Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Sophosmeldung: Troj/ZbotMem-B im Memory

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 02.07.2013, 16:29   #1
Piristibulus
 
Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Hallo und guten Abend,

ich hoffe, dass Ihr mir helfen könnt.

Ich habe heute bemerkt, dass die Funktionen der AltGr und der Strg Taste vertauscht zu sein schienen. Auch wurden bestimmte Akzentzeichen (´, ^, etc.) doppelt ausgegeben, obwohl ich die Taste nur einmal, und zwar nicht in Kombination mit einer anderen Taste gedrückt hatte).

Allerdings fiel mir auch auf, dass dieses Problem nicht immer in allen Programmen auftritt. (Ich verwende viele Tastaturoptionen und wechsle oft zwischen Sprachen hin und her.) So war "sticky notes" gar nicht, firefox zum Teil, IE, thunderbird und word non-stop davon betroffen.

Eine Recherche erbrachte unter anderem, dass möglicherweise ein Trojaner/Virenbefall vorliegt.

Ein Scan mit Sophos führte dann zur Meldung "Troj/ZBotMem-B has been detected in "UserMemory"". Entfernen sei nur manuell möglich.

Eine weitere Suche hat dann auf diese Seite geführt.

Ich hatte auch begonnen, die in der ersten Anleitung angewiesenen ersten drei Scans durchzuführen und defogger auf den Desktop heruntergeladen.

Ich habe es (da Win 7) als administrator ausgeführt und wie angewiesen die Emulatoren deaktiviert. Allerdings kehrt das Programm nach dem Ende des Scans (ca. 0.5-1 sec Dauer) sofort wieder zum ersten Menü zurück und fragt nach, ob ich "disable" oder "re-enable" ausführen möchte.
Im Eifer des Gefechts hab ich dann daneben geklickt als ich die Webseite nochmal anzeigen wollte und noch einmal "disable" gedrückt. Danach erschien wieder ok und dann das erste Menü (disable/re-enable).

Ein Log wird beide male nicht angezeigt, allerdings war mir so, als sei kurz ein Fenster erschienen (nicht mal 1 sec lang), das denen sehr ähnelt, die beim Aufrufen von cmd erscheinen.

Daher traue ich mich nicht die weiteren Schritte auszuführen.

Ich wäre sehr dankbar, wenn mir hier weiter geholfen werden könnte.

Vielen Dank und beste Grüße,

piristibulus

Alt 02.07.2013, 16:30   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Hi,

Systemscan mit FRST
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Scan.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)
__________________

__________________

Alt 02.07.2013, 16:58   #3
Piristibulus
 
Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Lieber Schrauber,

vielen Dank für die schnelle Hilfe.

Hier die logs:

1) FRST.txt:

Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-07-2013
Ran by Daniel (administrator) on 02-07-2013 17:48:52
Running from C:\Users\Daniel\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Sony Corporation) c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
(Samsung Electronics Co., Ltd.) C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(VoipBuster) C:\Program Files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe
(The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Daniel\AppData\Roaming\Waeged\ihurp.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Dropbox, Inc.) C:\Users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apntex.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SmarThru Office\BackUpSvr.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SmarThru Office\x64\LegacyLauncher.exe
(ALPS) C:\Program Files\Apoint\Apvfb.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update 5\VUAgent.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\Admload.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavMain.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [518784 2011-03-29] (Conexant Systems, Inc.)
HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [790688 2011-04-29] (Atheros Commnucations)
HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [657568 2011-04-29] (Atheros Commnucations)
HKLM\...\Run: [Apoint] %ProgramFiles%\Apoint\Apoint.exe [226672 2011-02-17] (Alps Electric Co., Ltd.)
HKLM\...\Run: [CDAServer] C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [438784 2010-12-17] ()
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-03-27] (Google Inc.)
HKCU\...\Run: [Google Update] "C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-03-28] (Google Inc.)
HKCU\...\Run: [HP Photosmart 5510 series (NET)] "C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN175050KX05NR:NW" -scfn "HP Photosmart 5510 series (NET)" -AutoStart 1 [2676584 2011-09-16] (Hewlett-Packard Co.)
HKCU\...\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1475584 2010-11-21] (Microsoft Corporation)
HKCU\...\Run: [VoipBuster] "C:\Program Files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe" -nosplash -minimized [19378496 2013-06-25] (VoipBuster)
HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18705664 2013-01-08] (Skype Technologies S.A.)
HKCU\...\Run: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean [3713032 2012-11-13] (Safer-Networking Ltd.)
HKCU\...\Run: [Cilehaze] C:\Users\Daniel\AppData\Roaming\Waeged\ihurp.exe [228864 2012-08-31] (The OpenSSL Project, hxxp://www.openssl.org/)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [2757312 2011-02-15] (Sony Corporation)
HKLM-x32\...\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)
HKLM-x32\...\Run: []  [x]
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard)
HKLM-x32\...\Run: [STO Backup Service] C:\Program Files (x86)\SmarThru Office\BackUpSvr.exe [199760 2012-01-13] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [STO Launcher Service] C:\Program Files (x86)\SmarThru Office\x64\LegacyLauncher.exe /autorun [405584 2012-01-13] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [929272 2013-04-03] (Sophos Limited)
HKLM-x32\...\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~2\SOPHOS~2.DLL [218256 2013-04-03] (Sophos Limited)
AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~2\SOPHOS~1.DLL [221840 2013-04-03] (Sophos Limited)
Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.wikipedia.org/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://vaioportal.sony.eu
SearchScopes: HKLM-x32 - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://start.funmoods.com/results.php?f=4&q={searchTerms}&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1Qzu0D0E0A0FyBzz0ByD0C0FyCzyyByC0AzytN0D0Tzu0CtBtCyCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=765507789
SearchScopes: HKCU - {623BD34C-6486-4770-B994-92555203C850} URL = hxxp://rover.ebay.com/rover/1/710-42480-16445-33/4?mpre=hxxp://shop.ebay.co.uk/?oemInLn=ieSrch-Q311&_nkw={searchTerms}
SearchScopes: HKCU - {8C1B1A63-658F-4F07-BDC0-B7765C458695} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Freecorder 6 - {6B34ACCF-1B63-4E1A-8633-461917C75544} - C:\Program Files (x86)\Freecorder 6\tbcore3.dll ()
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {6B34ACCF-1B63-4E1A-8633-461917C75544} -  No File
DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 20 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 20 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{F6BFC1EA-082D-4450-A95B-BF5334CE4940}: [NameServer]141.2.22.74,141.2.149.10

FireFox:
========
FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default
FF user.js: detected! => C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\user.js
FF NewTab: www.bl.uk
FF SearchEngine: Google
FF Homepage: hxxp://www.bl.uk/
FF Keyword.URL: hxxp://www.google.com/search?q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Extension: Visualisateur 3D de 20-20 - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\2020Player_IKEA@2020Technologies.com
FF Extension: Deutsches W?rterbuch - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\de-DE@dictionaries.addons.mozilla.org
FF Extension: Freecorder 6 - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{132E58DE-22BF-44CA-A061-7FCE1E8BA1EC}
FF Extension: browserprotect - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\browserprotect@browserprotect.com.xpi
FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.xpi
FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{e8f509f0-b677-11de-8a39-0800200c9a66}.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: SmartPrintButton - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: <?xml version="1.0"?>

<RDF xmlns="hxxp://www.w3.org/1999/02/22-rdf-syntax-ns#"
     xmlns:em="hxxp://www.mozilla.org/2004/em-rdf#">
  <Description about="urn:mozilla:install-manifest">
    <em:id>smartwebprinting@hp.com</em:id>
    <em:version>4.60</em:version>

    <em:targetApplication>
      <!-- Firefox -->
      <Description>
        <em:id>{ec8030f7-c20a-464f-9b0e-13a3a9e97384}</em:id>
        <em:minVersion>3.5.0.0</em:minVersion>
        <em:maxVersion>3.5.*.*</em:maxVersion>
      </Description>
    </em:targetApplication>

    <!-- front-end metadata -->
    <em:name>HP Smart Web Printing</em:name>
    <em:description>Print what you want, how you want.</em:description>
    <em:creator>hp.com</em:creator>
    <em:homepageURL>hxxp://www.hp.com/go/smartwebprinting</em:homepageURL>
    
    <em:aboutURL>chrome://hpsmartwebprinting/content/about.xul</em:aboutURL>
    <em:iconURL>chrome://hpsmartwebprinting/skin/toolbar-icon-normal-24.png</em:iconURL>
    <em:targetPlatform>WINNT_x86-msvc</em:targetPlatform>
  </Description>
</RDF>
 - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: <?xml version="1.0"?>

<RDF xmlns="hxxp://www.w3.org/1999/02/22-rdf-syntax-ns#"
     xmlns:em="hxxp://www.mozilla.org/2004/em-rdf#">
  <Description about="urn:mozilla:install-manifest">
    <em:id>smartwebprinting@hp.com</em:id>
    <em:version>4.60</em:version>

