06 - 2013-11-25 10:06 - 00000000 ____D C:\Program Files\VS Revo Group
2013-11-23 18:57 - 2013-11-26 15:30 - 00024339 _____ C:\Users\pc\Downloads\Addition.txt
2013-11-23 18:51 - 2013-11-23 18:52 - 01091525 _____ (Farbar) C:\Users\pc\Downloads\FRST.exe
2013-11-22 16:47 - 2013-11-22 16:47 - 00000000 ____D C:\Users\pc\Documents\tweaking.com_windows_repair_aio[1]
2013-11-20 18:21 - 2013-11-20 18:21 - 00000000 ___HD C:\VTRoot
2013-11-20 18:20 - 2013-11-20 18:20 - 00001420 _____ C:\Windows\system32\Drivers\fvstore.dat
2013-11-20 06:14 - 2013-11-20 18:14 - 00251361 _____ C:\Windows\system32\Drivers\sfi.dat
2013-11-20 06:06 - 2013-11-20 19:39 - 00000000 ____D C:\ProgramData\COMODO
2013-11-20 06:05 - 2013-11-20 06:05 - 00000000 ____D C:\Users\pc\AppData\Local\Comodo
2013-11-20 06:04 - 2013-11-20 19:41 - 00000000 ____D C:\Program Files\Comodo
2013-11-20 06:04 - 2013-11-20 06:04 - 00047368 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.dll
2013-11-20 06:04 - 2013-11-20 06:04 - 00000000 ____D C:\ProgramData\Comodo Downloader
2013-11-19 19:36 - 2013-11-19 19:36 - 00000786 _____ C:\Users\Public\Desktop\WashAndGo.lnk
2013-11-17 18:20 - 2013-12-03 10:19 - 00015290 _____ C:\Users\pc\Downloads\FRST.txt
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-16 22:44 - 2013-12-01 21:38 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:26 - 2013-11-16 20:27 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 17:42 - 2013-10-13 11:42 - 12344832 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 17:42 - 2013-10-13 11:08 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 17:42 - 2013-10-13 10:48 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 17:42 - 2013-10-13 10:37 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 17:42 - 2013-10-13 10:35 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-14 17:42 - 2013-10-13 10:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 17:42 - 2013-10-13 10:33 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-14 17:42 - 2013-10-13 10:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-14 17:42 - 2013-10-13 10:29 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 17:42 - 2013-10-13 10:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-14 17:42 - 2013-10-13 10:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 17:42 - 2013-10-13 10:20 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 16:15 - 2013-10-11 03:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 16:15 - 2013-10-11 03:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 16:15 - 2013-10-11 01:39 - 00218228 _____ C:\Windows\system32\WFP.TMF
2013-11-14 16:15 - 2013-10-03 13:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 16:15 - 2013-10-03 13:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-12 19:05 - 2013-11-16 20:14 - 00000000 ____D C:\AdwCleaner
2013-11-12 17:03 - 2013-11-12 17:04 - 00586560 _____ C:\EamClean.log
2013-11-11 04:05 - 2013-12-03 10:07 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 18:02 - 2013-11-12 14:17 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-06 18:02 - 2013-11-11 09:42 - 00000000 ____D C:\ProgramData\Skype

==================== One Month Modified Files and Folders =======

2013-12-03 10:19 - 2013-11-17 18:20 - 00015290 _____ C:\Users\pc\Downloads\FRST.txt
2013-12-03 10:18 - 2013-12-03 10:18 - 00028277 _____ C:\Users\pc\Desktop\FRST.txt
2013-12-03 10:07 - 2013-11-11 04:05 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-12-03 09:48 - 2013-12-01 21:38 - 00039584 _____ C:\Windows\WindowsUpdate.log
2013-12-03 09:24 - 2013-10-27 17:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-03 09:11 - 2006-11-02 11:33 - 01567416 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-03 09:07 - 2012-09-01 19:03 - 00000260 _____ C:\Windows\Tasks\AbelssoftPreloader.job
2013-12-03 09:07 - 2012-08-17 10:27 - 00000270 _____ C:\Windows\Tasks\CheckDriveBackgroundGuard.job
2013-12-03 09:06 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-03 09:06 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-03 09:06 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-03 09:06 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-12-02 10:53 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-12-02 09:36 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-12-01 21:38 - 2013-11-16 22:44 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-12-01 21:35 - 2013-12-01 21:34 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-01 21:33 - 2013-12-01 21:33 - 00075218 _____ C:\Windows\PFRO.log
2013-12-01 21:31 - 2013-12-01 21:31 - 00001181 _____ C:\AdwCleaner[S2].txt
2013-12-01 21:30 - 2013-12-01 21:30 - 00001118 _____ C:\AdwCleaner[R5].txt
2013-12-01 21:29 - 2013-12-01 21:29 - 00001057 _____ C:\AdwCleaner[R4].txt
2013-12-01 20:12 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-12-01 19:14 - 2013-12-01 19:14 - 00000000 _____ C:\Windows\setuperr.log
2013-12-01 19:14 - 2013-12-01 19:14 - 00000000 _____ C:\Windows\setupact.log
2013-11-27 21:51 - 2010-12-31 16:07 - 00164314 _____ C:\Windows\hpoins19.dat
2013-11-27 21:51 - 2010-12-31 16:07 - 00003905 _____ C:\ProgramData\hpzinstall.log
2013-11-27 19:51 - 2011-03-13 15:17 - 00000000 ____D C:\Users\pc\Documents\DonationCoder
2013-11-26 16:24 - 2013-11-26 11:07 - 136984476 _____ C:\Users\pc\Downloads\AIO_CDB_Full_Non-Network_deu_NB.exe.f46v1ws.partial
2013-11-26 15:30 - 2013-11-23 18:57 - 00024339 _____ C:\Users\pc\Downloads\Addition.txt
2013-11-25 19:14 - 2013-11-25 19:14 - 00000000 ____D C:\ProgramData\WindowsSearch
2013-11-25 17:58 - 2010-12-31 16:08 - 00000000 ____D C:\Program Files\HP
2013-11-25 17:47 - 2010-12-31 16:17 - 00000000 ____D C:\Program Files\Common Files\HP
2013-11-25 17:33 - 2010-12-31 17:05 - 00000000 ____D C:\Users\pc\AppData\Roaming\Image Zone Express
2013-11-25 16:49 - 2013-11-25 14:59 - 00000810 _____ C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Posteingang  directBOX Freemail – Cloudmail made in Germany.website
2013-11-25 11:03 - 2011-02-25 14:47 - 00000000 ____D C:\Program Files\Google
2013-11-25 10:06 - 2013-11-25 10:06 - 00000000 ____D C:\Program Files\VS Revo Group
2013-11-25 09:52 - 2006-11-02 11:23 - 00000179 _____ C:\Windows\win.ini
2013-11-23 18:52 - 2013-11-23 18:51 - 01091525 _____ (Farbar) C:\Users\pc\Downloads\FRST.exe
2013-11-22 19:49 - 2012-10-07 20:50 - 00060640 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT
2013-11-22 19:20 - 2012-10-23 14:57 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2013-11-22 16:47 - 2013-11-22 16:47 - 00000000 ____D C:\Users\pc\Documents\tweaking.com_windows_repair_aio[1]
2013-11-20 19:41 - 2013-11-20 06:04 - 00000000 ____D C:\Program Files\Comodo
2013-11-20 19:39 - 2013-11-20 06:06 - 00000000 ____D C:\ProgramData\COMODO
2013-11-20 19:20 - 2012-03-12 20:21 - 00001356 _____ C:\Users\pc\AppData\Local\d3d9caps.dat
2013-11-20 18:21 - 2013-11-20 18:21 - 00000000 ___HD C:\VTRoot
2013-11-20 18:20 - 2013-11-20 18:20 - 00001420 _____ C:\Windows\system32\Drivers\fvstore.dat
2013-11-20 18:14 - 2013-11-20 06:14 - 00251361 _____ C:\Windows\system32\Drivers\sfi.dat
2013-11-20 06:22 - 2011-10-12 20:30 - 00000000 ____D C:\ProgramData\Avira
2013-11-20 06:05 - 2013-11-20 06:05 - 00000000 ____D C:\Users\pc\AppData\Local\Comodo
2013-11-20 06:04 - 2013-11-20 06:04 - 00047368 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.dll
2013-11-20 06:04 - 2013-11-20 06:04 - 00000000 ____D C:\ProgramData\Comodo Downloader
2013-11-19 19:37 - 2011-07-11 18:49 - 00000000 ____D C:\Program Files\WashAndGo
2013-11-19 19:36 - 2013-11-19 19:36 - 00000786 _____ C:\Users\Public\Desktop\WashAndGo.lnk
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-17 11:48 - 2011-02-05 09:46 - 00000000 ____D C:\Users\pc\Desktop\diverse
2013-11-16 23:52 - 2013-10-20 23:55 - 00000000 ____D C:\Users\pc\Desktop\lookin back
2013-11-16 22:26 - 2010-10-15 17:12 - 00000000 ____D C:\Users\pc
2013-11-16 22:24 - 2011-05-07 02:25 - 00000000 ___RD C:\Users\pc\Dropbox
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:27 - 2013-11-16 20:26 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 20:14 - 2013-11-12 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 17:48 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 17:33 - 2013-10-11 10:50 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 17:28 - 2006-11-02 11:24 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2013-11-12 21:20 - 2011-02-25 15:30 - 00000000 ____D C:\Users\pc\AppData\Local\Adobe
2013-11-12 19:37 - 2013-10-29 04:57 - 00000000 ____D C:\Program Files\OXXOGames
2013-11-12 19:11 - 2012-07-11 09:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-12 19:10 - 2011-09-16 13:45 - 00000000 ____D C:\ProgramData\Uniblue
2013-11-12 17:04 - 2013-11-12 17:03 - 00586560 _____ C:\EamClean.log
2013-11-12 14:17 - 2013-11-06 18:02 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-11 09:42 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\Skype
2013-11-11 05:50 - 2010-10-16 12:32 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:44 - 2011-05-07 02:20 - 00000000 ____D C:\Users\pc\AppData\Roaming\Dropbox
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–

Some content of TEMP:
====================
C:\Users\pc\AppData\Local\temp\mbam-setup.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-12-03 09:13

