Na dann mal los, als erstes das Log von Eset:
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=f5dbab67ebe03a48858dfdb409f65f60
# engine=14848
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-08-21 11:38:55
# local_time=2013-08-21 01:38:55 (+0100, Westeuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=1286 16777214 100 97 10022 31851457 0 0
# scanned=103255
# found=33
# cleaned=0
# scan_time=6030
sh=91403A26D23237F6F93273B244B2FD558ACCF3F7 ft=1 fh=2db2a806fbb0a318 vn="probably a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\AdwCleaner\Quarantine\C\Dokumente und Einstellungen\All Users\Anwendungsdaten\Tarma Installer\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}\_Setupx.dll.vir"
sh=FFB950AE88F59EABAF949E700AFA1B7E53EB5B5B ft=1 fh=84407a9eea2f4085 vn="probably a variant of Win32/Adware.Yontoo.A application" ac=I fn="C:\AdwCleaner\Quarantine\C\Programme\Web Cake\WebCakeIEClient.dll.vir"
sh=500C84645A77F26CDF1AFE3E5F256CF4CDB48E8A ft=0 fh=0000000000000000 vn="Java/TrojanDownloader.Agent.NAK trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\18\12b6d4d2-5c4957f6"
sh=500C84645A77F26CDF1AFE3E5F256CF4CDB48E8A ft=0 fh=0000000000000000 vn="Java/TrojanDownloader.Agent.NAK trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\18\12b6d4d2-68990de5"
sh=500C84645A77F26CDF1AFE3E5F256CF4CDB48E8A ft=0 fh=0000000000000000 vn="Java/TrojanDownloader.Agent.NAK trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\18\12b6d4d2-6f5e4b6c"
sh=71942C47F9CAA1A1B31BF55ABED781A46F5C837F ft=0 fh=0000000000000000 vn="a variant of Java/TrojanDownloader.OpenStream.NCZ trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\2\1173f882-5daefe45"
sh=A0FDE7DE69B3B12C240E6D1081FDB2559201B8D0 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2009-3869.B trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\25\67dff619-5cb6a59e"
sh=A0FDE7DE69B3B12C240E6D1081FDB2559201B8D0 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2009-3869.B trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\25\67dff619-6eeaf711"
sh=A0FDE7DE69B3B12C240E6D1081FDB2559201B8D0 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2009-3869.B trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\25\67dff619-7dff8ab0"
sh=D88F7E483978D8FBDBE24EC01C0EA599EA1C77D8 ft=0 fh=0000000000000000 vn="a variant of Java/Agent.BP trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\38\6095e9a6-4d7b2d11"
sh=2EA4FC1715A53441E82F448014ED2A9425A36E04 ft=0 fh=0000000000000000 vn="a variant of Java/TrojanDownloader.Agent.NAN trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\4\436a0444-18785693"
sh=2EA4FC1715A53441E82F448014ED2A9425A36E04 ft=0 fh=0000000000000000 vn="a variant of Java/TrojanDownloader.Agent.NAN trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\4\436a0444-38a0aaae"
sh=2EA4FC1715A53441E82F448014ED2A9425A36E04 ft=0 fh=0000000000000000 vn="a variant of Java/TrojanDownloader.Agent.NAN trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\4\436a0444-5bd21f99"
sh=9AE9EDABC7C5B23E4B9305963E0BAA6A6D1A1A7B ft=0 fh=0000000000000000 vn="probably a variant of Win32/Agent.FQRCZBA trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\54\444a7a76-23616fc4"
sh=9AE9EDABC7C5B23E4B9305963E0BAA6A6D1A1A7B ft=0 fh=0000000000000000 vn="probably a variant of Win32/Agent.FQRCZBA trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\54\444a7a76-3ad911ab"
sh=9AE9EDABC7C5B23E4B9305963E0BAA6A6D1A1A7B ft=0 fh=0000000000000000 vn="probably a variant of Win32/Agent.FQRCZBA trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\54\444a7a76-5138ea85"
sh=143AD35452CCFB1B18AA0D926A2EB02483518A1C ft=0 fh=0000000000000000 vn="a variant of Java/Agent.A trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\60\601406bc-557a01e9"
sh=9AE9EDABC7C5B23E4B9305963E0BAA6A6D1A1A7B ft=0 fh=0000000000000000 vn="probably a variant of Win32/Agent.FQRCZBA trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmaudio.jar-4219cb0d-7dad7828.zip"