    <em:targetApplication>
      <!-- Firefox -->
      <Description>
        <em:id>{ec8030f7-c20a-464f-9b0e-13a3a9e97384}</em:id>
        <em:minVersion>3.5.0.0</em:minVersion>
        <em:maxVersion>3.5.*.*</em:maxVersion>
      </Description>
    </em:targetApplication>

    <!-- front-end metadata -->
    <em:name>HP Smart Web Printing</em:name>
    <em:description>Print what you want, how you want.</em:description>
    <em:creator>hp.com</em:creator>
    <em:homepageURL>hxxp://www.hp.com/go/smartwebprinting</em:homepageURL>
    
    <em:aboutURL>chrome://hpsmartwebprinting/content/about.xul</em:aboutURL>
    <em:iconURL>chrome://hpsmartwebprinting/skin/toolbar-icon-normal-24.png</em:iconURL>
    <em:targetPlatform>WINNT_x86-msvc</em:targetPlatform>
  </Description>
</RDF>
 - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

==================== Services (Whitelisted) =================

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-04-29] (Atheros)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation)
R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe [231936 2012-03-22] (Samsung Electronics Co., Ltd.)
R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [217592 2013-04-03] (Sophos Limited)
R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [159296 2013-04-03] (Sophos Limited)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [237048 2013-04-03] (Sophos Limited)
R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [357400 2013-04-03] (Sophos Limited)
R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2890232 2013-04-03] (Sophos Limited)
S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2010688 2013-04-03] (Sophos Limited)
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.)
R3 VUAgent; C:\Program Files\Sony\VAIO Update 5\VUAgent.exe [1021112 2011-03-30] (Sony Corporation)

==================== Drivers (Whitelisted) ====================

R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [154952 2013-04-03] (Sophos Limited)
S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [36640 2013-04-03] (Sophos Limited)
S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [25608 2013-04-03] (Sophos Plc)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-02 17:48 - 2013-07-02 17:48 - 00000000 ____D C:\FRST
2013-07-02 17:44 - 2013-07-02 17:44 - 01933556 ____A (Farbar) C:\Users\Daniel\Desktop\FRST64.exe
2013-07-02 17:06 - 2013-07-02 17:07 - 00000474 ____A C:\Users\Daniel\Desktop\defogger_disable.log
2013-07-02 17:06 - 2013-07-02 17:06 - 00000000 ____A C:\Users\Daniel\defogger_reenable
2013-07-02 17:04 - 2013-07-02 17:04 - 00050477 ____A C:\Users\Daniel\Desktop\Defogger.exe
2013-07-02 16:04 - 2013-07-02 16:04 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-07-02 16:02 - 2013-07-02 16:03 - 04396440 ____A (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup403.exe
2013-07-01 15:40 - 2013-07-01 15:47 - 00001434 ____A C:\Users\Daniel\Downloads\Antrag auf Ausstellung einer Bescheinigung für den Lohnsteuerabzug 2013.xml
2013-07-01 13:13 - 2013-07-01 21:43 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Vyde
2013-07-01 13:13 - 2013-07-01 13:13 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Waeged
2013-07-01 13:13 - 2013-07-01 13:13 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Qiebu
2013-06-26 14:28 - 2013-06-26 16:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-06-25 14:34 - 2013-06-25 14:34 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk
2013-06-21 11:47 - 2013-06-21 11:47 - 00150406 ____A C:\Users\Daniel\Documents\1662.ppsx
2013-06-19 08:08 - 2013-06-12 21:47 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-19 08:08 - 2013-06-12 21:43 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-19 08:08 - 2013-06-12 21:43 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-19 08:07 - 2013-06-19 08:08 - 00004802 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log
2013-06-19 08:07 - 2013-06-12 21:43 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-17 23:38 - 2013-06-17 23:42 - 00084339 ____A C:\Users\Daniel\Desktop\Briefvorlage-Birnstiel.dotx
2013-06-16 12:36 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-16 12:36 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-16 12:36 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-16 12:36 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-16 12:36 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-16 12:36 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-16 12:36 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-16 12:36 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-16 12:36 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-16 12:36 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-16 12:36 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-16 12:36 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-14 10:17 - 2013-06-20 15:13 - 00016101 ____A C:\Users\Daniel\Documents\Korrespondenztabelle.xlsx
2013-06-12 17:54 - 2013-06-20 10:32 - 00011854 ____A C:\Users\Daniel\Desktop\PruefungstermineSoSe2013.xlsx
2013-06-12 09:49 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-12 09:49 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 09:49 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-12 09:49 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-12 09:49 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-12 09:49 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-12 01:28 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-12 01:28 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-12 01:28 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-12 01:28 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-12 01:28 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-12 01:28 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-12 01:28 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-12 01:28 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-12 01:28 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-12 01:28 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-12 01:28 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 01:28 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 01:28 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-12 01:28 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 01:28 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-12 01:28 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-12 01:28 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-12 01:28 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-12 01:28 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-06-11 22:38 - 2013-07-02 15:57 - 00009676 ____A C:\Windows\setupact.log
2013-06-11 22:38 - 2013-06-11 22:38 - 00000000 ____A C:\Windows\setuperr.log
2013-06-11 15:06 - 2013-06-11 15:06 - 00000165 ___AH C:\Users\Daniel\Desktop\~$pruefungen.xlsx
2013-06-10 18:25 - 2013-06-13 10:16 - 00012345 ____A C:\Users\Daniel\Desktop\pruefungen.xlsx
2013-06-10 16:58 - 2013-06-10 16:58 - 00000000 ____D C:\Users\Daniel\Documents\maiko_doc

