7schläfer | 17.10.2013 21:23 | zoek.exe lief problemlos durch. Nach automatischem Neustart gab es: Code:
Zoek.exe Version 4.0.0.5 Updated 09-October-2013
Tool run by Admin on 17.10.2013 at 19:13:13,70.
Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\Admin\Desktop\zoek\zoek.exe [Script inserted]
==== System Restore Info ======================
17.10.2013 19:16:07 Zoek.exe System Restore Point Created Succesfully.
==== Creating Sample__1922.zip ======================
Copied file C:\Users\Admin\AppData\Local\SoftwareInstaller.exe to sample\SoftwareInstaller.exe
sample\SoftwareInstaller.exe renamed to B751E6F7103F28A6CA9FEA4082C514C1
C:\Users\Public\Desktop\sample__1922.zip created successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-3965941951-1394972469-2686460599-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{A057A204-BACC-4D26-9990-79A187E2698E} deleted successfully
HKEY_USERS\S-1-5-21-3965941951-1394972469-2686460599-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\t1g6v5m1.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.de/");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=");
user_pref("browser.search.defaultenginename", "Norton Safe Search");
user_pref("browser.search.selectedEngine", "Norton Safe Search");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\t1g6v5m1.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\prefs.js:
user_pref("browser.startup.homepage", "https://startpage.com/do/mypage.pl?prf=5ca07097e7f5522e50fdce583ba87d4e");
user_pref("browser.search.defaulturl", "https://startpage.com/do/mypage.pl?prf=5ca07097e7f5522e50fdce583ba87d4e");
user_pref("browser.search.defaultenginename", "Startpage");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\prefs.js:
ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\t1g6v5m1.default
user.js not found
---- Lines Search removed from prefs.js ----
---- Lines Search modified from prefs.js ----
---- Lines delta removed from prefs.js ----
---- Lines delta modified from prefs.js ----
---- Lines blekko removed from prefs.js ----
---- Lines blekko modified from prefs.js ----
---- Lines 3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} removed from prefs.js ----
---- Lines 3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} modified from prefs.js ----
---- FireFox user.js and prefs.js backups ----
prefs__1924_.backup
ProfilePath: C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default
user.js not found
---- Lines Search removed from prefs.js ----
---- Lines Search modified from prefs.js ----
---- Lines delta removed from prefs.js ----
---- Lines delta modified from prefs.js ----
---- Lines blekko removed from prefs.js ----
---- Lines blekko modified from prefs.js ----
---- Lines 3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} removed from prefs.js ----
---- Lines 3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} modified from prefs.js ----
---- FireFox user.js and prefs.js backups ----
prefs__1924_.backup
==== Deleting Files \ Folders ======================
"C:\Users\Admin\AppData\Local\SoftwareInstaller.exe" deleted
"C:\Windows\system32\appdata" deleted
"C:\Program Files\Covus Freemium" deleted
"C:\Program Files\Common Files\DVDVideoSoft\bin" deleted
"C:\Program Files\WebEnhance" deleted
"C:\found.000" deleted
"C:\Users\Admin\AppData\Roaming\Uniblue" deleted
"C:\Users\Admin\Documents\Freemium Driver Utilities" deleted
"C:\ProgramData\Package Cache" deleted
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Covus Freemium" deleted
"C:\Windows\system32\config\systemprofile\AppData\LocalLow\AVG Secure Search" deleted
"C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\t1g6v5m1.default\ICQToolbarData" deleted
"C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\GoogleToolbarData" deleted
"C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\ICQToolbarData" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{38e9e285-5266-4fe2-b5b5-c14c29b0cd45}"="C:\Program Files\WebEnhance\webenhance.xpi" []
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"{38e9e285-5266-4fe2-b5b5-c14c29b0cd45}"="C:\Program Files\WebEnhance\webenhance.xpi" []
==== Firefox Extensions ======================
ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\t1g6v5m1.default
- Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\IPSFF
- Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\coFFPlgn
- Microsoft .NET Framework Assistant - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
- FoxTab - %ProfilePath%\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi
ProfilePath: C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default
- Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
- Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\IPSFF
- Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\coFFPlgn
- bug489729Disable detach and tear off tab - %ProfilePath%\extensions\bug489729@alice0775
- Counterpixel - %ProfilePath%\extensions\counterpixel@jabubo.de
- Deutsches Wrterbuch - %ProfilePath%\extensions\de-DE@dictionaries.addons.mozilla.org
- Dictionary Switcher - %ProfilePath%\extensions\dictionary-switcher@design-noir.de
- British English Dictionary - %ProfilePath%\extensions\en-GB@dictionaries.addons.mozilla.org
- HTTPS-Everywhere - %ProfilePath%\extensions\https-everywhere@eff.org
- Flashblock - %ProfilePath%\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
- ChatZilla - %ProfilePath%\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
- CookieCuller - %ProfilePath%\extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}
- CookieSafe - %ProfilePath%\extensions\{9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}
- Ghostery - %ProfilePath%\extensions\firefox@ghostery.com.xpi
- OldFactory - %ProfilePath%\extensions\oldfactory@www.theme-oasis.org.xpi
- OldFactory Options - %ProfilePath%\extensions\oldfactory_options@www.theme-oasis.org.xpi
- Afmelden voor advertentiecookie - %ProfilePath%\extensions\optout@google.com.xpi
- PassIFox - %ProfilePath%\extensions\passifox@hanhuy.com.xpi
- TrackMeNot - %ProfilePath%\extensions\trackmenot@mrl.nyu.edu.xpi
- RefControl - %ProfilePath%\extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A}.xpi
- Ixquick Toolbar - %ProfilePath%\extensions\{70F241F6-52AB-4D45-993E-C1C09920095B}.xpi
- NoScript - %ProfilePath%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
- FireFTP - %ProfilePath%\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- BetterPrivacy - %ProfilePath%\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
- Greasemonkey - %ProfilePath%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
- FoxTab - %ProfilePath%\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi
AppDir: C:\Program Files\Mozilla Firefox
- Skype Click to Call - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\t1g6v5m1.default
4BF70B35B943BD73BD6E13EB7C1BA4B3 - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll - Shockwave Flash
04ACC61B47857E779CD92D1D88770BF1 - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
77B09C2C6F407531447DA75E3ACD1C5B - C:\Program Files\Adobe\Reader 10.0\Reader\browser\nppdf32.dll - Adobe Acrobat
260488E2BC07C276D1EDD54CCA086809 - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
179B446B36562BA025F38A5B0760DBEA - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U25
21D1C6D979A5B54A1F470074020D412D - C:\Program Files\CambridgeSoft\ChemOffice2012\ChemDraw\NPCDP32.DLL - ChemDraw
9381CD80303183C816A046B412521FE2 - C:\Program Files\CambridgeSoft\ChemOffice2012\Chem3D\npChem3DPlugin.dll - Bio3D
E42BD47C42B9A23B11F6B34A694D59D3 - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll - Foxit Reader Plugin for Mozilla
358878E398AB0FB8B1EE176C2E3EDF48 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll - Google Updater
AB87EEFFD18F2BAAFC274E7075EA6C67 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
==== Deleting Files \ Folders ======================
"C:\Users\7Schläfer\AppData\Roaming\Mozilla\Firefox\Profiles\rf8qbprm.default\extensions\firefox@ghostery.com.xpi" deleted
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
mkfokfffehpeedafpekjeddnmnjhmcmk - C:\Program Files\Norton Internet Security\Engine\19.9.1.14\Exts\Chrome.crx[12.09.2013 13:19]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.de/"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.de/"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
==== Reset Google Chrome ======================
Nothing found to reset
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\{38e9e285-5266-4fe2-b5b5-c14c29b0cd45} deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{38e9e285-5266-4fe2-b5b5-c14c29b0cd45} deleted successfully