sh=2EA4FC1715A53441E82F448014ED2A9425A36E04 ft=0 fh=0000000000000000 vn="a variant of Java/TrojanDownloader.Agent.NAN trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmseria.jar-14a8bfaf-2a49f05a.zip"
sh=A0FDE7DE69B3B12C240E6D1081FDB2559201B8D0 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2009-3869.B trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsetfi.jar-79c7685c-23145e35.zip"
sh=500C84645A77F26CDF1AFE3E5F256CF4CDB48E8A ft=0 fh=0000000000000000 vn="Java/TrojanDownloader.Agent.NAK trojan" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Sun\Java\Deployment\cache\javapi\v1.0\jar\nc.jar-51d0bfb5-67c746e2.zip"
sh=7295BCEEAEF79F82C5C69C255D0473E45CEC38AA ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\HP_Besitzer\Lokale Einstellungen\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\10\42633ca-3dfd3455"
sh=375347DEFD101FBE244DCF0C0D89D89578A053B8 ft=1 fh=71558cf322c1751b vn="probably a variant of Win32/Adware.Yontoo.A application" ac=I fn="C:\Programme\Movdap\WebCakeIEClient.dll"
sh=5576FAF2DB1B0B1D7F395BBC7DC61BF70430E2F8 ft=1 fh=5ee69de9dd0b2c20 vn="Win32/AdWare.Yontoo.E application" ac=I fn="C:\System Volume Information\_restore{2005CC72-E1D4-412C-8599-FDC32E05059E}\RP422\A0120497.exe"
sh=034BE991CB00B240F574CF8B7F0B1F407B1FD9B8 ft=1 fh=d540e00c2c6e80d8 vn="probably a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\System Volume Information\_restore{2005CC72-E1D4-412C-8599-FDC32E05059E}\RP422\A0120506.dll"
sh=A4127A1128284ACDFBE360776C85B37DE8D3CCA9 ft=1 fh=5b842a00c26b3b09 vn="a variant of Win32/Adware.AddLyrics.K application" ac=I fn="C:\System Volume Information\_restore{2005CC72-E1D4-412C-8599-FDC32E05059E}\RP425\A0121851.dll"
sh=8111DA165C8EA0528116AB614FE3EBD330B01C23 ft=1 fh=238e188e26ea23e7 vn="a variant of Win32/Adware.AddLyrics.K application" ac=I fn="C:\System Volume Information\_restore{2005CC72-E1D4-412C-8599-FDC32E05059E}\RP425\A0121853.exe"
sh=CE7C79C57829BE7051CC41871C460612ED2FF22F ft=1 fh=5b842a006057257e vn="a variant of Win32/Adware.AddLyrics.K application" ac=I fn="C:\System Volume Information\_restore{2005CC72-E1D4-412C-8599-FDC32E05059E}\RP427\A0122916.dll"
sh=AE89D918E85767A364B914F1C59D8925E8C6C3D4 ft=1 fh=47397c7a8f8b8411 vn="a variant of Win32/Adware.AddLyrics.K application" ac=I fn="C:\System Volume Information\_restore{2005CC72-E1D4-412C-8599-FDC32E05059E}\RP427\A0122918.exe"
sh=CED7867233AB7367F73893235ACDD419263CC31F ft=1 fh=a172cba60989904a vn="a variant of Win32/Adware.AddLyrics.J application" ac=I fn="C:\System Volume Information\_restore{2005CC72-E1D4-412C-8599-FDC32E05059E}\RP430\A0123797.dll"
sh=FE8E17D8C8D36C5F4F8DAE693A7636308E365FD0 ft=1 fh=c71c001175af56fc vn="a variant of Win32/Adware.AddLyrics.J application" ac=I fn="C:\System Volume Information\_restore{2005CC72-E1D4-412C-8599-FDC32E05059E}\RP430\A0123799.exe"
sh=91403A26D23237F6F93273B244B2FD558ACCF3F7 ft=1 fh=2db2a806fbb0a318 vn="probably a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\System Volume Information\_restore{2005CC72-E1D4-412C-8599-FDC32E05059E}\RP431\A0124232.dll"
sh=FFB950AE88F59EABAF949E700AFA1B7E53EB5B5B ft=1 fh=84407a9eea2f4085 vn="probably a variant of Win32/Adware.Yontoo.A application" ac=I fn="C:\System Volume Information\_restore{2005CC72-E1D4-412C-8599-FDC32E05059E}\RP431\A0124322.dll"
Als zweites das Log vom Securitycheck:
Results of screen317's Security Check version 0.99.72
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Kaspersky Internet Security 2013
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 1.75.0.1300
JavaFX 2.1.1
Java(TM) 6 Update 24
Java 7 Update 25
Adobe Flash Player 11.7.700.224
Adobe Reader XI
Mozilla Firefox (23.0.1)
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C::
````````````````````End of Log``````````````````````
Und zu guter letzt nochmal ein Log von FRST:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-08-2013
Ran by HP_Besitzer (administrator) on 21-08-2013 14:05:55
Running from C:\Dokumente und Einstellungen\HP_Besitzer\Eigene Dateien\Downloads