==================== End Of Log ============================

--- --- ---

--- --- ---

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-11-2013 03
Ran by pc (administrator) on PC-PC on 03-12-2013 10:19:13
Running from C:\Users\pc\Downloads
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\System32\PrintCtrl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
() C:\Program Files\Mobile Partner\Mobile Partner.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Lunascape Corporation) C:\Program Files\Lunascape\Lunascape6\Luna.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jp2launcher.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\java.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor)
HKLM\...\Run: [PrintDisp] - C:\Windows\System32\PrintDisp.exe [830464 2012-05-30] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKLM\...\Run: [CIS_{15198508-521A-4D69-8E5B-B94A6CCFF805}] - "C:\Users\pc\AppData\Local\Temp\cisBB91.exe" --PostUninstall {15198508-521A-4D69-8E5B-B94A6CCFF805} <===== ATTENTION
HKLM\...\Run: [CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}] - "C:\Users\pc\AppData\Local\Temp\cisBB91.exe" --PostUninstall {81EFDD93-DBBE-415B-BE6E-49B9664E3E82} <===== ATTENTION
HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2009-05-25] ()
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
Startup: C:\ProgramData\3214 ()
Startup: C:\ProgramData\Adobe ()
Startup: C:\ProgramData\Apple ()
Startup: C:\ProgramData\Apple Computer ()
Startup: C:\ProgramData\Application Data ()
Startup: C:\ProgramData\Atheros ()
Startup: C:\ProgramData\Avira ()
Startup: C:\ProgramData\Caphyon ()
Startup: C:\ProgramData\Common Files ()
Startup: C:\ProgramData\COMODO ()
Startup: C:\ProgramData\Comodo Downloader ()
Startup: C:\ProgramData\DatacardService ()
Startup: C:\ProgramData\Desktop ()
Startup: C:\ProgramData\Documents ()
Startup: C:\ProgramData\Favorites ()
Startup: C:\ProgramData\freenet ()
Startup: C:\ProgramData\Google ()
Startup: C:\ProgramData\HP ()
Startup: C:\ProgramData\hpzinstall.log ()
Startup: C:\ProgramData\Malwarebytes ()
Startup: C:\ProgramData\McAfee ()
Startup: C:\ProgramData\Microsoft ()
Startup: C:\ProgramData\ntuser.pol ()
Startup: C:\ProgramData\Nutzwerk ()
Startup: C:\ProgramData\Oracle ()
Startup: C:\ProgramData\PC Drivers HeadQuarters ()
Startup: C:\ProgramData\Skype ()
Startup: C:\ProgramData\Start Menu ()
Startup: C:\ProgramData\Sun ()
Startup: C:\ProgramData\Temp ()
Startup: C:\ProgramData\Templates ()
Startup: C:\ProgramData\TuneUp Software ()
Startup: C:\ProgramData\Uniblue ()
Startup: C:\ProgramData\Visan ()
Startup: C:\ProgramData\WEBREG ()
Startup: C:\ProgramData\WindowsSearch ()
Startup: C:\ProgramData\{6AD8E59C-250C-4201-B5BA-56ADEF76FF46} ()
Startup: C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} ()
Startup: C:\Users\Default\AppData ()
Startup: C:\Users\Default\Application Data ()
Startup: C:\Users\Default\Desktop ()
Startup: C:\Users\Default\Documents ()
Startup: C:\Users\Default\Downloads ()
Startup: C:\Users\Default\Favorites ()
Startup: C:\Users\Default\Links ()
Startup: C:\Users\Default\Local Settings ()
Startup: C:\Users\Default\Music ()
Startup: C:\Users\Default\My Documents ()
Startup: C:\Users\Default\NetHood ()
Startup: C:\Users\Default\NTUSER.DAT ()
Startup: C:\Users\Default\NTUSER.DAT.LOG ()
Startup: C:\Users\Default\ntuser.dat.LOG1 ()
Startup: C:\Users\Default\ntuser.dat.LOG2 ()
Startup: C:\Users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf ()
Startup: C:\Users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\Default\Pictures ()
Startup: C:\Users\Default\PrintHood ()
Startup: C:\Users\Default\Recent ()
Startup: C:\Users\Default\Saved Games ()
Startup: C:\Users\Default\SendTo ()
Startup: C:\Users\Default\Start Menu ()
Startup: C:\Users\Default\Templates ()
Startup: C:\Users\Default\Videos ()
Startup: C:\Users\pc\Anwendungsdaten ()
Startup: C:\Users\pc\AppData ()
Startup: C:\Users\pc\Contacts ()
Startup: C:\Users\pc\Cookies ()
Startup: C:\Users\pc\defogger_reenable ()
Startup: C:\Users\pc\Desktop ()
Startup: C:\Users\pc\Documents ()
Startup: C:\Users\pc\Downloads ()
Startup: C:\Users\pc\Dropbox ()
Startup: C:\Users\pc\Druckumgebung ()
Startup: C:\Users\pc\Eigene Dateien ()
Startup: C:\Users\pc\Favorites ()
Startup: C:\Users\pc\Links ()
Startup: C:\Users\pc\Lokale Einstellungen ()
Startup: C:\Users\pc\Music ()
Startup: C:\Users\pc\Netzwerkumgebung ()
Startup: C:\Users\pc\NTUSER.DAT ()
Startup: C:\Users\pc\ntuser.dat.LOG1 ()
Startup: C:\Users\pc\ntuser.dat.LOG2 ()
Startup: C:\Users\pc\NTUSER.DAT{091a2f77-0dd4-11e1-adc2-001e101f8aaa}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{091a2f77-0dd4-11e1-adc2-001e101f8aaa}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{091a2f77-0dd4-11e1-adc2-001e101f8aaa}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{18f80df2-94f1-11e1-9b06-001e101f1f81}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{18f80df2-94f1-11e1-9b06-001e101f1f81}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{18f80df2-94f1-11e1-9b06-001e101f1f81}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{61f7e8ce-d1c0-11e1-96a3-001e101fa1f5}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{61f7e8ce-d1c0-11e1-96a3-001e101fa1f5}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{61f7e8ce-d1c0-11e1-96a3-001e101fa1f5}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{7ba2ac88-0bc1-11e2-97c1-001e101f9843}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{7ba2ac88-0bc1-11e2-97c1-001e101f9843}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{7ba2ac88-0bc1-11e2-97c1-001e101f9843}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{95798ebd-91a7-11e0-90aa-001e101f50a4}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{95798ebd-91a7-11e0-90aa-001e101f50a4}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{95798ebd-91a7-11e0-90aa-001e101f50a4}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{97e579a9-8e0d-11e0-ba11-001e101fb681}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{97e579a9-8e0d-11e0-ba11-001e101fb681}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{97e579a9-8e0d-11e0-ba11-001e101fb681}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{a0d0f7e1-0d75-11e2-a058-001e101fa1f5}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{a0d0f7e1-0d75-11e2-a058-001e101fa1f5}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{a0d0f7e1-0d75-11e2-a058-001e101fa1f5}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{a36c2ac3-3489-11e1-8118-001e101fb45e}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{a36c2ac3-3489-11e1-8118-001e101fb45e}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{a36c2ac3-3489-11e1-8118-001e101fb45e}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{b866654e-a278-11e0-a74f-001e101fb45e}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{b866654e-a278-11e0-a74f-001e101fb45e}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{b866654e-a278-11e0-a74f-001e101fb45e}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{c36f8961-4242-11e3-8163-001e101f63cf}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{c36f8961-4242-11e3-8163-001e101f63cf}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{c36f8961-4242-11e3-8163-001e101f63cf}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d2e3e37f-7961-11e1-8a42-001e101f4da1}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{d2e3e37f-7961-11e1-8a42-001e101f4da1}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d2e3e37f-7961-11e1-8a42-001e101f4da1}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d33a6edf-7819-11e0-b880-001e101f4da1}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{d33a6edf-7819-11e0-b880-001e101f4da1}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d33a6edf-7819-11e0-b880-001e101f4da1}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d88fda87-23ff-11e1-af54-001e101f50a4}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{d88fda87-23ff-11e1-af54-001e101f50a4}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d88fda87-23ff-11e1-af54-001e101f50a4}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{f106339d-fca1-11e0-a9b0-001e101f8ed0}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{f106339d-fca1-11e0-a9b0-001e101f8ed0}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{f106339d-fca1-11e0-a9b0-001e101f8ed0}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\ntuser.ini ()
Startup: C:\Users\pc\pc - Verknüpfung.lnk
ShortcutTarget: pc - Verknüpfung.lnk -> C:\Users\pc ()
Startup: C:\Users\pc\Pictures ()
Startup: C:\Users\pc\Recent ()
Startup: C:\Users\pc\Searches ()
Startup: C:\Users\pc\SendTo ()
Startup: C:\Users\pc\Startmenü ()
Startup: C:\Users\pc\Videos ()
Startup: C:\Users\pc\Vorlagen ()
Startup: C:\Users\Public\AppData ()
Startup: C:\Users\Public\Desktop ()
Startup: C:\Users\Public\Documents ()
Startup: C:\Users\Public\Downloads ()
Startup: C:\Users\Public\Favorites ()
Startup: C:\Users\Public\Music ()
Startup: C:\Users\Public\Pictures ()
Startup: C:\Users\Public\Recorded TV ()
Startup: C:\Users\Public\Videos ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Tcpip\Parameters: [DhcpNameServer] 193.189.244.206 193.189.244.225
Tcpip\..\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: [NameServer]132.252.3.10,132.252.1.7

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] ()
S3 hpqcxs08; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S2 hpqddsvc; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [77824 2012-01-20] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
S2 vToolbarUpdater13.0.0;