==== Empty IE Cache ======================
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\7Schläfer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\7Schläfer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
No FireFox Cache found
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Admin\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
==== EOF on 17.10.2013 at 21:26:25,66 ======================
FRST lief ohne Probleme durch. Es lieferte FRST.txt:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013
Ran by Admin (administrator) on NOTEBOOK on 17-10-2013 21:35:29
Running from C:\Users\Admin\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Cisco Systems, Inc.) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
() C:\Program Files\GNU\GnuPG\dirmngr.exe
(Hauppauge Computer Works) C:\Program Files\WinTV\TVServer\HauppaugeTVServer.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
(Fujitsu Siemens Computers) C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
(Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(The Eraser Project) C:\Program Files\Eraser\Eraser.exe
() C:\Program Files\HP\HP UT\bin\hppusg.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(QFX Software Corporation) C:\Program Files\KeyScrambler\KeyScrambler.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
(Symantec Corporation) C:\Program Files\Norton Utilities 14\RMTray.exe
(Mirko Böer Softwareentwicklungen) C:\Program Files\MT\MT.exe
(The Privoxy team - www.privoxy.org) C:\Program Files\Privoxy\privoxy.exe
(Hauppauge Computer Works, Inc.) C:\Program Files\WinTV\WinTV7\WinTVTray.exe
(Microsoft Corporation) C:\Windows\system32\msiexec.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12005080 2013-08-28] (Realtek Semiconductor)
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [174872 2007-02-12] (Intel Corporation)
HKLM\...\Run: [BrStsMon00] - C:\Program Files\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM\...\Run: [Eraser] - C:\PROGRA~1\Eraser\Eraser.exe [980920 2012-05-22] (The Eraser Project)
HKLM\...\Run: [KeePass 2 PreLoad] - C:\Program Files\KeePass Password Safe 2\KeePass.exe [2010624 2013-07-20] (Dominik Reichl)
HKLM\...\Run: [IS CfgWiz] - C:\Program Files\HP\HP UT\bin\hppusg.exe [36864 2008-05-07] ()
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] - C:\Windows\KHALMNPR.EXE [76304 2008-02-29] (Logicool, Inc.)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [KeyScrambler] - C:\Program Files\KeyScrambler\keyscrambler.exe [508048 2013-07-14] (QFX Software Corporation)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKCU\...\Run: [NortonUtilities] - C:\Program Files\Norton Utilities 14\rmtray.exe [279912 2009-09-14] (Symantec Corporation)
HKCU\...\Run: [ISUSPM Startup] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [249856 2005-08-11] (Macrovision Corporation)
HKCU\...\Run: [Meine Traffic] - C:\PROGRA~1\MT\MT.EXE [1412096 2010-06-01] (Mirko Böer Softwareentwicklungen)
HKCU\...\Policies\system: [LogonHoursAction] 2
HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\7Schläfer\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [ 2008-02-23] (Google Inc.)
HKU\7Schläfer\...\Run: [ISUSPM Startup] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [ 2005-08-11] (Macrovision Corporation)
HKU\7Schläfer\...\Run: [TrueCrypt] - C:\Program Files\TrueCrypt\TrueCrypt.exe [ 2012-11-10] (TrueCrypt Foundation)
HKU\7Schläfer\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [ 2008-01-19] (Microsoft Corporation)
HKU\7Schläfer\...\Policies\system: [LogonHoursAction] 2
HKU\7Schläfer\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\Users\7Schläfer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
Startup: C:\Users\7Schläfer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\program\quickstart.exe ()
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll (Symantec Corporation)
Toolbar: HKCU -Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll (Symantec Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\t1g6v5m1.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @cambridgesoft.com/Chem3D,version=13.0 - C:\Program Files\CambridgeSoft\ChemOffice2012\Chem3D\npChem3DPlugin.dll (CambridgeSoft Corp.)
FF Plugin: @cambridgesoft.com/ChemDraw,version=13.0 - C:\Program Files\CambridgeSoft\ChemOffice2012\ChemDraw\npcdp32.dll (CambridgeSoft Corp.)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\t1g6v5m1.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\t1g6v5m1.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: No Name - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\t1g6v5m1.default\Extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\IPSFF
FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\coFFPlgn\
FF HKLM\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
========================== Services (Whitelisted) =================
S3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.)
R2 CVPND; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [1528608 2008-06-19] (Cisco Systems, Inc.)
R2 DirMngr; C:\Program Files\GNU\GnuPG\dirmngr.exe [224256 2011-03-02] ()
R2 HauppaugeTVServer; C:\Program Files\WinTV\TVServer\HauppaugeTVServer.exe [581632 2013-05-15] (Hauppauge Computer Works)
R2 NIS; C:\Program Files\Norton Internet Security\Engine\19.9.1.14\diMaster.dll [309688 2012-04-13] (Symantec Corporation)
S3 OpcEnum; C:\Windows\system32\OpcEnum.exe [98304 2005-11-25] (OPC Foundation)
R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 TestHandler; C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe [204800 2006-12-08] (Fujitsu Siemens Computers)
S3 VBMQANEGRY; C:\Users\Admin\AppData\Local\Temp\VBMQANEGRY.exe [x]
==================== Drivers (Whitelisted) ====================
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [278728 2008-08-09] ()
R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20131002.001\BHDrvx86.sys [1097304 2013-10-02] (Symantec Corporation)
S2 BrukerIR; C:\Windows\System32\Drivers\BrukerIR.sys [19384 2008-12-12] ()
R1 cbfs3; C:\Windows\system32\drivers\cbfs3.sys [299024 2012-04-09] (EldoS Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NIS\1309010.00E\ccSetx86.sys [132768 2012-06-07] (Symantec Corporation)
R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation)
S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
R2 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306299 2008-06-19] (Cisco Systems, Inc.)
R3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [125328 2008-03-29] (Deterministic Networks, Inc.)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376920 2013-10-05] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [108120 2013-08-27] (Symantec Corporation)
S3 ewsercd; C:\Windows\System32\DRIVERS\ewsercd.sys [100224 2010-03-18] (Huawei Technologies Co., Ltd.)
S3 hcw95bda; C:\Windows\System32\Drivers\hcw95bda.sys [573952 2013-04-22] (Hauppauge Computer Works, Inc.)
S3 hcw95rc; C:\Windows\System32\DRIVERS\hcw95rc.sys [16000 2013-04-22] (Hauppauge Computer Works, Inc.)
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\IPSDefs\20131014.001\IDSvix86.sys [392792 2013-10-08] (Symantec Corporation)
S4 JRAID; C:\Windows\system32\drivers\jraid.sys [48256 2007-06-13] (JMicron Technology Corp.)
S3 k750bus; C:\Windows\System32\DRIVERS\k750bus.sys [55216 2005-02-11] (MCCI)
S3 k750mdfl; C:\Windows\System32\DRIVERS\k750mdfl.sys [6576 2005-02-11] (MCCI)
S3 k750mdm; C:\Windows\System32\DRIVERS\k750mdm.sys [89872 2005-02-11] (MCCI)
S3 k750mgmt; C:\Windows\System32\DRIVERS\k750mgmt.sys [81728 2005-02-11] (MCCI)
S3 k750obex; C:\Windows\System32\DRIVERS\k750obex.sys [79488 2005-02-11] (MCCI)
R3 KeyScrambler; C:\Windows\System32\drivers\keyscrambler.sys [209016 2013-05-31] (QFX Software Corporation)
R3 LHidFilt; C:\Windows\System32\DRIVERS\LHidFilt.Sys [35472 2008-02-29] (Logicool, Inc.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25416 2008-08-09] ()
R3 LMouFilt; C:\Windows\System32\DRIVERS\LMouFilt.Sys [37008 2008-02-29] (Logicool, Inc.)
R3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [29072 2008-02-29] (Logicool, Inc.)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\VirusDefs\20131015.032\NAVENG.SYS [93272 2013-10-05] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\VirusDefs\20131015.032\NAVEX15.SYS [1612376 2013-10-05] (Symantec Corporation)
R3 NETwLv32; C:\Windows\System32\DRIVERS\NETwLv32.sys [6639616 2010-10-07] (Intel Corporation)
S3 Rockusb; C:\Windows\System32\DRIVERS\rockusb.sys [45040 2012-10-23] (Fuzhou Rockchip Electronics Co,Ltd.)