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
(Vodafone) C:\Programme\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Hama GmbH & Co KG) C:\Programme\Hama\Common\RaUI.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Mozilla Corporation) C:\Programme\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Programme\Mozilla Firefox\plugin-container.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [15969280 2006-01-23] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AVP] - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356376 2013-03-15] (Kaspersky Lab ZAO)
HKLM\...\Run: [Adobe ARM] - C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
Winlogon\Notify\AtiExtEvent: Ati2evxx.dll (ATI Technologies Inc.)
Winlogon\Notify\klogon: C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
HKCU\...\Run: [swg] - C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [68856 2008-01-16] (Google Inc.)
HKU\Default User\...\Run: [MSMSGS] - C:\Programme\Messenger\msmsgs.exe [ 2008-04-14] (Microsoft Corporation)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Hama Wireless LAN Utility.lnk
ShortcutTarget: Hama Wireless LAN Utility.lnk -> C:\Programme\Hama\Common\RaUI.exe (Hama GmbH & Co KG)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
HKCU\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {12378551-5AED-4537-87A6-1C2A8C0E4CE2} URL = hxxp://www.google.de/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7HPEA_deDE313
SearchScopes: HKCU - {90989A8E-7FD1-49C2-A41D-7247C3831AF0} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=99E6B5C7-12C1-43C1-AB73-DBA34A2572A0&apn_sauid=5853BE2F-8183-40E8-922F-BC11E2A71723
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: LyricsContainer - {77e880b5-cae7-4928-8507-ec2e5007e73e} - C:\Programme\LyricsContainer\128.dll No File
BHO: No Name - {78875F5C-A685-4405-8DC5-D48DC65452B0} - No File
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
BHO: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Programme\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -&Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: ipp - No CLSID Value -
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Winsock: Catalog9 01 bmnet.dll File Not found (Bytemobile, Inc.)
Winsock: Catalog9 02 bmnet.dll File Not found (Bytemobile, Inc.)
Winsock: Catalog9 03 bmnet.dll File Not found (Bytemobile, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\awtgne69.default
FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", "");
FF Homepage: web.de
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.11.2240 - C:\Programme\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.2.2298 - C:\Programme\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.1348 - C:\Programme\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: DealPly Shopping - C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\awtgne69.default\Extensions\{e53a26f5-7199-4a5b-86f5-d2e86854b979}
FF Extension: fdm_ffext - C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\awtgne69.default\Extensions\fdm_ffext@freedownloadmanager.org
FF Extension: Default - C:\Programme\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] C:\Programme\Vodafone\Vodafone Mobile Connect\Optimization Client\addon\
FF Extension: Bytemobile Optimization Client - C:\Programme\Vodafone\Vodafone Mobile Connect\Optimization Client\addon\
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM\...\Firefox\Extensions: C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Content Blocker - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF HKCU\...\Firefox\Extensions: [Lyrics@LyricsContainer.co] C:\Programme\LyricsContainer\128.xpi
========================== Services (Whitelisted) =================
S2 AVP; C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356376 2013-03-15] (Kaspersky Lab ZAO)
S2 gupdate; C:\Programme\Google\Update\GoogleUpdate.exe [135664 2010-01-29] (Google Inc.)
S3 gupdatem; C:\Programme\Google\Update\GoogleUpdate.exe [135664 2010-01-29] (Google Inc.)