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [57944 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [26984 2012-10-07] (AVG Technologies)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-08-19] (Emsisoft GmbH)
R3 KMWDFILTER; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [17408 2008-10-09] (Windows (R) Codename Longhorn DDK provider)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; No ImagePath
S3 IpInIp; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-03 10:18 - 2013-12-03 10:18 - 00028277 _____ C:\Users\pc\Desktop\FRST.txt
2013-12-01 21:38 - 2013-12-03 09:48 - 00039584 _____ C:\Windows\WindowsUpdate.log
2013-12-01 21:34 - 2013-12-01 21:35 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-01 21:33 - 2013-12-01 21:33 - 00075218 _____ C:\Windows\PFRO.log
2013-12-01 21:31 - 2013-12-01 21:31 - 00001181 _____ C:\AdwCleaner[S2].txt
2013-12-01 21:30 - 2013-12-01 21:30 - 00001118 _____ C:\AdwCleaner[R5].txt
2013-12-01 21:29 - 2013-12-01 21:29 - 00001057 _____ C:\AdwCleaner[R4].txt
2013-12-01 19:14 - 2013-12-01 19:14 - 00000000 _____ C:\Windows\setuperr.log
2013-12-01 19:14 - 2013-12-01 19:14 - 00000000 _____ C:\Windows\setupact.log
2013-11-26 11:07 - 2013-11-26 16:24 - 136984476 _____ C:\Users\pc\Downloads\AIO_CDB_Full_Non-Network_deu_NB.exe.f46v1ws.partial
2013-11-25 19:14 - 2013-11-25 19:14 - 00000000 ____D C:\ProgramData\WindowsSearch
2013-11-25 14:59 - 2013-11-25 16:49 - 00000810 _____ C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Posteingang  directBOX Freemail – Cloudmail made in Germany.website
2013-11-25 10:06 - 2013-11-25 10:06 - 00000000 ____D C:\Program Files\VS Revo Group
2013-11-23 18:57 - 2013-11-26 15:30 - 00024339 _____ C:\Users\pc\Downloads\Addition.txt
2013-11-23 18:51 - 2013-11-23 18:52 - 01091525 _____ (Farbar) C:\Users\pc\Downloads\FRST.exe
2013-11-22 16:47 - 2013-11-22 16:47 - 00000000 ____D C:\Users\pc\Documents\tweaking.com_windows_repair_aio[1]
2013-11-20 18:21 - 2013-11-20 18:21 - 00000000 ___HD C:\VTRoot
2013-11-20 18:20 - 2013-11-20 18:20 - 00001420 _____ C:\Windows\system32\Drivers\fvstore.dat
2013-11-20 06:14 - 2013-11-20 18:14 - 00251361 _____ C:\Windows\system32\Drivers\sfi.dat
2013-11-20 06:06 - 2013-11-20 19:39 - 00000000 ____D C:\ProgramData\COMODO
2013-11-20 06:05 - 2013-11-20 06:05 - 00000000 ____D C:\Users\pc\AppData\Local\Comodo
2013-11-20 06:04 - 2013-11-20 19:41 - 00000000 ____D C:\Program Files\Comodo
2013-11-20 06:04 - 2013-11-20 06:04 - 00047368 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.dll
2013-11-20 06:04 - 2013-11-20 06:04 - 00000000 ____D C:\ProgramData\Comodo Downloader
2013-11-19 19:36 - 2013-11-19 19:36 - 00000786 _____ C:\Users\Public\Desktop\WashAndGo.lnk
2013-11-17 18:20 - 2013-12-03 10:19 - 00015290 _____ C:\Users\pc\Downloads\FRST.txt
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-16 22:44 - 2013-12-01 21:38 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:26 - 2013-11-16 20:27 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 17:42 - 2013-10-13 11:42 - 12344832 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 17:42 - 2013-10-13 11:08 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 17:42 - 2013-10-13 10:48 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 17:42 - 2013-10-13 10:37 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 17:42 - 2013-10-13 10:35 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-14 17:42 - 2013-10-13 10:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 17:42 - 2013-10-13 10:33 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-14 17:42 - 2013-10-13 10:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-14 17:42 - 2013-10-13 10:29 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 17:42 - 2013-10-13 10:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-14 17:42 - 2013-10-13 10:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 17:42 - 2013-10-13 10:20 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 16:15 - 2013-10-11 03:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 16:15 - 2013-10-11 03:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 16:15 - 2013-10-11 01:39 - 00218228 _____ C:\Windows\system32\WFP.TMF
2013-11-14 16:15 - 2013-10-03 13:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 16:15 - 2013-10-03 13:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-12 19:05 - 2013-11-16 20:14 - 00000000 ____D C:\AdwCleaner
2013-11-12 17:03 - 2013-11-12 17:04 - 00586560 _____ C:\EamClean.log
2013-11-11 04:05 - 2013-12-03 10:07 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 18:02 - 2013-11-12 14:17 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-06 18:02 - 2013-11-11 09:42 - 00000000 ____D C:\ProgramData\Skype

==================== One Month Modified Files and Folders =======

2013-12-03 10:19 - 2013-11-17 18:20 - 00015290 _____ C:\Users\pc\Downloads\FRST.txt
2013-12-03 10:18 - 2013-12-03 10:18 - 00028277 _____ C:\Users\pc\Desktop\FRST.txt
2013-12-03 10:07 - 2013-11-11 04:05 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-12-03 09:48 - 2013-12-01 21:38 - 00039584 _____ C:\Windows\WindowsUpdate.log
2013-12-03 09:24 - 2013-10-27 17:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-03 09:11 - 2006-11-02 11:33 - 01567416 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-03 09:07 - 2012-09-01 19:03 - 00000260 _____ C:\Windows\Tasks\AbelssoftPreloader.job
2013-12-03 09:07 - 2012-08-17 10:27 - 00000270 _____ C:\Windows\Tasks\CheckDriveBackgroundGuard.job
2013-12-03 09:06 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-03 09:06 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-03 09:06 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-03 09:06 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-12-02 10:53 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-12-02 09:36 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-12-01 21:38 - 2013-11-16 22:44 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-12-01 21:35 - 2013-12-01 21:34 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-01 21:33 - 2013-12-01 21:33 - 00075218 _____ C:\Windows\PFRO.log
2013-12-01 21:31 - 2013-12-01 21:31 - 00001181 _____ C:\AdwCleaner[S2].txt
2013-12-01 21:30 - 2013-12-01 21:30 - 00001118 _____ C:\AdwCleaner[R5].txt
2013-12-01 21:29 - 2013-12-01 21:29 - 00001057 _____ C:\AdwCleaner[R4].txt
2013-12-01 20:12 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-12-01 19:14 - 2013-12-01 19:14 - 00000000 _____ C:\Windows\setuperr.log
2013-12-01 19:14 - 2013-12-01 19:14 - 00000000 _____ C:\Windows\setupact.log
2013-11-27 21:51 - 2010-12-31 16:07 - 00164314 _____ C:\Windows\hpoins19.dat
2013-11-27 21:51 - 2010-12-31 16:07 - 00003905 _____ C:\ProgramData\hpzinstall.log
2013-11-27 19:51 - 2011-03-13 15:17 - 00000000 ____D C:\Users\pc\Documents\DonationCoder
2013-11-26 16:24 - 2013-11-26 11:07 - 136984476 _____ C:\Users\pc\Downloads\AIO_CDB_Full_Non-Network_deu_NB.exe.f46v1ws.partial
2013-11-26 15:30 - 2013-11-23 18:57 - 00024339 _____ C:\Users\pc\Downloads\Addition.txt
2013-11-25 19:14 - 2013-11-25 19:14 - 00000000 ____D C:\ProgramData\WindowsSearch
2013-11-25 17:58 - 2010-12-31 16:08 - 00000000 ____D C:\Program Files\HP
2013-11-25 17:47 - 2010-12-31 16:17 - 00000000 ____D C:\Program Files\Common Files\HP
2013-11-25 17:33 - 2010-12-31 17:05 - 00000000 ____D C:\Users\pc\AppData\Roaming\Image Zone Express
2013-11-25 16:49 - 2013-11-25 14:59 - 00000810 _____ C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Posteingang  directBOX Freemail – Cloudmail made in Germany.website
2013-11-25 11:03 - 2011-02-25 14:47 - 00000000 ____D C:\Program Files\Google
2013-11-25 10:06 - 2013-11-25 10:06 - 00000000 ____D C:\Program Files\VS Revo Group
2013-11-25 09:52 - 2006-11-02 11:23 - 00000179 _____ C:\Windows\win.ini
2013-11-23 18:52 - 2013-11-23 18:51 - 01091525 _____ (Farbar) C:\Users\pc\Downloads\FRST.exe
2013-11-22 19:49 - 2012-10-07 20:50 - 00060640 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT
2013-11-22 19:20 - 2012-10-23 14:57 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2013-11-22 16:47 - 2013-11-22 16:47 - 00000000 ____D C:\Users\pc\Documents\tweaking.com_windows_repair_aio[1]
2013-11-20 19:41 - 2013-11-20 06:04 - 00000000 ____D C:\Program Files\Comodo
2013-11-20 19:39 - 2013-11-20 06:06 - 00000000 ____D C:\ProgramData\COMODO
2013-11-20 19:20 - 2012-03-12 20:21 - 00001356 _____ C:\Users\pc\AppData\Local\d3d9caps.dat
2013-11-20 18:21 - 2013-11-20 18:21 - 00000000 ___HD C:\VTRoot
2013-11-20 18:20 - 2013-11-20 18:20 - 00001420 _____ C:\Windows\system32\Drivers\fvstore.dat
2013-11-20 18:14 - 2013-11-20 06:14 - 00251361 _____ C:\Windows\system32\Drivers\sfi.dat
2013-11-20 06:22 - 2011-10-12 20:30 - 00000000 ____D C:\ProgramData\Avira
2013-11-20 06:05 - 2013-11-20 06:05 - 00000000 ____D C:\Users\pc\AppData\Local\Comodo
2013-11-20 06:04 - 2013-11-20 06:04 - 00047368 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.dll
2013-11-20 06:04 - 2013-11-20 06:04 - 00000000 ____D C:\ProgramData\Comodo Downloader
2013-11-19 19:37 - 2011-07-11 18:49 - 00000000 ____D C:\Program Files\WashAndGo
2013-11-19 19:36 - 2013-11-19 19:36 - 00000786 _____ C:\Users\Public\Desktop\WashAndGo.lnk
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-17 11:48 - 2011-02-05 09:46 - 00000000 ____D C:\Users\pc\Desktop\diverse
2013-11-16 23:52 - 2013-10-20 23:55 - 00000000 ____D C:\Users\pc\Desktop\lookin back
2013-11-16 22:26 - 2010-10-15 17:12 - 00000000 ____D C:\Users\pc
2013-11-16 22:24 - 2011-05-07 02:25 - 00000000 ___RD C:\Users\pc\Dropbox
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:27 - 2013-11-16 20:26 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 20:14 - 2013-11-12 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 17:48 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 17:33 - 2013-10-11 10:50 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 17:28 - 2006-11-02 11:24 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2013-11-12 21:20 - 2011-02-25 15:30 - 00000000 ____D C:\Users\pc\AppData\Local\Adobe
2013-11-12 19:37 - 2013-10-29 04:57 - 00000000 ____D C:\Program Files\OXXOGames
2013-11-12 19:11 - 2012-07-11 09:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-12 19:10 - 2011-09-16 13:45 - 00000000 ____D C:\ProgramData\Uniblue
2013-11-12 17:04 - 2013-11-12 17:03 - 00586560 _____ C:\EamClean.log
2013-11-12 14:17 - 2013-11-06 18:02 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-11 09:42 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\Skype
2013-11-11 05:50 - 2010-10-16 12:32 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:44 - 2011-05-07 02:20 - 00000000 ____D C:\Users\pc\AppData\Roaming\Dropbox
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–

Some content of TEMP:
====================
C:\Users\pc\AppData\Local\temp\mbam-setup.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-12-03 09:13