R0 sfsync04; C:\Windows\System32\drivers\sfsync04.sys [59520 2009-02-03] (Protection Technology (StarForce))
R0 sfvfs02; C:\Windows\System32\drivers\sfvfs02.sys [83320 2007-02-08] (Protection Technology (StarForce))
S3 SRTSP; C:\Windows\System32\Drivers\NIS\1309010.00E\SRTSP.SYS [574112 2012-07-06] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NIS\1309010.00E\SRTSPX.SYS [32928 2012-07-06] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NIS\1309010.00E\SYMDS.SYS [340088 2011-07-25] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NIS\1309010.00E\SYMEFA.SYS [924320 2012-05-22] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [141944 2012-03-27] (Symantec Corporation)
R1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [35960 2011-11-24] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NIS\1309010.00E\Ironx86.SYS [149624 2012-04-18] (Symantec Corporation)
R1 SYMTDIv; C:\Windows\System32\Drivers\NIS\1309010.00E\SYMTDIV.SYS [345208 2012-04-18] (Symantec Corporation)
S4 viamraid; C:\Windows\system32\drivers\viamraid.sys [102912 2006-11-08] (VIA Technologies inc,.ltd)
R2 WIBUKEY; C:\Windows\System32\DRIVERS\WibuKey.sys [72704 2009-02-26] (WIBU-SYSTEMS AG)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-19] (Microsoft Corporation)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
U2 wuaserv;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-17 21:26 - 2013-10-17 21:26 - 00000022 _____ C:\Windows\S.dirmngr
2013-10-17 19:27 - 2013-10-17 19:13 - 00024064 _____ C:\Windows\zoek-delete.exe
2013-10-17 19:22 - 2013-10-17 19:22 - 00659812 _____ C:\Users\Public\Desktop\sample__1922.zip
2013-10-17 19:15 - 2013-10-17 21:35 - 00013931 _____ C:\zoek-results.log
2013-10-17 19:12 - 2013-10-17 19:12 - 00000000 ____D C:\Users\Admin\Desktop\zoek
2013-10-17 15:22 - 2013-10-17 15:23 - 35289176 _____ (Dropbox, Inc.) C:\Users\7Schläfer\Downloads\Dropbox 2.4.2(1).exe
2013-10-16 19:55 - 2013-10-16 19:55 - 00000000 ____D C:\Windows\ERUNT
2013-10-16 19:45 - 2013-10-16 19:47 - 00000000 ____D C:\AdwCleaner
2013-10-16 19:38 - 2013-10-16 19:38 - 00023535 _____ C:\ComboFix.txt
2013-10-16 19:23 - 2013-10-16 19:38 - 00000000 ____D C:\ComboFix
2013-10-16 18:03 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-10-16 18:03 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-10-16 18:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-10-16 18:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-10-16 18:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-10-16 18:03 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-10-16 18:03 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-10-16 18:03 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-10-16 18:02 - 2013-10-16 19:38 - 00000000 ____D C:\Qoobox
2013-10-16 18:01 - 2013-10-16 19:10 - 00000000 ____D C:\Windows\erdnt
2013-10-16 17:54 - 2013-10-16 17:54 - 05133109 _____ (Swearware) C:\Users\7Schläfer\Downloads\ComboFix.exe
2013-10-16 17:40 - 2013-10-16 17:40 - 00386464 _____ (Bleeping Computer, LLC) C:\Users\7Schläfer\Downloads\show-hidden.exe
2013-10-16 17:08 - 2013-10-16 17:08 - 01048960 _____ C:\Users\Admin\Desktop\adwcleaner.exe
2013-10-16 17:08 - 2013-10-16 17:08 - 01033335 _____ (Thisisu) C:\Users\Admin\Desktop\JRT.exe
2013-10-16 17:05 - 2013-10-16 17:05 - 05133109 ____R (Swearware) C:\Users\Admin\Desktop\ComboFix.exe
2013-10-16 16:02 - 2013-10-16 16:02 - 00377856 _____ C:\Users\7Schläfer\Downloads\4xx537p0.exe
2013-10-16 15:00 - 2013-10-15 17:48 - 01087213 _____ (Farbar) C:\Users\Admin\Desktop\FRST.exe
2013-10-15 18:32 - 2013-10-15 18:32 - 00000000 ____D C:\FRST
2013-10-14 17:33 - 2013-10-14 17:33 - 00143632 _____ C:\Windows\Minidump\Mini101413-01.dmp
2013-10-12 11:32 - 2013-10-12 11:34 - 35289176 _____ (Dropbox, Inc.) C:\Users\7Schläfer\Downloads\Dropbox 2.4.2.exe
2013-10-12 02:18 - 2013-10-12 02:18 - 00001350 ____R C:\Windows\MeineTraffic_Uninstall.in
2013-10-12 02:18 - 2013-10-12 02:18 - 00000676 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meine Traffic.lnk
2013-10-12 02:18 - 2013-10-12 02:18 - 00000646 _____ C:\Users\Admin\Desktop\Meine Traffic.lnk
2013-10-12 02:18 - 2013-10-12 02:18 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meine Traffic
2013-10-12 02:18 - 2013-10-12 02:18 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Meine Traffic
2013-10-12 02:18 - 2013-10-12 02:18 - 00000000 ____D C:\Program Files\MT
2013-10-12 02:18 - 2010-06-01 14:30 - 00331136 _____ (Mirko Böer) C:\Windows\MTrUn.EXE
2013-10-12 02:17 - 2013-10-12 02:17 - 00000000 ____D C:\Users\7Schläfer\Downloads\mt(1)
2013-10-12 02:14 - 2013-10-12 02:14 - 00815948 _____ C:\Users\7Schläfer\Downloads\mt(1).zip
2013-10-12 01:22 - 2009-12-08 20:19 - 00113664 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbnet.sys
2013-10-12 01:22 - 2009-12-07 19:53 - 00103168 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys
2013-10-12 01:22 - 2009-10-12 15:22 - 00101120 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbdev.sys
2013-10-12 01:22 - 2007-08-09 04:06 - 00023424 _____ (Huawei Tech. Co., Ltd.) C:\Windows\system32\Drivers\ewdcsc.sys
2013-10-11 23:35 - 2013-10-11 23:35 - 00000182 _____ C:\Windows\WinTVInstall.LOG
2013-10-11 23:35 - 2013-10-11 23:35 - 00000000 ____D C:\Hauppauge
2013-10-11 23:35 - 2013-04-22 09:37 - 00573952 _____ (Hauppauge Computer Works, Inc.) C:\Windows\system32\Drivers\hcw95bda.sys
2013-10-11 23:35 - 2013-04-22 09:37 - 00016000 _____ (Hauppauge Computer Works, Inc.) C:\Windows\system32\Drivers\hcw95rc.sys
2013-10-11 22:14 - 2013-10-11 22:58 - 146116472 _____ C:\Users\7Schläfer\Downloads\WinTV7_CD_2.8a.exe
2013-10-11 17:34 - 2013-10-11 17:38 - 00000000 ____D C:\Windows\system32\MRT
2013-10-11 17:27 - 2013-09-22 12:29 - 12336128 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-11 17:27 - 2013-09-22 12:22 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-11 17:27 - 2013-09-22 12:22 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-11 17:27 - 2013-09-22 12:14 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-10-11 17:27 - 2013-09-22 12:13 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-11 17:27 - 2013-09-22 12:13 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-11 17:27 - 2013-09-22 12:12 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-10-11 17:27 - 2013-09-22 12:09 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-11 17:27 - 2013-09-22 12:08 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-10-11 17:27 - 2013-09-22 12:07 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-11 17:27 - 2013-09-22 12:06 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-10-11 17:27 - 2013-09-22 12:05 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-11 17:27 - 2013-09-22 12:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-11 17:27 - 2013-09-22 12:03 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-11 17:27 - 2013-09-22 12:03 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-10-11 17:27 - 2013-09-22 11:59 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-11 17:07 - 2013-08-27 04:47 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-10-11 17:07 - 2013-08-27 04:47 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-10-11 17:07 - 2013-08-27 04:47 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-10-11 17:07 - 2013-08-27 04:47 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-10-11 17:07 - 2013-08-27 03:52 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-10-11 17:07 - 2013-08-27 03:50 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-10-11 17:07 - 2013-08-27 03:32 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-10-11 17:07 - 2013-08-27 03:28 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-10-11 17:07 - 2013-08-27 03:28 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-10-11 17:07 - 2013-07-17 21:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-10-11 17:07 - 2013-05-02 06:04 - 00443904 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-10-11 17:07 - 2013-05-02 06:03 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\printcom.dll