S4 gusvc; C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe [194032 2012-08-24] (Google)
S4 IDriverT; C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation)
R2 MBAMScheduler; C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 Microsoft Office Groove Audit Service; C:\Programme\Microsoft Office\Office12\GrooveAuditService.exe [64856 2009-02-26] (Microsoft Corporation)
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [117656 2013-08-17] (Mozilla Foundation)
S3 odserv; C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE [440696 2011-07-20] (Microsoft Corporation)
S3 ose; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [145184 2006-10-26] (Microsoft Corporation)
S0 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [69632 2004-09-29] (HP)
R2 VMCService; C:\Programme\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [9216 2009-09-11] (Vodafone)
S4 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-11-03] (Microsoft Corporation)
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
S2 dealplylive; C:\Programme\DealPlyLive\Update\DealPlyLive.exe /svc [x]
S3 dealplylivem; C:\Programme\DealPlyLive\Update\DealPlyLive.exe /medsvc [x]
S4 JavaQuickStarterService; "C:\Programme\Java\jre7\bin\jqs.exe" -service -config "C:\Programme\Java\jre7\lib\deploy\jqs\jqs.conf" [x]
==================== Drivers (Whitelisted) ====================
R2 AegisP; C:\Windows\System32\DRIVERS\AegisP.sys [21419 2009-12-30] (Meetinghouse Data Communications)
S3 hwusbfake; C:\Windows\System32\DRIVERS\ewusbfake.sys [102656 2009-06-29] (Huawei Technologies Co., Ltd.)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [136024 2012-06-19] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [591968 2013-04-24] (Kaspersky Lab ZAO)
R3 klim5; C:\Windows\System32\DRIVERS\klim5.sys [35672 2012-06-27] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [24408 2012-10-25] (Kaspersky Lab)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [24920 2012-10-25] (Kaspersky Lab)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [44000 2013-06-19] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [145040 2013-04-24] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 PROCEXP113; C:\WINDOWS\system32\Drivers\PROCEXP113.SYS [12568 2013-08-19] (Sysinternals - www.sysinternals.com)
R3 RT73; C:\Windows\System32\DRIVERS\rt73.sys [451968 2007-10-01] (Ralink Technology, Corp.)
S3 rtl8139; C:\Windows\System32\DRIVERS\RTL8139.SYS [20992 2004-08-03] (Realtek Semiconductor Corporation)
S3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2008-11-19] (LG Electronics Inc.)
S3 UsbDiag; C:\Windows\System32\DRIVERS\lgusbdiag.sys [19968 2008-11-19] (LG Electronics Inc.)
S3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [24832 2008-11-19] (LG Electronics Inc.)
S3 ATIXPGAA; \??\C:\PCDR5\ATIXPGAA.SYS [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 esgiguard; \??\C:\Programme\Enigma Software Group\SpyHunter\esgiguard.sys [x]
S3 PCD5SRVC{085326CB-51A3560A-05010003}; \??\C:\PROGRA~1\PC-DOC~1\PCD5SRVC.pkms [x]
S3 PcdrNdisuio; system32\DRIVERS\pcdrndisuio.sys [x]
U3 TlntSvr;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-20 18:59 - 2013-08-20 19:04 - 00000000 ____D C:\AdwCleaner
2013-08-20 18:32 - 2013-08-20 18:32 - 00000767 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-20 18:32 - 2013-08-20 18:32 - 00000000 ____D C:\Programme\Malwarebytes' Anti-Malware
2013-08-20 18:32 - 2013-08-20 18:32 - 00000000 ____D C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Malwarebytes
2013-08-20 18:32 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-08-19 18:40 - 2013-08-19 18:40 - 00021067 _____ C:\ComboFix.txt
2013-08-19 18:40 - 2013-08-19 18:40 - 00012568 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP113.SYS
2013-08-19 13:18 - 2013-08-19 13:18 - 00000000 ____D C:\FRST
2013-08-19 13:16 - 2013-08-21 13:21 - 00000896 _____ C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineUA.job
2013-08-19 13:16 - 2013-08-21 13:21 - 00000892 _____ C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineCore.job
2013-08-19 13:16 - 2013-08-19 13:16 - 00000000 ____D C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\0D0S1L2Z1P1B0T1P1B2Z