==================== End Of Log ============================

--- --- ---

--- --- ---

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-11-2013 03
Ran by pc (administrator) on PC-PC on 03-12-2013 10:19:13
Running from C:\Users\pc\Downloads
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\System32\PrintCtrl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
() C:\Program Files\Mobile Partner\Mobile Partner.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Lunascape Corporation) C:\Program Files\Lunascape\Lunascape6\Luna.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jp2launcher.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\java.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor)
HKLM\...\Run: [PrintDisp] - C:\Windows\System32\PrintDisp.exe [830464 2012-05-30] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKLM\...\Run: [CIS_{15198508-521A-4D69-8E5B-B94A6CCFF805}] - "C:\Users\pc\AppData\Local\Temp\cisBB91.exe" --PostUninstall {15198508-521A-4D69-8E5B-B94A6CCFF805} <===== ATTENTION
HKLM\...\Run: [CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}] - "C:\Users\pc\AppData\Local\Temp\cisBB91.exe" --PostUninstall {81EFDD93-DBBE-415B-BE6E-49B9664E3E82} <===== ATTENTION
HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2009-05-25] ()
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
Startup: C:\ProgramData\3214 ()
Startup: C:\ProgramData\Adobe ()
Startup: C:\ProgramData\Apple ()
Startup: C:\ProgramData\Apple Computer ()
Startup: C:\ProgramData\Application Data ()
Startup: C:\ProgramData\Atheros ()
Startup: C:\ProgramData\Avira ()
Startup: C:\ProgramData\Caphyon ()
Startup: C:\ProgramData\Common Files ()
Startup: C:\ProgramData\COMODO ()
Startup: C:\ProgramData\Comodo Downloader ()
Startup: C:\ProgramData\DatacardService ()
Startup: C:\ProgramData\Desktop ()
Startup: C:\ProgramData\Documents ()
Startup: C:\ProgramData\Favorites ()
Startup: C:\ProgramData\freenet ()
Startup: C:\ProgramData\Google ()
Startup: C:\ProgramData\HP ()
Startup: C:\ProgramData\hpzinstall.log ()
Startup: C:\ProgramData\Malwarebytes ()
Startup: C:\ProgramData\McAfee ()
Startup: C:\ProgramData\Microsoft ()
Startup: C:\ProgramData\ntuser.pol ()
Startup: C:\ProgramData\Nutzwerk ()
Startup: C:\ProgramData\Oracle ()
Startup: C:\ProgramData\PC Drivers HeadQuarters ()
Startup: C:\ProgramData\Skype ()
Startup: C:\ProgramData\Start Menu ()
Startup: C:\ProgramData\Sun ()
Startup: C:\ProgramData\Temp ()
Startup: C:\ProgramData\Templates ()
Startup: C:\ProgramData\TuneUp Software ()
Startup: C:\ProgramData\Uniblue ()
Startup: C:\ProgramData\Visan ()
Startup: C:\ProgramData\WEBREG ()
Startup: C:\ProgramData\WindowsSearch ()
Startup: C:\ProgramData\{6AD8E59C-250C-4201-B5BA-56ADEF76FF46} ()
Startup: C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} ()
Startup: C:\Users\Default\AppData ()
Startup: C:\Users\Default\Application Data ()
Startup: C:\Users\Default\Desktop ()
Startup: C:\Users\Default\Documents ()
Startup: C:\Users\Default\Downloads ()
Startup: C:\Users\Default\Favorites ()
Startup: C:\Users\Default\Links ()
Startup: C:\Users\Default\Local Settings ()
Startup: C:\Users\Default\Music ()
Startup: C:\Users\Default\My Documents ()
Startup: C:\Users\Default\NetHood ()
Startup: C:\Users\Default\NTUSER.DAT ()
Startup: C:\Users\Default\NTUSER.DAT.LOG ()
Startup: C:\Users\Default\ntuser.dat.LOG1 ()
Startup: C:\Users\Default\ntuser.dat.LOG2 ()
Startup: C:\Users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf ()
Startup: C:\Users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\Default\Pictures ()
Startup: C:\Users\Default\PrintHood ()
Startup: C:\Users\Default\Recent ()
Startup: C:\Users\Default\Saved Games ()
Startup: C:\Users\Default\SendTo ()
Startup: C:\Users\Default\Start Menu ()
Startup: C:\Users\Default\Templates ()
Startup: C:\Users\Default\Videos ()
Startup: C:\Users\pc\Anwendungsdaten ()
Startup: C:\Users\pc\AppData ()
Startup: C:\Users\pc\Contacts ()
Startup: C:\Users\pc\Cookies ()
Startup: C:\Users\pc\defogger_reenable ()
Startup: C:\Users\pc\Desktop ()
Startup: C:\Users\pc\Documents ()
Startup: C:\Users\pc\Downloads ()
Startup: C:\Users\pc\Dropbox ()
Startup: C:\Users\pc\Druckumgebung ()
Startup: C:\Users\pc\Eigene Dateien ()
Startup: C:\Users\pc\Favorites ()
Startup: C:\Users\pc\Links ()
Startup: C:\Users\pc\Lokale Einstellungen ()
Startup: C:\Users\pc\Music ()
Startup: C:\Users\pc\Netzwerkumgebung ()
Startup: C:\Users\pc\NTUSER.DAT ()
Startup: C:\Users\pc\ntuser.dat.LOG1 ()
Startup: C:\Users\pc\ntuser.dat.LOG2 ()
Startup: C:\Users\pc\NTUSER.DAT{091a2f77-0dd4-11e1-adc2-001e101f8aaa}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{091a2f77-0dd4-11e1-adc2-001e101f8aaa}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{091a2f77-0dd4-11e1-adc2-001e101f8aaa}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{18f80df2-94f1-11e1-9b06-001e101f1f81}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{18f80df2-94f1-11e1-9b06-001e101f1f81}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{18f80df2-94f1-11e1-9b06-001e101f1f81}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{61f7e8ce-d1c0-11e1-96a3-001e101fa1f5}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{61f7e8ce-d1c0-11e1-96a3-001e101fa1f5}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{61f7e8ce-d1c0-11e1-96a3-001e101fa1f5}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{7ba2ac88-0bc1-11e2-97c1-001e101f9843}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{7ba2ac88-0bc1-11e2-97c1-001e101f9843}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{7ba2ac88-0bc1-11e2-97c1-001e101f9843}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{95798ebd-91a7-11e0-90aa-001e101f50a4}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{95798ebd-91a7-11e0-90aa-001e101f50a4}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{95798ebd-91a7-11e0-90aa-001e101f50a4}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{97e579a9-8e0d-11e0-ba11-001e101fb681}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{97e579a9-8e0d-11e0-ba11-001e101fb681}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{97e579a9-8e0d-11e0-ba11-001e101fb681}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{a0d0f7e1-0d75-11e2-a058-001e101fa1f5}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{a0d0f7e1-0d75-11e2-a058-001e101fa1f5}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{a0d0f7e1-0d75-11e2-a058-001e101fa1f5}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{a36c2ac3-3489-11e1-8118-001e101fb45e}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{a36c2ac3-3489-11e1-8118-001e101fb45e}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{a36c2ac3-3489-11e1-8118-001e101fb45e}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{b866654e-a278-11e0-a74f-001e101fb45e}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{b866654e-a278-11e0-a74f-001e101fb45e}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{b866654e-a278-11e0-a74f-001e101fb45e}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{c36f8961-4242-11e3-8163-001e101f63cf}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{c36f8961-4242-11e3-8163-001e101f63cf}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{c36f8961-4242-11e3-8163-001e101f63cf}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d2e3e37f-7961-11e1-8a42-001e101f4da1}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{d2e3e37f-7961-11e1-8a42-001e101f4da1}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d2e3e37f-7961-11e1-8a42-001e101f4da1}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d33a6edf-7819-11e0-b880-001e101f4da1}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{d33a6edf-7819-11e0-b880-001e101f4da1}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d33a6edf-7819-11e0-b880-001e101f4da1}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d88fda87-23ff-11e1-af54-001e101f50a4}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{d88fda87-23ff-11e1-af54-001e101f50a4}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{d88fda87-23ff-11e1-af54-001e101f50a4}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{f106339d-fca1-11e0-a9b0-001e101f8ed0}.TM.blf ()
Startup: C:\Users\pc\NTUSER.DAT{f106339d-fca1-11e0-a9b0-001e101f8ed0}.TMContainer00000000000000000001.regtrans-ms ()
Startup: C:\Users\pc\NTUSER.DAT{f106339d-fca1-11e0-a9b0-001e101f8ed0}.TMContainer00000000000000000002.regtrans-ms ()
Startup: C:\Users\pc\ntuser.ini ()
Startup: C:\Users\pc\pc - Verknüpfung.lnk
ShortcutTarget: pc - Verknüpfung.lnk -> C:\Users\pc ()
Startup: C:\Users\pc\Pictures ()
Startup: C:\Users\pc\Recent ()
Startup: C:\Users\pc\Searches ()
Startup: C:\Users\pc\SendTo ()
Startup: C:\Users\pc\Startmenü ()
Startup: C:\Users\pc\Videos ()
Startup: C:\Users\pc\Vorlagen ()
Startup: C:\Users\Public\AppData ()
Startup: C:\Users\Public\Desktop ()
Startup: C:\Users\Public\Documents ()
Startup: C:\Users\Public\Downloads ()
Startup: C:\Users\Public\Favorites ()
Startup: C:\Users\Public\Music ()
Startup: C:\Users\Public\Pictures ()
Startup: C:\Users\Public\Recorded TV ()
Startup: C:\Users\Public\Videos ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - {288575EA-507B-42CB-97BE-ACED08F1998A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
SearchScopes: HKCU - {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Tcpip\Parameters: [DhcpNameServer] 193.189.244.206 193.189.244.225
Tcpip\..\Interfaces\{71B5F900-DE2A-46C9-B7E6-710EF36AF2A5}: [NameServer]132.252.3.10,132.252.1.7

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] ()
S3 hpqcxs08; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S2 hpqddsvc; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [77824 2012-01-20] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
S2 vToolbarUpdater13.0.0;