2013-10-11 17:07 - 2013-03-08 05:52 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-10-11 17:07 - 2012-11-08 05:48 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2013-10-11 17:06 - 2013-08-29 09:36 - 02050048 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-11 17:06 - 2013-08-02 06:09 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-10-11 17:06 - 2013-08-01 05:16 - 00638400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-11 17:06 - 2013-08-01 04:49 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2013-10-11 17:06 - 2013-07-10 11:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-10-11 17:06 - 2013-07-09 14:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-11 17:06 - 2013-07-08 06:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-10-11 17:06 - 2013-07-08 06:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-11 17:06 - 2013-07-05 06:53 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-11 17:06 - 2013-07-04 06:21 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-11 17:06 - 2013-06-29 04:07 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-11 17:06 - 2013-06-29 04:07 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-11 17:06 - 2013-06-29 04:07 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-11 17:06 - 2013-06-29 04:06 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-11 17:06 - 2013-06-27 01:01 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-11 17:06 - 2013-06-15 15:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2013-10-11 17:06 - 2013-06-15 13:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-10-11 17:06 - 2013-04-24 06:00 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-10-11 17:06 - 2013-04-24 03:46 - 00812544 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-10-11 17:06 - 2013-04-17 14:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-10-11 17:06 - 2013-03-09 05:45 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-10-11 17:06 - 2013-03-09 03:28 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-10-11 17:06 - 2013-03-03 21:07 - 01082232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2013-10-11 17:06 - 2011-05-05 15:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-11 17:05 - 2013-07-20 12:44 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-11 17:05 - 2013-07-16 06:35 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2013-10-11 17:05 - 2013-07-12 11:04 - 00073344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys
2013-10-11 17:05 - 2013-07-03 04:10 - 00025472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-11 17:05 - 2013-06-04 06:16 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-11 17:05 - 2013-06-04 03:49 - 00293376 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-11 17:05 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-10-11 17:05 - 2013-03-08 05:53 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-10-11 17:05 - 2013-02-12 03:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2013-10-11 16:57 - 2013-07-08 06:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-10-11 16:57 - 2013-07-08 06:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-10-11 16:57 - 2013-07-08 06:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-10-11 16:57 - 2013-07-08 06:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-10-11 16:48 - 2013-10-11 16:48 - 01273160 _____ C:\Users\Admin\Downloads\KeyScrambler_Setup.exe
2013-10-11 16:29 - 2013-10-11 16:29 - 00143624 _____ C:\Windows\Minidump\Mini101113-01.dmp
2013-10-11 16:20 - 2009-02-26 11:05 - 00398336 _____ (Intel(R) Corporation) C:\Windows\system32\TVWizudlg.exe
2013-10-11 16:20 - 2009-02-26 11:04 - 00140288 _____ () C:\Windows\system32\igfxtvcx.dll
2013-10-11 16:02 - 2013-10-11 16:02 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2013-10-11 16:00 - 2008-02-29 11:12 - 00029072 _____ (Logicool, Inc.) C:\Windows\system32\Drivers\LUsbFilt.sys
2013-10-11 15:55 - 2013-10-11 16:20 - 00000000 ____D C:\Windows\system32\Lang
2013-10-11 15:12 - 2013-08-05 11:50 - 00053248 _____ (Windows XP Bundled build C-Centric Single User) C:\Windows\system32\CSVer.dll
2013-10-11 15:08 - 2013-10-11 15:08 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_LMouFilt_01005.Wdf
2013-10-11 15:08 - 2008-02-29 12:00 - 01419232 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01005.dll
2013-10-11 15:08 - 2008-02-29 11:12 - 00076304 _____ (Logicool, Inc.) C:\Windows\KHALMNPR.Exe
2013-10-11 15:08 - 2008-02-29 11:12 - 00037008 _____ (Logicool, Inc.) C:\Windows\system32\Drivers\LMouFilt.Sys
2013-10-11 15:08 - 2008-02-29 11:12 - 00035472 _____ (Logicool, Inc.) C:\Windows\system32\Drivers\LHidFilt.Sys
2013-10-11 15:07 - 2013-10-11 15:07 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2013-10-11 15:06 - 2013-10-11 15:06 - 00000000 ____D C:\Program Files\Realtek
2013-10-11 15:00 - 2013-10-11 15:00 - 00001736 _____ C:\Windows\DPINST.LOG
2013-10-11 14:51 - 2013-10-11 21:41 - 00000000 ____D C:\ProgramData\DriversGalaxy
2013-10-11 14:48 - 2013-10-11 14:48 - 00444400 _____ C:\Users\Admin\Downloads\DLG_free-driver-scout_chip_de-DE.exe
2013-10-11 14:44 - 2013-10-16 19:46 - 00000000 ____D C:\ProgramData\Uniblue
2013-10-11 14:42 - 2013-10-11 14:43 - 05712008 _____ (Uniblue Systems Ltd ) C:\Users\Admin\Downloads\driverscanner.exe
2013-10-11 13:59 - 2013-10-11 13:59 - 01528184 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\GenuineCheck.exe
2013-09-30 14:27 - 2013-10-11 19:03 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-09-30 14:26 - 2013-10-11 14:00 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-25 20:20 - 2013-09-25 20:20 - 00008288 _____ C:\Users\7Schläfer\.recently-used.xbel
2013-09-20 22:07 - 2013-09-20 22:07 - 00002552 _____ C:\{60A54E3E-9BF6-4BF4-954C-880ACD5E123E}
==================== One Month Modified Files and Folders =======
2013-10-17 21:35 - 2013-10-17 19:15 - 00013931 _____ C:\zoek-results.log
2013-10-17 21:29 - 2008-02-22 22:02 - 01228074 _____ C:\Windows\WindowsUpdate.log
2013-10-17 21:26 - 2013-10-17 21:26 - 00000022 _____ C:\Windows\S.dirmngr
2013-10-17 21:25 - 2012-07-30 11:05 - 00032802 _____ C:\Windows\PFRO.log
2013-10-17 21:25 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-17 21:25 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-17 21:25 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-17 21:24 - 2006-11-02 15:01 - 00032534 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-17 20:24 - 2012-06-15 15:13 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-17 19:24 - 2010-01-10 17:26 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-10-17 19:22 - 2013-10-17 19:22 - 00659812 _____ C:\Users\Public\Desktop\sample__1922.zip