2013-08-19 13:14 - 2013-08-19 13:14 - 00000746 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Open It!.lnk
2013-08-19 13:14 - 2013-08-19 13:14 - 00000000 ____D C:\Programme\OpenIt
2013-08-17 22:03 - 2013-08-18 11:18 - 00000000 ____D C:\Programme\Mozilla Firefox
2013-08-13 21:21 - 2013-08-13 21:21 - 00012656 _____ C:\WINDOWS\KB2862772-IE8.log
2013-08-13 21:06 - 2013-08-13 21:06 - 00005930 _____ C:\WINDOWS\KB2863058.log
2013-08-13 21:06 - 2013-08-13 21:06 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$
2013-08-13 21:06 - 2013-08-13 21:06 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$
2013-08-13 21:06 - 2013-08-13 21:06 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$
2013-08-13 21:05 - 2013-08-13 21:05 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$
2013-08-13 20:56 - 2013-08-13 21:06 - 00012158 _____ C:\WINDOWS\KB2859537.log
2013-08-13 20:56 - 2013-08-13 21:06 - 00010580 _____ C:\WINDOWS\KB2850869.log
2013-08-11 20:41 - 2013-08-20 18:23 - 00000000 ____D C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Movdap
2013-08-11 20:41 - 2013-08-13 20:28 - 00000000 ____D C:\Programme\Movdap
2013-08-05 19:36 - 2013-08-05 19:36 - 00001725 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader XI.lnk
2013-07-26 00:06 - 2013-08-13 21:21 - 00000000 ____D C:\WINDOWS\system32\MRT
==================== One Month Modified Files and Folders =======
2013-08-21 14:05 - 2010-03-26 14:48 - 00000430 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{78FACF78-67DD-4A88-B022-5384325BC146}.job
2013-08-21 14:03 - 2007-12-27 18:22 - 00000000 ___RD C:\Programme
2013-08-21 14:02 - 2004-11-02 20:13 - 01950614 _____ C:\WINDOWS\WindowsUpdate.log
2013-08-21 14:01 - 2008-03-16 16:47 - 00000000 ____D C:\Dokumente und Einstellungen\HP_Besitzer\Desktop\Michael
2013-08-21 13:23 - 2010-01-29 00:27 - 00001090 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-21 13:21 - 2013-08-19 13:16 - 00000896 _____ C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineUA.job
2013-08-21 13:21 - 2013-08-19 13:16 - 00000892 _____ C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineCore.job
2013-08-21 12:21 - 2004-11-02 20:13 - 00032642 _____ C:\WINDOWS\SchedLgU.Txt
2013-08-21 11:55 - 2006-02-22 13:07 - 00000000 __SHD C:\Dokumente und Einstellungen\NetworkService
2013-08-21 11:16 - 2007-12-27 12:04 - 00000000 ___RD C:\Dokumente und Einstellungen\HP_Besitzer\Eigene Dateien\Eigene Bilder
2013-08-21 10:51 - 2010-01-29 00:27 - 00001086 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-21 10:51 - 2007-12-27 10:52 - 00000000 ____D C:\WINDOWS\system32\Lang
2013-08-21 10:51 - 2004-11-02 20:13 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-08-20 23:43 - 2007-12-27 12:04 - 00000190 ___SH C:\Dokumente und Einstellungen\HP_Besitzer\ntuser.ini
2013-08-20 23:43 - 2007-12-27 12:04 - 00000000 ____D C:\Dokumente und Einstellungen\HP_Besitzer
2013-08-20 23:43 - 2004-11-02 20:00 - 00000216 _____ C:\WINDOWS\wiadebug.log
2013-08-20 23:43 - 2004-11-02 20:00 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-08-20 22:43 - 2008-02-10 12:41 - 00000000 ____D C:\Dokumente und Einstellungen\HP_Besitzer\Desktop\Manfred
2013-08-20 19:12 - 2010-07-25 11:08 - 00000000 ____D C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Software Informer
2013-08-20 19:04 - 2013-08-20 18:59 - 00000000 ____D C:\AdwCleaner
2013-08-20 19:04 - 2007-12-27 12:04 - 00000000 ___RD C:\Dokumente und Einstellungen\HP_Besitzer\Startmenü\Programme
2013-08-20 18:32 - 2013-08-20 18:32 - 00000767 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-20 18:32 - 2013-08-20 18:32 - 00000000 ____D C:\Programme\Malwarebytes' Anti-Malware
2013-08-20 18:32 - 2013-08-20 18:32 - 00000000 ____D C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Malwarebytes
2013-08-20 18:23 - 2013-08-11 20:41 - 00000000 ____D C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Movdap
2013-08-20 12:04 - 2008-01-27 14:39 - 00032274 _____ C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\wklnhst.dat
2013-08-20 12:04 - 2007-12-27 10:53 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2013-08-19 18:52 - 2005-10-27 01:43 - 00000000 ____D C:\WINDOWS\Help