==================== One Month Modified Files and Folders =======

2013-07-02 17:48 - 2013-07-02 17:48 - 00000000 ____D C:\FRST
2013-07-02 17:47 - 2009-07-14 06:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-02 17:47 - 2009-07-14 06:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-02 17:44 - 2013-07-02 17:44 - 01933556 ____A (Farbar) C:\Users\Daniel\Desktop\FRST64.exe
2013-07-02 17:39 - 2012-03-27 19:43 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-02 17:10 - 2012-04-04 15:20 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA.job
2013-07-02 17:07 - 2013-07-02 17:06 - 00000474 ____A C:\Users\Daniel\Desktop\defogger_disable.log
2013-07-02 17:06 - 2013-07-02 17:06 - 00000000 ____A C:\Users\Daniel\defogger_reenable
2013-07-02 17:06 - 2012-03-12 21:09 - 00000000 ____D C:\users\Daniel
2013-07-02 17:04 - 2013-07-02 17:04 - 00050477 ____A C:\Users\Daniel\Desktop\Defogger.exe
2013-07-02 17:01 - 2012-04-06 15:34 - 00000258 ____A C:\Windows\Tasks\HP Photo Creations Messager.job
2013-07-02 16:51 - 2013-01-21 11:26 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-02 16:12 - 2012-04-15 21:33 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Skype
2013-07-02 16:04 - 2013-07-02 16:04 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-07-02 16:03 - 2013-07-02 16:02 - 04396440 ____A (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup403.exe
2013-07-02 16:03 - 2012-06-13 23:11 - 00000000 ____D C:\Program Files\CCleaner
2013-07-02 16:01 - 2012-02-06 14:45 - 01601197 ____A C:\Windows\WindowsUpdate.log
2013-07-02 16:00 - 2012-03-26 15:06 - 00000000 ___RD C:\Users\Daniel\Dropbox
2013-07-02 16:00 - 2012-03-26 14:58 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Dropbox
2013-07-02 15:58 - 2012-03-27 19:43 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-02 15:57 - 2013-06-11 22:38 - 00009676 ____A C:\Windows\setupact.log
2013-07-02 15:57 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-02 15:42 - 2013-05-02 00:35 - 00000000 ____D C:\Users\Daniel\Documents\shamela-r1
2013-07-02 15:42 - 2012-03-29 01:43 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\shamela
2013-07-01 21:57 - 2012-04-04 15:20 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core.job
2013-07-01 21:43 - 2013-07-01 13:13 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Vyde
2013-07-01 15:47 - 2013-07-01 15:40 - 00001434 ____A C:\Users\Daniel\Downloads\Antrag auf Ausstellung einer Bescheinigung für den Lohnsteuerabzug 2013.xml
2013-07-01 13:47 - 2012-03-25 16:55 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps
2013-07-01 13:13 - 2013-07-01 13:13 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Waeged
2013-07-01 13:13 - 2013-07-01 13:13 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Qiebu
2013-06-28 16:48 - 2012-03-24 20:21 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Mozilla
2013-06-28 12:30 - 2013-02-22 22:33 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\vlc
2013-06-28 12:11 - 2012-11-22 16:29 - 00000099 ____A C:\Users\Public\LMDebug.log
2013-06-27 08:44 - 2013-05-28 12:59 - 00177947 ____A C:\test.xml
2013-06-26 17:33 - 2012-04-24 23:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-06-26 16:02 - 2013-06-26 14:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-06-26 13:54 - 2012-04-26 19:34 - 00000000 ____D C:\Users\Daniel\Documents\Citavi 3
2013-06-26 00:00 - 2012-07-25 18:26 - 00000000 ____D C:\Users\Daniel\Documents\Calibre Library
2013-06-25 15:11 - 2009-07-14 07:13 - 00778834 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-25 14:34 - 2013-06-25 14:34 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk
2013-06-25 09:17 - 2012-03-27 19:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\Google
2013-06-21 16:32 - 2012-07-07 22:14 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\dvdcss
2013-06-21 11:47 - 2013-06-21 11:47 - 00150406 ____A C:\Users\Daniel\Documents\1662.ppsx
2013-06-20 15:13 - 2013-06-14 10:17 - 00016101 ____A C:\Users\Daniel\Documents\Korrespondenztabelle.xlsx