2013-10-17 19:13 - 2013-10-17 19:27 - 00024064 _____ C:\Windows\zoek-delete.exe
2013-10-17 19:12 - 2013-10-17 19:12 - 00000000 ____D C:\Users\Admin\Desktop\zoek
2013-10-17 19:12 - 2008-06-15 14:35 - 00000000 ____D C:\Users\Admin\AppData\Roaming\ESTsoft
2013-10-17 19:06 - 2012-12-23 03:01 - 00000000 ____D C:\Users\7Schläfer\AppData\Roaming\KeePass
2013-10-17 17:37 - 2012-03-02 12:31 - 00000000 ____D C:\Users\7Schläfer\AppData\Roaming\Dropbox
2013-10-17 15:37 - 2013-08-20 02:19 - 00000000 ____D C:\Users\7Schläfer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-17 15:23 - 2013-10-17 15:22 - 35289176 _____ (Dropbox, Inc.) C:\Users\7Schläfer\Downloads\Dropbox 2.4.2(1).exe
2013-10-17 15:19 - 2011-08-21 18:20 - 00000000 ____D C:\Users\7Schläfer\AppData\Roaming\gnupg
2013-10-16 22:51 - 2006-11-02 12:33 - 01470534 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-16 19:55 - 2013-10-16 19:55 - 00000000 ____D C:\Windows\ERUNT
2013-10-16 19:47 - 2013-10-16 19:45 - 00000000 ____D C:\AdwCleaner
2013-10-16 19:46 - 2013-10-11 14:44 - 00000000 ____D C:\ProgramData\Uniblue
2013-10-16 19:46 - 2009-01-11 17:56 - 00000000 ____D C:\ProgramData\ICQ
2013-10-16 19:38 - 2013-10-16 19:38 - 00023535 _____ C:\ComboFix.txt
2013-10-16 19:38 - 2013-10-16 19:23 - 00000000 ____D C:\ComboFix
2013-10-16 19:38 - 2013-10-16 18:02 - 00000000 ____D C:\Qoobox
2013-10-16 19:35 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini
2013-10-16 19:13 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default
2013-10-16 19:13 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public
2013-10-16 19:10 - 2013-10-16 18:01 - 00000000 ____D C:\Windows\erdnt
2013-10-16 18:36 - 2006-11-02 12:22 - 48234496 _____ C:\Windows\system32\config\software.bak
2013-10-16 18:36 - 2006-11-02 12:22 - 43253760 _____ C:\Windows\system32\config\COMPON~3.bak
2013-10-16 18:36 - 2006-11-02 12:22 - 30408704 _____ C:\Windows\system32\config\system.bak
2013-10-16 18:36 - 2006-11-02 12:22 - 03932160 _____ C:\Windows\system32\config\default.bak
2013-10-16 18:36 - 2006-11-02 12:22 - 00262144 _____ C:\Windows\system32\config\security.bak
2013-10-16 18:36 - 2006-11-02 12:22 - 00090112 _____ C:\Windows\system32\config\sam.bak
2013-10-16 17:55 - 2012-12-23 03:08 - 00019006 _____ C:\Users\7Schläfer\Documents\NewDatabase.kdbx
2013-10-16 17:54 - 2013-10-16 17:54 - 05133109 _____ (Swearware) C:\Users\7Schläfer\Downloads\ComboFix.exe
2013-10-16 17:40 - 2013-10-16 17:40 - 00386464 _____ (Bleeping Computer, LLC) C:\Users\7Schläfer\Downloads\show-hidden.exe
2013-10-16 17:08 - 2013-10-16 17:08 - 01048960 _____ C:\Users\Admin\Desktop\adwcleaner.exe
2013-10-16 17:08 - 2013-10-16 17:08 - 01033335 _____ (Thisisu) C:\Users\Admin\Desktop\JRT.exe
2013-10-16 17:05 - 2013-10-16 17:05 - 05133109 ____R (Swearware) C:\Users\Admin\Desktop\ComboFix.exe
2013-10-16 16:02 - 2013-10-16 16:02 - 00377856 _____ C:\Users\7Schläfer\Downloads\4xx537p0.exe
2013-10-15 18:32 - 2013-10-15 18:32 - 00000000 ____D C:\FRST
2013-10-15 18:22 - 2010-04-24 12:20 - 00000000 ____D C:\Windows\pss
2013-10-15 17:48 - 2013-10-16 15:00 - 01087213 _____ (Farbar) C:\Users\Admin\Desktop\FRST.exe
2013-10-14 17:33 - 2013-10-14 17:33 - 00143632 _____ C:\Windows\Minidump\Mini101413-01.dmp
2013-10-14 17:33 - 2013-04-22 00:26 - 2137468297 _____ C:\Windows\MEMORY.DMP
2013-10-14 17:33 - 2009-10-22 21:39 - 00000000 ____D C:\Windows\Minidump
2013-10-13 12:16 - 2010-02-06 17:12 - 00001052 _____ C:\Windows\Tasks\Google Software Updater.job
2013-10-12 11:34 - 2013-10-12 11:32 - 35289176 _____ (Dropbox, Inc.) C:\Users\7Schläfer\Downloads\Dropbox 2.4.2.exe
2013-10-12 10:13 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-10-12 02:18 - 2013-10-12 02:18 - 00001350 ____R C:\Windows\MeineTraffic_Uninstall.in
2013-10-12 02:18 - 2013-10-12 02:18 - 00000676 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meine Traffic.lnk
2013-10-12 02:18 - 2013-10-12 02:18 - 00000646 _____ C:\Users\Admin\Desktop\Meine Traffic.lnk
2013-10-12 02:18 - 2013-10-12 02:18 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meine Traffic
2013-10-12 02:18 - 2013-10-12 02:18 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Meine Traffic
2013-10-12 02:18 - 2013-10-12 02:18 - 00000000 ____D C:\Program Files\MT
2013-10-12 02:17 - 2013-10-12 02:17 - 00000000 ____D C:\Users\7Schläfer\Downloads\mt(1)
2013-10-12 02:14 - 2013-10-12 02:14 - 00815948 _____ C:\Users\7Schläfer\Downloads\mt(1).zip
2013-10-12 01:22 - 2011-10-25 16:46 - 00000000 ____D C:\Program Files\Mobile Partner
2013-10-12 01:22 - 2008-02-23 00:12 - 00000000 ____D C:\Users\Admin
2013-10-11 23:49 - 2013-03-19 22:24 - 00000401 _____ C:\Windows\ODBCINST.INI
2013-10-11 23:49 - 2010-03-08 15:49 - 00001153 _____ C:\Windows\ODBC.INI
2013-10-11 23:47 - 2013-03-19 22:24 - 00037639 _____ C:\Windows\Irremote.ini
2013-10-11 23:47 - 2013-03-19 22:23 - 00000000 ____D C:\Users\Public\WinTV
2013-10-11 23:47 - 2013-03-19 22:23 - 00000000 ____D C:\Program Files\WinTV
2013-10-11 23:46 - 2013-03-19 22:23 - 00000000 ____D C:\ProgramData\Hauppauge
2013-10-11 23:46 - 2008-02-23 19:13 - 00000000 ____D C:\Program Files\InstallShield Installation Information
2013-10-11 23:41 - 2013-03-19 22:22 - 00007390 _____ C:\Windows\HCWPNP.INI
2013-10-11 23:40 - 2013-03-19 22:20 - 00094911 _____ C:\hcwDriverInstall.txt
2013-10-11 23:35 - 2013-10-11 23:35 - 00000182 _____ C:\Windows\WinTVInstall.LOG
2013-10-11 23:35 - 2013-10-11 23:35 - 00000000 ____D C:\Hauppauge
2013-10-11 23:35 - 2013-03-19 22:19 - 00000000 ____D C:\Users\Admin\AppData\Local\autorun
2013-10-11 22:58 - 2013-10-11 22:14 - 146116472 _____ C:\Users\7Schläfer\Downloads\WinTV7_CD_2.8a.exe
2013-10-11 22:22 - 2008-07-29 15:40 - 00000000 ___RD C:\Users\7Schläfer\Desktop\tools
2013-10-11 22:22 - 2008-06-22 20:08 - 00000664 _____ C:\Users\7Schläfer\Documents\grstyles.stl
2013-10-11 21:41 - 2013-10-11 14:51 - 00000000 ____D C:\ProgramData\DriversGalaxy
2013-10-11 21:41 - 2009-10-26 13:24 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-10-11 21:41 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\spool
2013-10-11 21:41 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\registration
2013-10-11 19:03 - 2013-09-30 14:27 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-10-11 18:26 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-10-11 18:08 - 2006-11-02 14:47 - 00431184 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-11 18:05 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer
2013-10-11 18:05 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal
2013-10-11 18:05 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-10-11 18:04 - 2013-05-28 20:20 - 00004922 _____ C:\Windows\setupact.log
2013-10-11 17:38 - 2013-10-11 17:34 - 00000000 ____D C:\Windows\system32\MRT
2013-10-11 16:48 - 2013-10-11 16:48 - 01273160 _____ C:\Users\Admin\Downloads\KeyScrambler_Setup.exe
2013-10-11 16:48 - 2009-11-18 18:05 - 00000000 ____D C:\Program Files\KeyScrambler
2013-10-11 16:29 - 2013-10-11 16:29 - 00143624 _____ C:\Windows\Minidump\Mini101113-01.dmp
2013-10-11 16:20 - 2013-10-11 15:55 - 00000000 ____D C:\Windows\system32\Lang
2013-10-11 16:20 - 2010-03-21 00:11 - 00000000 ____D C:\Program Files\Intel