2013-08-19 18:46 - 2013-01-09 13:28 - 00123797 _____ C:\WINDOWS\setupapi.log
2013-08-19 18:40 - 2013-08-19 18:40 - 00021067 _____ C:\ComboFix.txt
2013-08-19 18:40 - 2013-08-19 18:40 - 00012568 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP113.SYS
2013-08-19 18:40 - 2011-02-23 19:05 - 00000000 ____D C:\Qoobox
2013-08-19 18:34 - 2004-11-02 19:57 - 00000227 _____ C:\WINDOWS\system.ini
2013-08-19 18:32 - 2004-11-02 20:13 - 46923776 _____ C:\WINDOWS\system32\config\software.bak
2013-08-19 18:32 - 2004-11-02 20:13 - 08388608 _____ C:\WINDOWS\system32\config\system.bak
2013-08-19 18:32 - 2004-11-02 20:13 - 05033984 _____ C:\WINDOWS\system32\config\default.bak
2013-08-19 18:32 - 2004-11-02 20:13 - 00262144 _____ C:\WINDOWS\system32\config\SECURITY.bak
2013-08-19 18:32 - 2004-11-02 20:13 - 00024576 _____ C:\WINDOWS\system32\config\SAM.bak
2013-08-19 18:31 - 2013-07-04 13:08 - 00008192 ____H C:\WINDOWS\system32\config\SECURITY.tmp.LOG
2013-08-19 18:31 - 2011-02-23 19:09 - 00000000 ____D C:\WINDOWS\ERDNT
2013-08-19 18:29 - 2007-12-27 10:35 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-08-19 13:18 - 2013-08-19 13:18 - 00000000 ____D C:\FRST
2013-08-19 13:16 - 2013-08-19 13:16 - 00000000 ____D C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\0D0S1L2Z1P1B0T1P1B2Z
2013-08-19 13:14 - 2013-08-19 13:14 - 00000746 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Open It!.lnk
2013-08-19 13:14 - 2013-08-19 13:14 - 00000000 ____D C:\Programme\OpenIt
2013-08-18 20:13 - 2012-06-29 17:12 - 00000000 ____D C:\Programme\Mozilla Maintenance Service
2013-08-18 11:18 - 2013-08-17 22:03 - 00000000 ____D C:\Programme\Mozilla Firefox
2013-08-13 21:21 - 2013-08-13 21:21 - 00012656 _____ C:\WINDOWS\KB2862772-IE8.log
2013-08-13 21:21 - 2013-07-26 00:06 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-08-13 21:21 - 2007-12-27 10:43 - 00524195 _____ C:\WINDOWS\updspapi.log
2013-08-13 21:21 - 2004-11-02 20:08 - 01149962 _____ C:\WINDOWS\tsoc.log
2013-08-13 21:21 - 2004-11-02 20:08 - 00971157 _____ C:\WINDOWS\comsetup.log
2013-08-13 21:21 - 2004-11-02 20:08 - 00589678 _____ C:\WINDOWS\ntdtcsetup.log
2013-08-13 21:21 - 2004-11-02 20:08 - 00473162 _____ C:\WINDOWS\iis6.log
2013-08-13 21:21 - 2004-11-02 20:08 - 00160591 _____ C:\WINDOWS\ocmsn.log
2013-08-13 21:21 - 2004-11-02 20:08 - 00001374 _____ C:\WINDOWS\imsins.log
2013-08-13 21:21 - 2004-11-02 20:03 - 02996935 _____ C:\WINDOWS\FaxSetup.log
2013-08-13 21:21 - 2004-11-02 20:03 - 01461857 _____ C:\WINDOWS\ocgen.log
2013-08-13 21:21 - 2004-11-02 20:03 - 00150340 _____ C:\WINDOWS\msgsocm.log
2013-08-13 21:16 - 2008-09-24 20:24 - 75778376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-08-13 21:10 - 2004-11-02 20:10 - 01185362 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-08-13 21:06 - 2013-08-13 21:06 - 00005930 _____ C:\WINDOWS\KB2863058.log
2013-08-13 21:06 - 2013-08-13 21:06 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$
2013-08-13 21:06 - 2013-08-13 21:06 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$
2013-08-13 21:06 - 2013-08-13 21:06 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$
2013-08-13 21:06 - 2013-08-13 20:56 - 00012158 _____ C:\WINDOWS\KB2859537.log
2013-08-13 21:06 - 2013-08-13 20:56 - 00010580 _____ C:\WINDOWS\KB2850869.log
2013-08-13 21:06 - 2008-01-14 23:31 - 00637876 _____ C:\WINDOWS\system32\TZLog.log
2013-08-13 21:06 - 2004-11-02 20:08 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-08-13 21:05 - 2013-08-13 21:05 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$
2013-08-13 20:28 - 2013-08-11 20:41 - 00000000 ____D C:\Programme\Movdap
2013-08-11 20:16 - 2004-11-02 20:09 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl
2013-08-05 19:36 - 2013-08-05 19:36 - 00001725 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader XI.lnk
2013-08-05 19:36 - 2009-01-04 12:12 - 00000000 ____D C:\Programme\Gemeinsame Dateien\Adobe
2013-08-05 19:36 - 2007-12-27 11:11 - 00000000 ____D C:\Programme\Adobe
2013-07-26 04:47 - 2012-06-13 22:07 - 00522240 ____N (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsdbgui.dll