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [57944 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [26984 2012-10-07] (AVG Technologies)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-08-19] (Emsisoft GmbH)
R3 KMWDFILTER; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [17408 2008-10-09] (Windows (R) Codename Longhorn DDK provider)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; No ImagePath
S3 IpInIp; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-03 10:18 - 2013-12-03 10:18 - 00028277 _____ C:\Users\pc\Desktop\FRST.txt
2013-12-01 21:38 - 2013-12-03 09:48 - 00039584 _____ C:\Windows\WindowsUpdate.log
2013-12-01 21:34 - 2013-12-01 21:35 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-01 21:33 - 2013-12-01 21:33 - 00075218 _____ C:\Windows\PFRO.log
2013-12-01 21:31 - 2013-12-01 21:31 - 00001181 _____ C:\AdwCleaner[S2].txt
2013-12-01 21:30 - 2013-12-01 21:30 - 00001118 _____ C:\AdwCleaner[R5].txt
2013-12-01 21:29 - 2013-12-01 21:29 - 00001057 _____ C:\AdwCleaner[R4].txt
2013-12-01 19:14 - 2013-12-01 19:14 - 00000000 _____ C:\Windows\setuperr.log
2013-12-01 19:14 - 2013-12-01 19:14 - 00000000 _____ C:\Windows\setupact.log
2013-11-26 11:07 - 2013-11-26 16:24 - 136984476 _____ C:\Users\pc\Downloads\AIO_CDB_Full_Non-Network_deu_NB.exe.f46v1ws.partial
2013-11-25 19:14 - 2013-11-25 19:14 - 00000000 ____D C:\ProgramData\WindowsSearch
2013-11-25 14:59 - 2013-11-25 16:49 - 00000810 _____ C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Posteingang  directBOX Freemail – Cloudmail made in Germany.website
2013-11-25 10:06 - 2013-11-25 10:06 - 00000000 ____D C:\Program Files\VS Revo Group
2013-11-23 18:57 - 2013-11-26 15:30 - 00024339 _____ C:\Users\pc\Downloads\Addition.txt
2013-11-23 18:51 - 2013-11-23 18:52 - 01091525 _____ (Farbar) C:\Users\pc\Downloads\FRST.exe
2013-11-22 16:47 - 2013-11-22 16:47 - 00000000 ____D C:\Users\pc\Documents\tweaking.com_windows_repair_aio[1]
2013-11-20 18:21 - 2013-11-20 18:21 - 00000000 ___HD C:\VTRoot
2013-11-20 18:20 - 2013-11-20 18:20 - 00001420 _____ C:\Windows\system32\Drivers\fvstore.dat
2013-11-20 06:14 - 2013-11-20 18:14 - 00251361 _____ C:\Windows\system32\Drivers\sfi.dat
2013-11-20 06:06 - 2013-11-20 19:39 - 00000000 ____D C:\ProgramData\COMODO
2013-11-20 06:05 - 2013-11-20 06:05 - 00000000 ____D C:\Users\pc\AppData\Local\Comodo
2013-11-20 06:04 - 2013-11-20 19:41 - 00000000 ____D C:\Program Files\Comodo
2013-11-20 06:04 - 2013-11-20 06:04 - 00047368 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.dll
2013-11-20 06:04 - 2013-11-20 06:04 - 00000000 ____D C:\ProgramData\Comodo Downloader
2013-11-19 19:36 - 2013-11-19 19:36 - 00000786 _____ C:\Users\Public\Desktop\WashAndGo.lnk
2013-11-17 18:20 - 2013-12-03 10:19 - 00015290 _____ C:\Users\pc\Downloads\FRST.txt
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-16 22:44 - 2013-12-01 21:38 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:26 - 2013-11-16 20:27 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 17:42 - 2013-10-13 11:42 - 12344832 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 17:42 - 2013-10-13 11:08 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 17:42 - 2013-10-13 10:48 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 17:42 - 2013-10-13 10:37 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 17:42 - 2013-10-13 10:35 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-14 17:42 - 2013-10-13 10:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 17:42 - 2013-10-13 10:33 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-14 17:42 - 2013-10-13 10:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 17:42 - 2013-10-13 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-14 17:42 - 2013-10-13 10:29 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 17:42 - 2013-10-13 10:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 17:42 - 2013-10-13 10:26 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-14 17:42 - 2013-10-13 10:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 17:42 - 2013-10-13 10:20 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 16:15 - 2013-10-11 03:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 16:15 - 2013-10-11 03:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 16:15 - 2013-10-11 01:39 - 00218228 _____ C:\Windows\system32\WFP.TMF
2013-11-14 16:15 - 2013-10-03 13:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 16:15 - 2013-10-03 13:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-12 19:05 - 2013-11-16 20:14 - 00000000 ____D C:\AdwCleaner
2013-11-12 17:03 - 2013-11-12 17:04 - 00586560 _____ C:\EamClean.log
2013-11-11 04:05 - 2013-12-03 10:07 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–
2013-11-06 18:02 - 2013-11-12 14:17 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-06 18:02 - 2013-11-11 09:42 - 00000000 ____D C:\ProgramData\Skype

==================== One Month Modified Files and Folders =======

2013-12-03 10:19 - 2013-11-17 18:20 - 00015290 _____ C:\Users\pc\Downloads\FRST.txt
2013-12-03 10:18 - 2013-12-03 10:18 - 00028277 _____ C:\Users\pc\Desktop\FRST.txt
2013-12-03 10:07 - 2013-11-11 04:05 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-12-03 09:48 - 2013-12-01 21:38 - 00039584 _____ C:\Windows\WindowsUpdate.log
2013-12-03 09:24 - 2013-10-27 17:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-03 09:11 - 2006-11-02 11:33 - 01567416 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-03 09:07 - 2012-09-01 19:03 - 00000260 _____ C:\Windows\Tasks\AbelssoftPreloader.job
2013-12-03 09:07 - 2012-08-17 10:27 - 00000270 _____ C:\Windows\Tasks\CheckDriveBackgroundGuard.job
2013-12-03 09:06 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-03 09:06 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-03 09:06 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-03 09:06 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-12-02 10:53 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-12-02 09:36 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-12-01 21:38 - 2013-11-16 22:44 - 00000000 ____D C:\Users\pc\Desktop\trojaner
2013-12-01 21:35 - 2013-12-01 21:34 - 00276144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-01 21:33 - 2013-12-01 21:33 - 00075218 _____ C:\Windows\PFRO.log
2013-12-01 21:31 - 2013-12-01 21:31 - 00001181 _____ C:\AdwCleaner[S2].txt
2013-12-01 21:30 - 2013-12-01 21:30 - 00001118 _____ C:\AdwCleaner[R5].txt
2013-12-01 21:29 - 2013-12-01 21:29 - 00001057 _____ C:\AdwCleaner[R4].txt
2013-12-01 20:12 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-12-01 19:14 - 2013-12-01 19:14 - 00000000 _____ C:\Windows\setuperr.log
2013-12-01 19:14 - 2013-12-01 19:14 - 00000000 _____ C:\Windows\setupact.log
2013-11-27 21:51 - 2010-12-31 16:07 - 00164314 _____ C:\Windows\hpoins19.dat
2013-11-27 21:51 - 2010-12-31 16:07 - 00003905 _____ C:\ProgramData\hpzinstall.log
2013-11-27 19:51 - 2011-03-13 15:17 - 00000000 ____D C:\Users\pc\Documents\DonationCoder
2013-11-26 16:24 - 2013-11-26 11:07 - 136984476 _____ C:\Users\pc\Downloads\AIO_CDB_Full_Non-Network_deu_NB.exe.f46v1ws.partial
2013-11-26 15:30 - 2013-11-23 18:57 - 00024339 _____ C:\Users\pc\Downloads\Addition.txt
2013-11-25 19:14 - 2013-11-25 19:14 - 00000000 ____D C:\ProgramData\WindowsSearch
2013-11-25 17:58 - 2010-12-31 16:08 - 00000000 ____D C:\Program Files\HP
2013-11-25 17:47 - 2010-12-31 16:17 - 00000000 ____D C:\Program Files\Common Files\HP
2013-11-25 17:33 - 2010-12-31 17:05 - 00000000 ____D C:\Users\pc\AppData\Roaming\Image Zone Express
2013-11-25 16:49 - 2013-11-25 14:59 - 00000810 _____ C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Posteingang  directBOX Freemail – Cloudmail made in Germany.website
2013-11-25 11:03 - 2011-02-25 14:47 - 00000000 ____D C:\Program Files\Google
2013-11-25 10:06 - 2013-11-25 10:06 - 00000000 ____D C:\Program Files\VS Revo Group
2013-11-25 09:52 - 2006-11-02 11:23 - 00000179 _____ C:\Windows\win.ini
2013-11-23 18:52 - 2013-11-23 18:51 - 01091525 _____ (Farbar) C:\Users\pc\Downloads\FRST.exe
2013-11-22 19:49 - 2012-10-07 20:50 - 00060640 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT
2013-11-22 19:20 - 2012-10-23 14:57 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2013-11-22 16:47 - 2013-11-22 16:47 - 00000000 ____D C:\Users\pc\Documents\tweaking.com_windows_repair_aio[1]
2013-11-20 19:41 - 2013-11-20 06:04 - 00000000 ____D C:\Program Files\Comodo
2013-11-20 19:39 - 2013-11-20 06:06 - 00000000 ____D C:\ProgramData\COMODO
2013-11-20 19:20 - 2012-03-12 20:21 - 00001356 _____ C:\Users\pc\AppData\Local\d3d9caps.dat
2013-11-20 18:21 - 2013-11-20 18:21 - 00000000 ___HD C:\VTRoot
2013-11-20 18:20 - 2013-11-20 18:20 - 00001420 _____ C:\Windows\system32\Drivers\fvstore.dat
2013-11-20 18:14 - 2013-11-20 06:14 - 00251361 _____ C:\Windows\system32\Drivers\sfi.dat
2013-11-20 06:22 - 2011-10-12 20:30 - 00000000 ____D C:\ProgramData\Avira
2013-11-20 06:05 - 2013-11-20 06:05 - 00000000 ____D C:\Users\pc\AppData\Local\Comodo
2013-11-20 06:04 - 2013-11-20 06:04 - 00047368 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.dll
2013-11-20 06:04 - 2013-11-20 06:04 - 00000000 ____D C:\ProgramData\Comodo Downloader
2013-11-19 19:37 - 2011-07-11 18:49 - 00000000 ____D C:\Program Files\WashAndGo
2013-11-19 19:36 - 2013-11-19 19:36 - 00000786 _____ C:\Users\Public\Desktop\WashAndGo.lnk
2013-11-17 12:02 - 2013-11-17 12:02 - 00001610 _____ C:\Users\pc\Desktop\Snipping Tool.lnk
2013-11-17 11:48 - 2011-02-05 09:46 - 00000000 ____D C:\Users\pc\Desktop\diverse
2013-11-16 23:52 - 2013-10-20 23:55 - 00000000 ____D C:\Users\pc\Desktop\lookin back
2013-11-16 22:26 - 2010-10-15 17:12 - 00000000 ____D C:\Users\pc
2013-11-16 22:24 - 2011-05-07 02:25 - 00000000 ___RD C:\Users\pc\Dropbox
2013-11-16 20:31 - 2013-11-16 20:31 - 00000000 ____D C:\Windows\ERUNT
2013-11-16 20:27 - 2013-11-16 20:26 - 00001029 _____ C:\AdwCleaner[R3].txt
2013-11-16 20:26 - 2013-11-16 20:26 - 00000970 _____ C:\AdwCleaner[R2].txt
2013-11-16 20:14 - 2013-11-12 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-15 20:04 - 2013-11-15 20:04 - 00000000 ____D C:\FRST
2013-11-14 17:48 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 17:33 - 2013-10-11 10:50 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 17:28 - 2006-11-02 11:24 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-11-13 09:46 - 2011-02-25 14:47 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2013-11-12 21:20 - 2011-02-25 15:30 - 00000000 ____D C:\Users\pc\AppData\Local\Adobe
2013-11-12 19:37 - 2013-10-29 04:57 - 00000000 ____D C:\Program Files\OXXOGames
2013-11-12 19:11 - 2012-07-11 09:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-12 19:10 - 2011-09-16 13:45 - 00000000 ____D C:\ProgramData\Uniblue
2013-11-12 17:04 - 2013-11-12 17:03 - 00586560 _____ C:\EamClean.log
2013-11-12 14:17 - 2013-11-06 18:02 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2013-11-11 09:42 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\Skype
2013-11-11 05:50 - 2010-10-16 12:32 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-11 04:05 - 2013-11-11 04:05 - 00000000 ____D C:\Users\pc\Documents\Anti-Malware
2013-11-09 17:44 - 2011-05-07 02:20 - 00000000 ____D C:\Users\pc\AppData\Roaming\Dropbox
2013-11-09 17:35 - 2013-11-09 17:35 - 103387443 _____ C:\Windows\system32\섶㋨–