2013-10-11 16:02 - 2013-10-11 16:02 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2013-10-11 15:11 - 2008-02-28 22:12 - 00000000 ____D C:\Intel
2013-10-11 15:08 - 2013-10-11 15:08 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_LMouFilt_01005.Wdf
2013-10-11 15:07 - 2013-10-11 15:07 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2013-10-11 15:06 - 2013-10-11 15:06 - 00000000 ____D C:\Program Files\Realtek
2013-10-11 15:06 - 2008-01-16 06:29 - 00000000 ____D C:\Windows\system32\RTCOM
2013-10-11 15:00 - 2013-10-11 15:00 - 00001736 _____ C:\Windows\DPINST.LOG
2013-10-11 14:48 - 2013-10-11 14:48 - 00444400 _____ C:\Users\Admin\Downloads\DLG_free-driver-scout_chip_de-DE.exe
2013-10-11 14:47 - 2010-03-20 17:48 - 00000000 ____D C:\Program Files\Uniblue
2013-10-11 14:43 - 2013-10-11 14:42 - 05712008 _____ (Uniblue Systems Ltd ) C:\Users\Admin\Downloads\driverscanner.exe
2013-10-11 14:00 - 2013-09-30 14:26 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-10-11 14:00 - 2010-04-08 15:45 - 00000000 ____D C:\Program Files\Norton Utilities 14
2013-10-11 14:00 - 2009-01-13 09:36 - 00000000 ____D C:\Users\7Schläfer\Desktop\communication
2013-10-11 13:59 - 2013-10-11 13:59 - 01528184 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\GenuineCheck.exe
2013-10-09 01:25 - 2012-04-04 12:43 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-09 01:25 - 2011-05-19 15:51 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-06 17:53 - 2010-04-08 14:07 - 00000000 ____D C:\Users\Public\Downloads\Norton
2013-10-06 17:53 - 2010-03-24 14:20 - 00000000 ____D C:\ProgramData\Norton
2013-10-01 17:51 - 2012-04-27 15:47 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-09-26 02:19 - 2006-11-02 12:24 - 78106760 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-09-26 01:18 - 2008-06-14 19:19 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Skype
2013-09-25 21:23 - 2011-03-02 15:52 - 00000000 ____D C:\Users\Admin\AppData\Local\CrashDumps
2013-09-25 20:30 - 2008-12-12 01:56 - 00000000 ___HD C:\Users\7Schläfer\.gimp-2.6
2013-09-25 20:20 - 2013-09-25 20:20 - 00008288 _____ C:\Users\7Schläfer\.recently-used.xbel
2013-09-25 20:20 - 2008-02-23 12:16 - 00000000 ____D C:\Users\7Schläfer
2013-09-25 14:47 - 2008-12-12 02:05 - 00000000 ____D C:\Users\7Schläfer\AppData\Roaming\gtk-2.0
2013-09-24 11:10 - 2012-10-31 13:07 - 00000000 ____D C:\Users\7Schläfer\AppData\Roaming\.purple
2013-09-22 12:29 - 2013-10-11 17:27 - 12336128 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-22 12:22 - 2013-10-11 17:27 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-22 12:22 - 2013-10-11 17:27 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-22 12:14 - 2013-10-11 17:27 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-09-22 12:13 - 2013-10-11 17:27 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-22 12:13 - 2013-10-11 17:27 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-22 12:12 - 2013-10-11 17:27 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-09-22 12:09 - 2013-10-11 17:27 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-22 12:08 - 2013-10-11 17:27 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-09-22 12:07 - 2013-10-11 17:27 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-22 12:06 - 2013-10-11 17:27 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-09-22 12:05 - 2013-10-11 17:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-22 12:03 - 2013-10-11 17:27 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-22 12:03 - 2013-10-11 17:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-22 12:03 - 2013-10-11 17:27 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-09-22 11:59 - 2013-10-11 17:27 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-21 20:50 - 2012-11-10 03:13 - 00000000 ____D C:\Users\7Schläfer\AppData\Local\Eraser 6
2013-09-20 22:07 - 2013-09-20 22:07 - 00002552 _____ C:\{60A54E3E-9BF6-4BF4-954C-880ACD5E123E}
2013-09-17 03:31 - 2010-03-26 16:05 - 00000000 ____D C:\Users\7Schläfer\AppData\Local\CrashDumps
Some content of TEMP:
====================
C:\Users\7Schläfer\AppData\Local\Temp\DataCard_Setup.exe
C:\Users\7Schläfer\AppData\Local\Temp\ResetDevice.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-17 21:32
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
... und addition.txt: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 03-10-2013
Ran by Admin at 2013-10-17 21:36:41
Running from C:\Users\Admin\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Norton Internet Security (Disabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Disabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security (Disabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
==================== Installed Programs ======================
32 Bit HP CIO Components Installer (Version: 2.1.4)
ACD/Labs Software in C:\Program Files\ACDFREE11\ (Version: v11.00, FREE)
Adobe Digital Editions
Adobe Flash Player 11 Plugin (Version: 11.9.900.117)
Adobe Flash Player 9 ActiveX (Version: 9)
Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8)
ALTools Update (Version: v11.4.28.1)
ALZip 8.51 (Version: v8.51)
Apple Software Update (Version: 2.1.1.116)
Battlecruiser Millennium FREEWARE (Version: 1.09.03)
Broken Sword 2.5
CambridgeSoft ChemBioDraw Ultra 13.0 (Version: 13.0)
CCleaner (Version: 2.30)
Celtx (2.7) (Version: 2.7 (de))
C-evo
Chinese Simplified Fonts Support For Adobe Reader 9 (Version: 9.0.0)
Cisco AnyConnect VPN Client (Version: 2.5.3055)
Cisco Systems VPN Client 5.0.03.0560 (Version: 5.0.3)
Citavi (Version: 3.2.0.0)
Civilization: Call To Power
Core Temp 1.0 RC4 (Version: 1.0)
CustomerResearchQFolder (Version: 1.00.0000)
DAVE 2.0 (Version: 2.0)
Dev-C++ 5 beta 9 release (4.9.9.2)
Diablo II
Diamond 3 (Version: 3.0.0)
DivX Version Checker (Version: 7.1.0.9)
DP Hash 1.0 (Version: 1.0)
DSL Connection Manager (Version: 1.1.1116)
ElsterFormular (Version: 14.3.11574)
enCIFer (Version: 1.4)
Eraser 6.0.10.2620 (Version: 6.0.2620)
FirstSteps Diagnostics (Version: 1.00)
Foxit Reader (Version: 5.4.3.920)
Free Audio CD Burner version 1.2
Free CD to MP3 Converter
Free Driver Scout (Version: 1.0.0.0)
Free YouTube to MP3 Converter version 3.11.26.706 (Version: 3.11.26.706)
FSCLounge (Version: 1.0.0)
GIMP 2.6.3
Google Earth (Version: 4.3.7284.3916)
Google Updater (Version: 2.4.2432.1652)
Gothic II
Gpg4win (2.1.0) (Version: 2.1.0)
GPL Ghostscript 8.62
GPL Ghostscript Fonts
GSview 4.9
Guitar Pro 3.0
Guitar Pro 5.2
Hauppauge WinTV 7 (Version: v7.0.31161 (CD 2.8a))
HijackThis 2.0.2 (Version: 2.0.2)
HL-2240 (Version: 1.0.6.0)
HP Customer Participation Program 10.0 (Version: 10.0)
HP LaserJet P2050 Series 2.0 (Version: 2.0)
HP Update (Version: 4.000.007.003)
hppFonts (Version: 001.001.00061)
hppManualsP2050 (Version: 000.002.00033)
hppPQVideoP2050 (Version: 000.002.00033)
hppQFolderP2050 (Version: 1.00.0000)
hppTLBXFXP2050 (Version: 000.105.00098)
hppusgP2050 (Version: 000.000.00006)
hpzTLBXFX (Version: 004.014.00150)
Inkscape 0.48.2 (Version: 0.48.2)
Intel(R) Graphics Media Accelerator Driver
Intel(R) Matrix Storage Manager
Intel(R) TV Wizard
Japanese Fonts Support For Adobe Reader 9 (Version: 9.0.0)
Java 7 Update 25 (Version: 7.0.250)
Java Auto Updater (Version: 2.1.9.5)
Java(TM) 6 Update 3 (Version: 1.6.0.30)
Java(TM) 6 Update 5 (Version: 1.6.0.50)