2013-07-26 04:47 - 2009-08-02 23:28 - 00247808 ____N (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieproxy.dll
2013-07-26 04:47 - 2009-08-02 23:28 - 00012800 ____N (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpshims.dll
2013-07-26 04:47 - 2008-08-26 09:57 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iertutil.dll
2013-07-26 04:47 - 2008-08-26 09:57 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeeds.dll
2013-07-26 04:47 - 2008-08-26 09:57 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2013-07-26 04:47 - 2007-08-13 18:54 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2013-07-26 04:47 - 2007-08-13 18:54 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2013-07-26 04:47 - 2007-08-13 18:34 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 06017536 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 06017536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtml.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 01469440 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-07-26 04:47 - 2004-08-04 06:00 - 01469440 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetcpl.cpl
2013-07-26 04:47 - 2004-08-04 06:00 - 01215488 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 01215488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\urlmon.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wininet.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00759296 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\vgx.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00611840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstime.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00611840 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mstime.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\occache.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\occache.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iepeers.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\url.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\url.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtmled.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\licmgr10.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\licmgr10.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2013-07-26 04:47 - 2004-08-04 06:00 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsproxy.dll
2013-07-26 04:46 - 2010-06-10 06:46 - 00743424 ____N (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedvtool.dll
2013-07-26 04:46 - 2008-10-03 18:58 - 11113472 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieframe.dll
2013-07-26 04:46 - 2007-08-13 18:54 - 11113472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-07-26 04:46 - 2004-08-04 06:00 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2013-07-26 04:46 - 2004-08-04 06:00 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedkcs32.dll
2013-07-25 21:23 - 2004-08-04 06:00 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-07-25 21:23 - 2004-08-04 06:00 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ie4uinit.exe
2013-07-25 17:52 - 2004-08-04 06:00 - 00385024 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2004-08-04 06:00] - [2008-04-14 04:22] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\Windows\System32\winlogon.exe
[2004-08-04 06:00] - [2008-04-14 04:23] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\Windows\System32\svchost.exe
[2004-08-04 06:00] - [2008-04-14 04:23] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\Windows\System32\services.exe
[2004-08-04 06:00] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc
C:\Windows\System32\User32.dll
[2004-08-04 06:00] - [2008-04-14 04:22] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\Windows\System32\userinit.exe
[2004-08-04 06:00] - [2008-04-14 04:23] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\Windows\System32\Drivers\volsnap.sys
[2004-08-04 06:00] - [2008-04-14 03:52] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================
--- --- ---
Danke für deine hilfe, würde gerne noch erfahren wie ich so etwas in zukunft vermeiden oder beheben kann?