Some content of TEMP:
====================
C:\Users\pc\AppData\Local\temp\mbam-setup.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-12-03 09:13

==================== End Of Log ============================

--- --- ---

--- --- ---

gruß
mädchen

mädchen 03.12.2013 10:48

Hä?
Habe ich dreimal das gleiche drin?
Ich krieg ne Krise..... .
Code:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 23-11-2013 03
Ran by pc at 2013-12-03 10:20:35
Running from C:\Users\pc\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Emsisoft Anti-Malware (Enabled - Out of date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Anti-Malware (Enabled - Out of date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}

==================== Installed Programs ======================

32 Bit HP CIO Components Installer (Version: 1.0.0)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8)
AIO_CDB_ProductContext (Version: 82.0.242.000)
AIO_CDB_Software (Version: 82.0.242.000)
AIO_Scan (Version: 82.0.173.000)
Atheros Client Installation Program (Version: 7.0)
BufferChm (Version: 82.0.173.000)
Copy (Version: 82.0.188.000)
CustomerResearchQFolder (Version: 1.00.0000)
Destinations (Version: 82.0.173.000)
DeviceManagementQFolder (Version: 1.00.0000)
DocProc (Version: 8.1.0.0)
DocProcQFolder (Version: 1.00.0000)
Dropbox (HKCU Version: 2.0.22)
Emsisoft Anti-Malware (Version: 8.1)
eSupportQFolder (Version: 1.00.0000)
F300 (Version: 82.0.242.000)
F300_Help (Version: 82.0.242.000)
F300Trb (Version: 82.0.242.000)
Fax (Version: 82.0.188.000)
HPProductAssistant (Version: 82.0.173.000)
Intel(R) Graphics Media Accelerator Driver
Java 7 Update 45 (Version: 7.0.450)
Java Auto Updater (Version: 2.1.9.8)
Lunascape6 (All Users) (Version: 6.8.9.27075)
MarketResearch (Version: 82.0.174.000)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mobile Partner (Version: 11.302.09.04.382)
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MyKeyFinder (Version: 2012)
Paint.NET v3.5.10 (Version: 3.60.0)
Realtek 8169 8168 8101E 8102E Ethernet Driver (Version: 1.00.0000)
Realtek High Definition Audio Driver (Version: 6.0.1.5618)
Revo Uninstaller 1.95 (Version: 1.95)
Scan (Version: 8.1.0.0)
SolutionCenter (Version: 82.0.188.000)
Status (Version: 82.0.173.000)
Toolbox (Version: 82.0.173.000)
TrayApp (Version: 82.0.188.000)
UnloadSupport (Version: 1.00.0000)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Visual C++ 9.0 CRT (x86) WinSXS MSM (Version: 9.0)
WashAndGo (Version: 17.7)
WebReg (Version: 82.0.173.000)

==================== Restore Points  =========================

01-12-2013 07:35:17 Windows Update
01-12-2013 16:06:19 Windows Update
01-12-2013 17:25:25 Windows Update
01-12-2013 18:46:13 Windows Update

==================== Hosts content: ==========================

2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost
::1            localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0AD797DB-679C-4254-BF1F-187451269FBE} - System32\Tasks\RunAsStdUser Task => C:\Program Files\NetDrive\netdrive.exe
Task: {0B923855-EFEC-4D6E-BF2C-25DC4D5D10FF} - System32\Tasks\WebReg Deskjet F300 series => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
Task: {0DB7D8BC-5FDE-4CFF-AB4F-B3762ACCEAB8} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - pc => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {139DBA5E-5972-4876-81F7-3862E17F0935} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2008-01-21] (Microsoft Corporation)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {2504DD76-8025-4C3F-A286-DF638CF048E8} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => C:\Program Files\Windows Defender\MpCmdRun.exe [2008-01-21] (Microsoft Corporation)
Task: {2DE1ED62-3B3F-4610-86ED-E838057F6213} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {47CC68FF-DD27-4AC9-BD10-1206F7305F4A} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {51C71A63-7357-4492-80C2-B8A4B3E96899} - System32\Tasks\AbelssoftPreloader => C:\Program Files\WashAndGo\AbelssoftPreloader.exe [2013-11-18] (Microsoft)
Task: {793C7D04-E0F7-41B2-9376-BCB3BC77411B} - System32\Tasks\CheckDriveBackgroundGuard => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: {8CFE559A-52BC-433E-B3B9-E2296815C970} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-27] (Adobe Systems Incorporated)
Task: {99982336-9432-499D-A415-B1D0E9EE6E6A} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => C:\Windows\System32\pla.dll [2008-01-21] (Microsoft Corporation)
Task: {A7F9AF08-9C24-4D9D-A77B-6C6A29823CB3} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-12] (Microsoft Corporation)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: C:\Windows\Tasks\AbelssoftPreloader.job => C:\Program Files\WashAndGo\AbelssoftPreloader.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\CheckDriveBackgroundGuard.job => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: C:\Windows\Tasks\WebReg Deskjet F300 series.job => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe

==================== Loaded Modules (whitelisted) =============

2011-06-27 15:24 - 2007-08-23 15:39 - 00014848 _____ () C:\Program Files\Mobile Partner\isaputrace.dll
2011-06-27 15:24 - 2009-12-10 10:51 - 00114688 _____ () C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll
2011-06-27 15:24 - 2009-09-19 10:21 - 00139264 _____ () C:\Program Files\Mobile Partner\NetInfoPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:48 - 00090112 _____ () C:\Program Files\Mobile Partner\DialUpPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:54 - 00057344 _____ () C:\Program Files\Mobile Partner\ConfigFilePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:40 - 00991232 _____ () C:\Program Files\Mobile Partner\NDISAPI.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00155648 _____ () C:\Program Files\Mobile Partner\DetectDev.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00557056 _____ () C:\Program Files\Mobile Partner\atcomm.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\XCodec.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\DeviceOperate.dll
2011-06-27 15:24 - 2009-06-18 09:56 - 00032768 _____ () C:\Program Files\Mobile Partner\NotifyServicePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:52 - 00192512 _____ () C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00143360 _____ () C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll
2011-06-27 15:24 - 2007-07-31 14:50 - 00090112 _____ () C:\Program Files\Mobile Partner\FileManager.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00159744 _____ () C:\Program Files\Mobile Partner\SMSPlugin.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00201640 _____ () C:\Program Files\Java\jre7\bin\jp2iexp.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00016808 _____ () C:\Program Files\Java\jre7\bin\jp2native.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (12/01/2013 05:17:09 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - 1>Failed to compile: mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070003


System errors:
=============
Error: (12/03/2013 09:46:45 AM) (Source: Dhcp) (User: )
Description: Die IP-Adresslease 10.153.58.122 für die Netzwerkkarte mit der Netzwerkadresse 001E101F63CF wurde durch den DHCP-Server 10.40.62.94 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet).

Error: (12/03/2013 09:08:34 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (12/03/2013 09:06:52 AM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (12/03/2013 09:06:52 AM) (Source: Service Control Manager) (User: )
Description: HP CUE DeviceDiscovery Service%%2

Error: (12/02/2013 10:27:36 AM) (Source: Tcpip) (User: )
Description: Das System hat einen Adressenkonflikt der IP-Adresse 10.51.157.43 mit dem Computer mit der
Netzwerkhardwareadresse 02-50-F3-00-00-00 ermittelt. Netzwerkvorgänge könnten daher auf diesem
System unterbrochen werden.

Error: (12/02/2013 10:27:36 AM) (Source: Dhcp) (User: )
Description: Die IP-Adresslease 10.51.157.43 für die Netzwerkkarte mit der Netzwerkadresse 001E101F21C1 wurde durch den DHCP-Server 10.72.69.98 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet).

Error: (12/02/2013 09:21:53 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (12/02/2013 09:20:31 AM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (12/02/2013 09:20:31 AM) (Source: Service Control Manager) (User: )
Description: HP CUE DeviceDiscovery Service%%2

Error: (12/01/2013 09:38:47 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032


Microsoft Office Sessions:
=========================
Error: (12/01/2013 05:17:09 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - 1>Failed to compile: mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070003
mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089


CodeIntegrity Errors:
===================================
  Date: 2013-11-16 19:42:13.862
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:12.565
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:11.355
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:10.079
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:08.808
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:07.537
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:59.462
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:58.202
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:56.953
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:55.763
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 52%
Total physical RAM: 2038.64 MB
Available physical RAM: 972.93 MB
Total Pagefile: 4320.32 MB
Available Pagefile: 2809.07 MB
Total Virtual: 2047.88 MB
Available Virtual: 1905.56 MB

==================== Drives ================================

Drive c: (OS_Install) (Fixed) (Total:63.48 GB) (Free:32.76 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Mobile Partner) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS
Drive e: (Data) (Fixed) (Total:387.63 GB) (Free:359 GB) NTFS
Drive i: (Lexar) (Removable) (Total:7.46 GB) (Free:5.79 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 9AC9B968)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=63 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=388 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 7 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=7 GB) - (Type=0C)

==================== End Of Log ============================Additional scan result of Farbar Recovery Scan Tool (x86) Version: 23-11-2013 03
Ran by pc at 2013-12-03 10:20:35
Running from C:\Users\pc\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Emsisoft Anti-Malware (Enabled - Out of date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Anti-Malware (Enabled - Out of date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}