Java(TM) 6 Update 7 (Version: 1.6.0.70)
KeePass Password Safe 2.23
KeyScrambler (Version: 3.2.0.3)
Malwarebytes' Anti-Malware
MarketResearch (Version: 100.0.170.000)
Meine Traffic 2.20
MestReNova LITE 5.2.5-5780 (Version: 5.2.5-5780)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft PowerPoint Viewer (Version: 14.0.4763.1000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (Version: 9.0.21022.218)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (Version: 11.0.51106.1)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (Version: 11.0.51106)
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (Version: 11.0.51106)
Microsoft Works (Version: 9.7.0621)
MiKTeX 2.9 (Version: 2.9)
Miro (Version: 5.0.4)
Mobile Partner (Version: 16.001.06.03.52)
Motorola SM56 Speakerphone Modem (Version: 6.12.25.06)
Mozilla Firefox 24.0 (x86 de) (Version: 24.0)
Mozilla Maintenance Service (Version: 24.0)
Mozilla Thunderbird 24.0 (x86 de) (Version: 24.0)
MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MTX (Version: 1.0.0)
Nero 7 Essentials (Version: 7.02.5851)
Norton Bootable Recovery Tool Wizard (Version: 3.0.0.66)
Norton Internet Security (Version: 19.9.1.14)
Norton Utilities (Version: 14.5)
NVIDIA WDM Drivers
OPC Core Components 2.00 Redistributable (Version: 2.00.230)
OpenAL
OpenOffice.org 3.4.1 (Version: 3.41.9593)
OPUS_65 (Version: 6.5.97)
Ortep for Windows v2.02 (Version: 2.02)
PDF24 Creator 5.2.0
PDFCreator (Version: 0.9.5)
PDF-Viewer (Version: 2.0.41.5)
PDF-XChange Shell Extentions (Version: 2.0.41.5)
Pidgin (Version: 2.10.6)
pidgin-otr 4.0.0-1 (Version: 4.0.0-1)
POV-Ray for Windows v3.6.1c (Version: 3.6)
POV-Ray for Windows v3.62 (Version: 3.62)
Prince of Persia T2T
Privateer
Privoxy (remove only)
QuickTime (Version: 7.71.80.42)
Realtek High Definition Audio Driver (Version: 6.0.1.7026)
Reversion - The escape (HKCU Version: 1.03)
Sacred
SciFinder Scholar 2007
SciFinder Scholar Toolbar
Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002) (Version: 1.0.0)
Sid Meier's Civilization IV Colonization (Version: 1.01)
Simple Sudoku 4.2
Skype Click to Call (Version: 5.9.9216)
Skype™ 6.6 (Version: 6.6.106)
Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0)
SpinWorks_3 (Version: 3.1.6)
Spybot - Search & Destroy (Version: 1.6.2)
TeXnicCenter Version 1 Beta 7.50 (Version: Version 1 Beta 7.50)
TrekStor eReaderSuite
TrueCrypt (Version: 7.1a)
UFO:AI 2.4 (Version: 2.4)
Uniblue ProcessScanner
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3)
Update Manager (Version: 4.60)
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0)
Visual C++ 2008 x86 Runtime - (v9.0.30729) (Version: 9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01 (Version: 9.0.30729.01)
VLC media player 2.0.8 (Version: 2.0.8)
WebEnhance
WebReg (Version: 100.0.170.000)
WIBU-KEY Setup (WIBU-KEY Remove) (Version: Version 5.20a of 2006-Dec-01 (Setup))
Widelands Build14 (Version: Widelands Build14)
Windows Media Player Firefox Plugin (Version: 1.0.0.8)
Wuala CBFS (Version: 3.2.107.0)
Xvid 1.1.3 final uninstall (Version: 1.1)
YaCy
Zak McKracken - Between Time and Space
==================== Restore Points =========================
11-10-2013 11:58:53 Made by Norton Utilities
11-10-2013 12:49:15 Free Driver Scout
11-10-2013 12:59:26 DriverUtilities
11-10-2013 13:06:16 Gerätetreiber-Paketinstallation: Realtek Semiconductor Corp. Audio-, Video- und Gamecontroller
11-10-2013 13:08:04 Gerätetreiber-Paketinstallation: Logicool Mäuse und andere Zeigegeräte
11-10-2013 13:08:54 Gerätetreiber-Paketinstallation: Realtek Netzwerkadapter
11-10-2013 13:12:06 Gerätetreiber-Paketinstallation: Intel Systemgeräte
11-10-2013 13:12:59 Gerätetreiber-Paketinstallation: Intel Systemgeräte
11-10-2013 13:14:17 Gerätetreiber-Paketinstallation: Intel IDE ATA/ATAPI-Controller
11-10-2013 13:15:39 Gerätetreiber-Paketinstallation: Intel USB-Controller
11-10-2013 13:16:48 Gerätetreiber-Paketinstallation: Intel Systemgeräte
11-10-2013 13:17:57 Gerätetreiber-Paketinstallation: Intel Systemgeräte
11-10-2013 13:19:06 Gerätetreiber-Paketinstallation: Intel IDE ATA/ATAPI-Controller
11-10-2013 13:21:21 Gerätetreiber-Paketinstallation: Intel Systemgeräte
11-10-2013 13:21:30 Gerätetreiber-Paketinstallation: Intel IDE ATA/ATAPI-Controller
11-10-2013 13:24:31 Gerätetreiber-Paketinstallation: Intel Systemgeräte
11-10-2013 13:25:03 Gerätetreiber-Paketinstallation: Intel IDE ATA/ATAPI-Controller
11-10-2013 13:25:28 Gerätetreiber-Paketinstallation: Intel IDE ATA/ATAPI-Controller
11-10-2013 13:28:11 Gerätetreiber-Paketinstallation: Intel IDE ATA/ATAPI-Controller
11-10-2013 13:30:02 Gerätetreiber-Paketinstallation: Intel IDE ATA/ATAPI-Controller
11-10-2013 13:31:57 Gerätetreiber-Paketinstallation: Intel USB-Controller
11-10-2013 13:34:43 Gerätetreiber-Paketinstallation: Intel Systemgeräte
11-10-2013 13:37:38 Gerätetreiber-Paketinstallation: Intel Systemgeräte
11-10-2013 13:44:54 Gerätetreiber-Paketinstallation: Intel Systemgeräte
11-10-2013 13:45:27 Gerätetreiber-Paketinstallation: Intel IDE ATA/ATAPI-Controller
11-10-2013 13:46:41 Gerätetreiber-Paketinstallation: Intel Systemgeräte
11-10-2013 13:51:50 Gerätetreiber-Paketinstallation: Intel IDE ATA/ATAPI-Controller
11-10-2013 13:54:28 Gerätetreiber-Paketinstallation: Intel Corporation Grafikkarte
11-10-2013 13:59:04 Gerätetreiber-Paketinstallation: Intel Netzwerkadapter
11-10-2013 14:00:17 Gerätetreiber-Paketinstallation: Logicool Eingabegeräte (Human Interface Devices)
11-10-2013 15:07:54 Windows Update
11-10-2013 18:30:08 Gerätetreiber-Paketinstallation: HUAWEI Incorporated Modems
11-10-2013 18:32:22 Gerätetreiber-Paketinstallation: HUAWEI Incorporated Netzwerkadapter
11-10-2013 18:33:10 Gerätetreiber-Paketinstallation: HUAWEI Incorporated Anschlüsse (COM & LPT)
11-10-2013 18:34:36 Gerätetreiber-Paketinstallation: HUAWEI Incorporated Anschlüsse (COM & LPT)
11-10-2013 19:35:05 Wiederherstellungsvorgang
11-10-2013 21:36:48 Gerätetreiber-Paketinstallation: Hauppauge Computer Works, Inc. Audio-, Video- und Gamecontroller
11-10-2013 21:47:44 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106
12-10-2013 15:16:35 Geplanter Prüfpunkt
16-10-2013 17:23:46 ComboFix created restore point
17-10-2013 17:15:21 zoek.exe restore point
==================== Hosts content: ==========================
2012-08-26 21:02 - 2013-10-16 19:00 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {02B3DBBA-9F10-4864-A660-362B08A93FD9} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: {10271444-A593-459F-A03C-E9E893CF09E5} - System32\Tasks\Google Software Updater => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-09-07] (Google)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {2FD1DAC8-294E-4054-8701-71CC0753330B} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2008-01-19] (Microsoft Corporation)
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation)
Task: {8FCBDDAF-3D95-4F9D-A26A-2834F113D02A} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton Internet Security\Engine\19.9.1.14\WSCStub.exe [2013-02-02] (Symantec Corporation)
Task: {A6FD3EB8-15E6-4144-8507-8BD5F0CE760F} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files\Norton Internet Security\Engine\19.9.1.14\SymErr.exe [2012-02-04] (Symantec Corporation)