==================== Installed Programs ======================

32 Bit HP CIO Components Installer (Version: 1.0.0)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8)
AIO_CDB_ProductContext (Version: 82.0.242.000)
AIO_CDB_Software (Version: 82.0.242.000)
AIO_Scan (Version: 82.0.173.000)
Atheros Client Installation Program (Version: 7.0)
BufferChm (Version: 82.0.173.000)
Copy (Version: 82.0.188.000)
CustomerResearchQFolder (Version: 1.00.0000)
Destinations (Version: 82.0.173.000)
DeviceManagementQFolder (Version: 1.00.0000)
DocProc (Version: 8.1.0.0)
DocProcQFolder (Version: 1.00.0000)
Dropbox (HKCU Version: 2.0.22)
Emsisoft Anti-Malware (Version: 8.1)
eSupportQFolder (Version: 1.00.0000)
F300 (Version: 82.0.242.000)
F300_Help (Version: 82.0.242.000)
F300Trb (Version: 82.0.242.000)
Fax (Version: 82.0.188.000)
HPProductAssistant (Version: 82.0.173.000)
Intel(R) Graphics Media Accelerator Driver
Java 7 Update 45 (Version: 7.0.450)
Java Auto Updater (Version: 2.1.9.8)
Lunascape6 (All Users) (Version: 6.8.9.27075)
MarketResearch (Version: 82.0.174.000)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mobile Partner (Version: 11.302.09.04.382)
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MyKeyFinder (Version: 2012)
Paint.NET v3.5.10 (Version: 3.60.0)
Realtek 8169 8168 8101E 8102E Ethernet Driver (Version: 1.00.0000)
Realtek High Definition Audio Driver (Version: 6.0.1.5618)
Revo Uninstaller 1.95 (Version: 1.95)
Scan (Version: 8.1.0.0)
SolutionCenter (Version: 82.0.188.000)
Status (Version: 82.0.173.000)
Toolbox (Version: 82.0.173.000)
TrayApp (Version: 82.0.188.000)
UnloadSupport (Version: 1.00.0000)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Visual C++ 9.0 CRT (x86) WinSXS MSM (Version: 9.0)
WashAndGo (Version: 17.7)
WebReg (Version: 82.0.173.000)

==================== Restore Points  =========================

01-12-2013 07:35:17 Windows Update
01-12-2013 16:06:19 Windows Update
01-12-2013 17:25:25 Windows Update
01-12-2013 18:46:13 Windows Update

==================== Hosts content: ==========================

2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost
::1            localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0AD797DB-679C-4254-BF1F-187451269FBE} - System32\Tasks\RunAsStdUser Task => C:\Program Files\NetDrive\netdrive.exe
Task: {0B923855-EFEC-4D6E-BF2C-25DC4D5D10FF} - System32\Tasks\WebReg Deskjet F300 series => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
Task: {0DB7D8BC-5FDE-4CFF-AB4F-B3762ACCEAB8} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - pc => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {139DBA5E-5972-4876-81F7-3862E17F0935} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2008-01-21] (Microsoft Corporation)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {2504DD76-8025-4C3F-A286-DF638CF048E8} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => C:\Program Files\Windows Defender\MpCmdRun.exe [2008-01-21] (Microsoft Corporation)
Task: {2DE1ED62-3B3F-4610-86ED-E838057F6213} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {47CC68FF-DD27-4AC9-BD10-1206F7305F4A} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {51C71A63-7357-4492-80C2-B8A4B3E96899} - System32\Tasks\AbelssoftPreloader => C:\Program Files\WashAndGo\AbelssoftPreloader.exe [2013-11-18] (Microsoft)
Task: {793C7D04-E0F7-41B2-9376-BCB3BC77411B} - System32\Tasks\CheckDriveBackgroundGuard => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: {8CFE559A-52BC-433E-B3B9-E2296815C970} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-27] (Adobe Systems Incorporated)
Task: {99982336-9432-499D-A415-B1D0E9EE6E6A} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => C:\Windows\System32\pla.dll [2008-01-21] (Microsoft Corporation)
Task: {A7F9AF08-9C24-4D9D-A77B-6C6A29823CB3} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-12] (Microsoft Corporation)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: C:\Windows\Tasks\AbelssoftPreloader.job => C:\Program Files\WashAndGo\AbelssoftPreloader.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\CheckDriveBackgroundGuard.job => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: C:\Windows\Tasks\WebReg Deskjet F300 series.job => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe

==================== Loaded Modules (whitelisted) =============

2011-06-27 15:24 - 2007-08-23 15:39 - 00014848 _____ () C:\Program Files\Mobile Partner\isaputrace.dll
2011-06-27 15:24 - 2009-12-10 10:51 - 00114688 _____ () C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll
2011-06-27 15:24 - 2009-09-19 10:21 - 00139264 _____ () C:\Program Files\Mobile Partner\NetInfoPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:48 - 00090112 _____ () C:\Program Files\Mobile Partner\DialUpPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:54 - 00057344 _____ () C:\Program Files\Mobile Partner\ConfigFilePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:40 - 00991232 _____ () C:\Program Files\Mobile Partner\NDISAPI.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00155648 _____ () C:\Program Files\Mobile Partner\DetectDev.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00557056 _____ () C:\Program Files\Mobile Partner\atcomm.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\XCodec.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\DeviceOperate.dll
2011-06-27 15:24 - 2009-06-18 09:56 - 00032768 _____ () C:\Program Files\Mobile Partner\NotifyServicePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:52 - 00192512 _____ () C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00143360 _____ () C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll
2011-06-27 15:24 - 2007-07-31 14:50 - 00090112 _____ () C:\Program Files\Mobile Partner\FileManager.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00159744 _____ () C:\Program Files\Mobile Partner\SMSPlugin.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00201640 _____ () C:\Program Files\Java\jre7\bin\jp2iexp.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00016808 _____ () C:\Program Files\Java\jre7\bin\jp2native.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (12/01/2013 05:17:09 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - 1>Failed to compile: mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070003


System errors:
=============
Error: (12/03/2013 09:46:45 AM) (Source: Dhcp) (User: )
Description: Die IP-Adresslease 10.153.58.122 für die Netzwerkkarte mit der Netzwerkadresse 001E101F63CF wurde durch den DHCP-Server 10.40.62.94 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet).

Error: (12/03/2013 09:08:34 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (12/03/2013 09:06:52 AM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (12/03/2013 09:06:52 AM) (Source: Service Control Manager) (User: )
Description: HP CUE DeviceDiscovery Service%%2

Error: (12/02/2013 10:27:36 AM) (Source: Tcpip) (User: )
Description: Das System hat einen Adressenkonflikt der IP-Adresse 10.51.157.43 mit dem Computer mit der
Netzwerkhardwareadresse 02-50-F3-00-00-00 ermittelt. Netzwerkvorgänge könnten daher auf diesem
System unterbrochen werden.

Error: (12/02/2013 10:27:36 AM) (Source: Dhcp) (User: )
Description: Die IP-Adresslease 10.51.157.43 für die Netzwerkkarte mit der Netzwerkadresse 001E101F21C1 wurde durch den DHCP-Server 10.72.69.98 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet).

Error: (12/02/2013 09:21:53 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (12/02/2013 09:20:31 AM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (12/02/2013 09:20:31 AM) (Source: Service Control Manager) (User: )
Description: HP CUE DeviceDiscovery Service%%2

Error: (12/01/2013 09:38:47 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032


Microsoft Office Sessions:
=========================
Error: (12/01/2013 05:17:09 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - 1>Failed to compile: mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070003
mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089


CodeIntegrity Errors:
===================================
  Date: 2013-11-16 19:42:13.862
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:12.565
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:11.355
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:10.079
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:08.808
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:07.537
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:59.462
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:58.202
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:56.953
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:55.763
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 52%
Total physical RAM: 2038.64 MB
Available physical RAM: 972.93 MB
Total Pagefile: 4320.32 MB
Available Pagefile: 2809.07 MB
Total Virtual: 2047.88 MB
Available Virtual: 1905.56 MB

==================== Drives ================================

Drive c: (OS_Install) (Fixed) (Total:63.48 GB) (Free:32.76 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Mobile Partner) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS
Drive e: (Data) (Fixed) (Total:387.63 GB) (Free:359 GB) NTFS
Drive i: (Lexar) (Removable) (Total:7.46 GB) (Free:5.79 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 9AC9B968)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=63 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=388 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 7 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=7 GB) - (Type=0C)

==================== End Of Log ============================Additional scan result of Farbar Recovery Scan Tool (x86) Version: 23-11-2013 03
Ran by pc at 2013-12-03 10:20:35
Running from C:\Users\pc\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Emsisoft Anti-Malware (Enabled - Out of date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Anti-Malware (Enabled - Out of date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}

==================== Installed Programs ======================

32 Bit HP CIO Components Installer (Version: 1.0.0)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8)
AIO_CDB_ProductContext (Version: 82.0.242.000)
AIO_CDB_Software (Version: 82.0.242.000)
AIO_Scan (Version: 82.0.173.000)
Atheros Client Installation Program (Version: 7.0)
BufferChm (Version: 82.0.173.000)
Copy (Version: 82.0.188.000)
CustomerResearchQFolder (Version: 1.00.0000)
Destinations (Version: 82.0.173.000)
DeviceManagementQFolder (Version: 1.00.0000)
DocProc (Version: 8.1.0.0)
DocProcQFolder (Version: 1.00.0000)
Dropbox (HKCU Version: 2.0.22)
Emsisoft Anti-Malware (Version: 8.1)
eSupportQFolder (Version: 1.00.0000)
F300 (Version: 82.0.242.000)
F300_Help (Version: 82.0.242.000)
F300Trb (Version: 82.0.242.000)
Fax (Version: 82.0.188.000)
HPProductAssistant (Version: 82.0.173.000)
Intel(R) Graphics Media Accelerator Driver
Java 7 Update 45 (Version: 7.0.450)
Java Auto Updater (Version: 2.1.9.8)
Lunascape6 (All Users) (Version: 6.8.9.27075)
MarketResearch (Version: 82.0.174.000)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mobile Partner (Version: 11.302.09.04.382)
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MyKeyFinder (Version: 2012)
Paint.NET v3.5.10 (Version: 3.60.0)
Realtek 8169 8168 8101E 8102E Ethernet Driver (Version: 1.00.0000)
Realtek High Definition Audio Driver (Version: 6.0.1.5618)
Revo Uninstaller 1.95 (Version: 1.95)
Scan (Version: 8.1.0.0)
SolutionCenter (Version: 82.0.188.000)
Status (Version: 82.0.173.000)
Toolbox (Version: 82.0.173.000)
TrayApp (Version: 82.0.188.000)
UnloadSupport (Version: 1.00.0000)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Visual C++ 9.0 CRT (x86) WinSXS MSM (Version: 9.0)
WashAndGo (Version: 17.7)
WebReg (Version: 82.0.173.000)

==================== Restore Points  =========================

01-12-2013 07:35:17 Windows Update
01-12-2013 16:06:19 Windows Update
01-12-2013 17:25:25 Windows Update
01-12-2013 18:46:13 Windows Update