Task: {DCED19B2-0F58-414D-9A9B-972D92154426} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files\Norton Internet Security\Engine\19.9.1.14\SymErr.exe [2012-02-04] (Symantec Corporation)
Task: {E17AE139-FFFB-40C7-BF5C-49DBEF6A9F97} - System32\Tasks\RunAsStdUser_jugg_client_en => C:\Program Files\JuggernautEn\JuggernautClientEn.exe
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] ()
Task: {FAD97B25-7F13-441D-AECA-79BC7D6CEBF6} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
==================== Loaded Modules (whitelisted) =============
2008-05-07 10:38 - 2008-05-07 10:38 - 00057344 _____ () C:\Program Files\HP\HP UT\bin\HPUsageTracking.dll
2008-05-07 10:38 - 2008-05-07 10:38 - 00069632 _____ () C:\Program Files\HP\HP UT\bin\HPTools.dll
2008-05-07 10:38 - 2008-05-07 10:38 - 00114688 _____ () C:\Program Files\HP\HP UT\bin\HPToolkit.dll
2008-05-07 10:38 - 2008-05-07 10:38 - 00040960 _____ () C:\Program Files\HP\HP UT\bin\Enumeration.dll
2010-11-14 14:25 - 2010-11-14 14:25 - 00086528 _____ () C:\Program Files\Privoxy\mgwz.dll
2013-03-19 22:23 - 2013-05-15 13:15 - 00025600 _____ () C:\Program Files\WinTV\TVServer\HauppaugeTVServerps.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\TEMP:8AB6C1D7
AlternateDataStreams: C:\ProgramData\TEMP:C8B8CEBD
AlternateDataStreams: C:\ProgramData\TEMP:D287FACF
AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Cisco Systems VPN Adapter
Description: Cisco Systems VPN Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: CVirtA
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: Cisco AnyConnect VPN Virtual Miniport Adapter for Windows
Description: Cisco AnyConnect VPN Virtual Miniport Adapter for Windows
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (10/17/2013 09:27:21 PM) (Source: MsiInstaller) (User: notebook)
Description: Product: Update Manager -- Error 1706.No valid source could be found for product Update Manager. The Windows Installer cannot continue.
Error: (10/17/2013 07:24:46 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\ADMIN\DOCUMENTS\FREEMIUM DRIVER UTILITIES\DOWNLOADS> in der Hash-Zuordnung kann nicht aktualisiert werden.
Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
Error: (10/17/2013 07:08:16 PM) (Source: MsiInstaller) (User: notebook)
Description: Product: Update Manager -- Error 1706.No valid source could be found for product Update Manager. The Windows Installer cannot continue.
Error: (10/17/2013 00:00:07 AM) (Source: Windows Backup) (User: )
Description: Die Dateisicherung ist aufgrund eines Fehlers beim Schreiben in das Sicherungsziel J:\ fehlgeschlagen. Fehler: Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006)
System errors:
=============
Error: (10/17/2013 09:26:20 PM) (Source: Service Control Manager) (User: )
Description: cdrom
Error: (10/17/2013 09:26:15 PM) (Source: Service Control Manager) (User: )
Description: Bruker FTIR Driver%%87
Error: (10/17/2013 07:24:05 PM) (Source: Service Control Manager) (User: )
Description: PEVSystemStart
Error: (10/17/2013 07:24:00 PM) (Source: Service Control Manager) (User: )
Description: PEVSystemStart
Error: (10/17/2013 07:23:59 PM) (Source: Service Control Manager) (User: )
Description: PEVSystemStart
Error: (10/17/2013 07:23:58 PM) (Source: Service Control Manager) (User: )
Description: PEVSystemStart
Error: (10/17/2013 07:23:57 PM) (Source: Service Control Manager) (User: )
Description: PEVSystemStart
Error: (10/17/2013 03:15:32 PM) (Source: Service Control Manager) (User: )
Description: cdrom
Error: (10/17/2013 03:15:31 PM) (Source: Service Control Manager) (User: )
Description: Bruker FTIR Driver%%87
Error: (10/17/2013 03:15:29 PM) (Source: Dhcp) (User: )
Description: Die IP-Adresslease 192.168.0.101 für die Netzwerkkarte mit der Netzwerkadresse 001B77E0FB33 wurde durch den DHCP-Server 192.168.0.1 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet).
Microsoft Office Sessions:
=========================
Error: (10/17/2013 09:27:21 PM) (Source: MsiInstaller)(User: notebook)
Description: Product: Update Manager -- Error 1706.No valid source could be found for product Update Manager. The Windows Installer cannot continue.(NULL)(NULL)(NULL)(NULL)
Error: (10/17/2013 07:24:46 PM) (Source: Windows Search Service)(User: )
Description: Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
C:\USERS\ADMIN\DOCUMENTS\FREEMIUM DRIVER UTILITIES\DOWNLOADS
Error: (10/17/2013 07:08:16 PM) (Source: MsiInstaller)(User: notebook)
Description: Product: Update Manager -- Error 1706.No valid source could be found for product Update Manager. The Windows Installer cannot continue.(NULL)(NULL)(NULL)(NULL)
Error: (10/17/2013 00:00:07 AM) (Source: Windows Backup)(User: )
Description: J:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006)
CodeIntegrity Errors:
===================================
Date: 2013-10-16 19:27:36.224
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-16 19:27:35.990
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-16 19:27:35.756
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-16 19:27:35.537
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-16 19:26:11.001
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-16 19:26:10.767
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-16 19:26:10.548
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-16 19:26:10.314
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-16 19:25:58.942
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20131002.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-16 19:25:58.724
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20131002.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 54%
Total physical RAM: 2037.7 MB
Available physical RAM: 935.5 MB
Total Pagefile: 4316.45 MB
Available Pagefile: 3154.48 MB
Total Virtual: 2047.88 MB
Available Virtual: 1918.42 MB
==================== Drives ================================
Drive c: (SYSTEM) (Fixed) (Total:148.1 GB) (Free:20.32 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:73.07 GB) (Free:32.26 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: DDF755B2)
Partition 1: (Not Active) - (Size=12 GB) - (Type=27)
Partition 2: (Active) - (Size=148 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=73 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Rechner läuft soweit stabil (und gefühlt schneller, als zuvor). Eine Admin-Authorisierung eines Zugriffs von Softwareupdater.UI.exe wird nach Start nicht mehr verlangt (das war schon nach dem ersten Combofix so). Einen Viren-Scan mit meinem Norton hab ich nach der Prozedur noch nicht gemacht, soll ich?
Firefox ist um einige Add-ons ärmer (was ja wahrscheinlich so gedacht war), z.B. hat's Ghostery abgeschossen. Gibt es dafür einen Grund? Startseite ist wieder google, was wieder gändert wird. RefControl wurde von <Ersetzen> auf <Normal> geändert usw. Zwischenzeitlich war die Lesezeichen-Leiste bei Start des FF immer weg, egal, ob sie das Häckchen bei Einstellungen hatte oder nicht. Jetzt funktioniert das aber wieder. Etwas seltsam ist, dass FF bei jedem Start das Master-Passwort haben will, selbst wenn nirgends eine PW-Abfrage möglich ist. Das würde ich gerne noch fixen.
P.S.:
Habe auf dem Desktop des normalen Nutzerprofiles jetzt eine Datei "sample__1922.zip" mit dem Inhalt Ordner "sample" und darin die zwei Dateien "B751E6F7103F28A6CA9FEA4082C514C1" und "sample-content.html". Soll das so? |