==================== Hosts content: ==========================

2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost
::1            localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0AD797DB-679C-4254-BF1F-187451269FBE} - System32\Tasks\RunAsStdUser Task => C:\Program Files\NetDrive\netdrive.exe
Task: {0B923855-EFEC-4D6E-BF2C-25DC4D5D10FF} - System32\Tasks\WebReg Deskjet F300 series => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
Task: {0DB7D8BC-5FDE-4CFF-AB4F-B3762ACCEAB8} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - pc => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {139DBA5E-5972-4876-81F7-3862E17F0935} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2008-01-21] (Microsoft Corporation)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {2504DD76-8025-4C3F-A286-DF638CF048E8} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => C:\Program Files\Windows Defender\MpCmdRun.exe [2008-01-21] (Microsoft Corporation)
Task: {2DE1ED62-3B3F-4610-86ED-E838057F6213} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {47CC68FF-DD27-4AC9-BD10-1206F7305F4A} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {51C71A63-7357-4492-80C2-B8A4B3E96899} - System32\Tasks\AbelssoftPreloader => C:\Program Files\WashAndGo\AbelssoftPreloader.exe [2013-11-18] (Microsoft)
Task: {793C7D04-E0F7-41B2-9376-BCB3BC77411B} - System32\Tasks\CheckDriveBackgroundGuard => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: {8CFE559A-52BC-433E-B3B9-E2296815C970} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-27] (Adobe Systems Incorporated)
Task: {99982336-9432-499D-A415-B1D0E9EE6E6A} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => C:\Windows\System32\pla.dll [2008-01-21] (Microsoft Corporation)
Task: {A7F9AF08-9C24-4D9D-A77B-6C6A29823CB3} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-12] (Microsoft Corporation)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: C:\Windows\Tasks\AbelssoftPreloader.job => C:\Program Files\WashAndGo\AbelssoftPreloader.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\CheckDriveBackgroundGuard.job => C:\Program Files\CheckDrive\CheckDriveBackgroundGuard.exe
Task: C:\Windows\Tasks\WebReg Deskjet F300 series.job => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe

==================== Loaded Modules (whitelisted) =============

2011-06-27 15:24 - 2007-08-23 15:39 - 00014848 _____ () C:\Program Files\Mobile Partner\isaputrace.dll
2011-06-27 15:24 - 2009-12-10 10:51 - 00114688 _____ () C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll
2011-06-27 15:24 - 2009-09-19 10:21 - 00139264 _____ () C:\Program Files\Mobile Partner\NetInfoPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:48 - 00090112 _____ () C:\Program Files\Mobile Partner\DialUpPlugin.dll
2011-06-27 15:24 - 2009-06-18 09:54 - 00057344 _____ () C:\Program Files\Mobile Partner\ConfigFilePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:40 - 00991232 _____ () C:\Program Files\Mobile Partner\NDISAPI.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00155648 _____ () C:\Program Files\Mobile Partner\DetectDev.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00557056 _____ () C:\Program Files\Mobile Partner\atcomm.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\XCodec.dll
2011-06-27 15:24 - 2009-05-23 10:02 - 00061440 _____ () C:\Program Files\Mobile Partner\DeviceOperate.dll
2011-06-27 15:24 - 2009-06-18 09:56 - 00032768 _____ () C:\Program Files\Mobile Partner\NotifyServicePlugin.dll
2011-06-27 15:24 - 2009-12-10 10:52 - 00192512 _____ () C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00143360 _____ () C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll
2011-06-27 15:24 - 2007-07-31 14:50 - 00090112 _____ () C:\Program Files\Mobile Partner\FileManager.dll
2011-06-27 15:24 - 2009-06-19 14:10 - 00159744 _____ () C:\Program Files\Mobile Partner\SMSPlugin.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00201640 _____ () C:\Program Files\Java\jre7\bin\jp2iexp.dll
2013-10-27 12:29 - 2013-10-27 12:29 - 00016808 _____ () C:\Program Files\Java\jre7\bin\jp2native.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (12/01/2013 05:17:09 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - 1>Failed to compile: mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070003


System errors:
=============
Error: (12/03/2013 09:46:45 AM) (Source: Dhcp) (User: )
Description: Die IP-Adresslease 10.153.58.122 für die Netzwerkkarte mit der Netzwerkadresse 001E101F63CF wurde durch den DHCP-Server 10.40.62.94 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet).

Error: (12/03/2013 09:08:34 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (12/03/2013 09:06:52 AM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (12/03/2013 09:06:52 AM) (Source: Service Control Manager) (User: )
Description: HP CUE DeviceDiscovery Service%%2

Error: (12/02/2013 10:27:36 AM) (Source: Tcpip) (User: )
Description: Das System hat einen Adressenkonflikt der IP-Adresse 10.51.157.43 mit dem Computer mit der
Netzwerkhardwareadresse 02-50-F3-00-00-00 ermittelt. Netzwerkvorgänge könnten daher auf diesem
System unterbrochen werden.

Error: (12/02/2013 10:27:36 AM) (Source: Dhcp) (User: )
Description: Die IP-Adresslease 10.51.157.43 für die Netzwerkkarte mit der Netzwerkadresse 001E101F21C1 wurde durch den DHCP-Server 10.72.69.98 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet).

Error: (12/02/2013 09:21:53 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (12/02/2013 09:20:31 AM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater13.0.0%%3

Error: (12/02/2013 09:20:31 AM) (Source: Service Control Manager) (User: )
Description: HP CUE DeviceDiscovery Service%%2

Error: (12/01/2013 09:38:47 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032


Microsoft Office Sessions:
=========================
Error: (12/01/2013 05:17:09 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - 1>Failed to compile: mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070003
mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089


CodeIntegrity Errors:
===================================
  Date: 2013-11-16 19:42:13.862
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:12.565
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:11.355
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:10.079
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:08.808
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:42:07.537
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:59.462
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:58.202
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:56.953
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-11-16 19:41:55.763
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 52%
Total physical RAM: 2038.64 MB
Available physical RAM: 972.93 MB
Total Pagefile: 4320.32 MB
Available Pagefile: 2809.07 MB
Total Virtual: 2047.88 MB
Available Virtual: 1905.56 MB

==================== Drives ================================

Drive c: (OS_Install) (Fixed) (Total:63.48 GB) (Free:32.76 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Mobile Partner) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS
Drive e: (Data) (Fixed) (Total:387.63 GB) (Free:359 GB) NTFS
Drive i: (Lexar) (Removable) (Total:7.46 GB) (Free:5.79 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 9AC9B968)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=63 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=388 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 7 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=7 GB) - (Type=0C)

==================== End Of Log ============================


schrauber 04.12.2013 10:15

Zitat:

ab in Bett mit dir.
das war jetzt eindeutig zweideutig :D


Die Auflistung der noch bestehenden Problem fehlt :)

mädchen 05.12.2013 10:22

Guten Morgen,
das war eindeutig fürsorglich gemeint,du mit deiner Grippe!

Ich wollte erst Tastaur,Mouse und Druckerkabel erneuern bevor ich wieder schrei dass was nicht klappt. Schäm....Tastaur war dann wohl kaputt,Mouse auch.Text lässt sich wunderbar eintippen,markieren geht auch wieder,scrollen auch, aber den Drucker habe ich nicht installieren können.

Die Musik auf you tube kommt in Bruchstücken,drop down Menues öffnen sich nicht immer und bleiben auch,lassen sich nicht wegklicken.Nach dem Starten nach Eingabe des Passwortes bleibt das Ding stehen,die Internetverbindung trennt sich immer wieder von selbst,Dateien können nicht geöffnet werden,öfter die Netzwerkfehlermeldung dass ein anderer PC die gleiche IP Adresse hat und es deshalb zu Konflikten kommt,automatische Installation der Tastaur stoppte mehrmals,Druckerinstallation unmöglich,da wird dann ein Bildchen mit durchgekreuztem Druckerkabel angezeigt,geht nicht.Und komischerweise kann ich das weder abbrechen noch das Fenster schliessen.Mausanzeiger hängt auch manchmal fest,lässt sich nicht mehr bewegen.Die Kreuzchen zum Schließen von Seiten werden manchmal nicht angezeigt.Mehrere Fenster/Seiten werden gleichzeitig in Bruchstücken angezeigt.Will ich links von google anklicken verändert sich der Mausanzeiger,habe dann einen Cursor(?- sieht aus wie römisch eins) und kann nicht anklicken.Immer wieder keine Rückmeldung von Lunascape oder von anderen Programmen.Dauernd : dieses Programm kann die Webseite nicht anzeigen.Will ich mich einloggen und klick auf den Button bleibt das Ding wieder stehen.Dieser Balken zum rauf und runterschieben bleibt grau beim anklicken und lässt sich nicht schieben.Mehr fällt mir im Moment nicht ein.
lg,
mädchen

schrauber 05.12.2013 13:17

Für alle deine Probleme, bis auf dieses
Zitat:

öfter die Netzwerkfehlermeldung dass ein anderer PC die gleiche IP Adresse hat und es deshalb zu Konflikten kommt
würde ich dir jetzt folgendes raten:

Daten sichern, alles formatieren, und einmal sauber neuaufsetzen, sonast bekommst Du da keine Ruhe mehr rein.

Wenn das getan ist, und das hier

Zitat:

öfter die Netzwerkfehlermeldung dass ein anderer PC die gleiche IP Adresse hat und es deshalb zu Konflikten kommt
immer noch vorkommt, schauen wir uns deine netzwerk Config an, ich hatte das auch mal.

mädchen 05.12.2013 17:47

Hi,

Daten sichern das kann ich.Habe ich ja vor der längeren Pause schon gemacht.
Aber formatieren und neu aufsetzen........da weiß ich wieder nicht wie man sowas macht.
Du scheinst immer zu vergessen dass ich keinen blassen Schimmer habe.

grüße,
mädchen

schrauber 06.12.2013 10:20

Dann fangen wir vorne an:

Windows DVD zur Hand? :)

Sichere als schon mal deine Daten, melde dich wenn erledigt :)

mädchen 06.12.2013 18:24

Daten sind schon gesichert.Ich weiß nur nach dem Umzug nicht wo meine DVDS abgeblieben sind.Wenn ich sie nicht finde,gibts ne Möglichkeit sich eine runterzuladen? Habe schon gestern gesucht im Internet aber nichts gefunden.
Apropos Daten......ich habe das meiste ja vor Monaten gemacht,als die Kiste noch infiziert war.D.h. der ganze Kram muss dann nochmal gereinigt werden,ne?
Jetzt habe ich nur n kleinen Stick da,da kann ich das nicht alles neu sichern.
LG
mädchen

Ha!
Wer Ordnung hält ist nur zu faul zu suchen.
Ich habe eine CD von meinem Computer gefunden,da steht nur nix drauf von Windows Vista...hä?...nur der Name des PCs .Aber was soll da sonst drauf sein? Und dann habe ich noch eine Motherboard Support CD gefunden,wobei ich nicht weiß ob sie von diesem Pc ist oder von meinem alten.Braucht man das auch?

schrauber 07.12.2013 12:14

Die brauchen wir auch. Die anderen CD mal einlegen (wo nix drauf steht) was siehst du im Explorer?

Die gesicherten Daten sollten i.O sein,wenn es nur Texte, Musik und so ist.


Alle Zeitangaben in WEZ +1. Es ist jetzt 08:18 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19