2013-06-20 14:30 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF
2013-06-20 10:32 - 2013-06-12 17:54 - 00011854 ____A C:\Users\Daniel\Desktop\PruefungstermineSoSe2013.xlsx
2013-06-19 08:08 - 2013-06-19 08:07 - 00004802 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log
2013-06-19 08:08 - 2012-02-06 14:56 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-17 23:42 - 2013-06-17 23:38 - 00084339 ____A C:\Users\Daniel\Desktop\Briefvorlage-Birnstiel.dotx
2013-06-15 13:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-06-13 10:16 - 2013-06-10 18:25 - 00012345 ____A C:\Users\Daniel\Desktop\pruefungen.xlsx
2013-06-12 21:48 - 2012-12-07 17:18 - 00867240 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-06-12 21:48 - 2012-02-06 14:56 - 00789416 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-06-12 21:47 - 2013-06-19 08:08 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-12 21:43 - 2013-06-19 08:08 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-12 21:43 - 2013-06-19 08:08 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-12 21:43 - 2013-06-19 08:07 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-12 17:51 - 2012-04-30 21:30 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-12 17:51 - 2012-04-30 21:30 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-12 12:44 - 2011-02-11 00:48 - 00000000 ____D C:\Windows\Panther
2013-06-12 09:49 - 2012-03-24 18:57 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-11 22:38 - 2013-06-11 22:38 - 00000000 ____A C:\Windows\setuperr.log
2013-06-11 20:26 - 2009-07-14 07:08 - 00032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-11 15:06 - 2013-06-11 15:06 - 00000165 ___AH C:\Users\Daniel\Desktop\~$pruefungen.xlsx
2013-06-10 16:58 - 2013-06-10 16:58 - 00000000 ____D C:\Users\Daniel\Documents\maiko_doc
2013-06-08 16:08 - 2013-06-16 12:36 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-08 16:07 - 2013-06-16 12:36 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-08 16:06 - 2013-06-16 12:36 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-08 16:06 - 2013-06-16 12:36 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-08 16:06 - 2013-06-16 12:36 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-08 14:28 - 2013-06-16 12:36 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-08 13:42 - 2013-06-16 12:36 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-08 13:40 - 2013-06-16 12:36 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-08 13:40 - 2013-06-16 12:36 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-08 13:40 - 2013-06-16 12:36 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-08 13:40 - 2013-06-16 12:36 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-08 13:13 - 2013-06-16 12:36 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-07 23:02 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries
2013-06-07 09:58 - 2012-02-06 14:44 - 00000000 ____D C:\ProgramData\Sony Corporation

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-23 14:39

==================== End Of Log ============================
         

1) Addtion.txt:

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-07-2013
Ran by Daniel at 2013-07-02 17:49:37
Running from C:\Users\Daniel\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

 Update for Microsoft Office 2007 (KB2508958) (x32)
?????? Windows Live (x32 Version: 15.4.3502.0922)
??????? ????????? Windows Live Mesh ActiveX ??? ?????????? ?????????? (x32 Version: 15.4.5722.2)
??????? ?????????? Windows Live Mesh ActiveX ??? ????????? ??????????? (x32 Version: 15.4.5722.2)
??????? ??????????? ??? Windows Live (x32 Version: 15.4.3502.0922)
???????? ??????? ActiveX ??? Windows Live Mesh ??? ?????????????? ????????? (x32 Version: 15.4.5722.2)
???????? ?????????? Windows Live (x32 Version: 15.4.3502.0922)
?????????? Windows Live (x32 Version: 15.4.3502.0922)
??????????? ?? Windows Live (x32 Version: 15.4.3502.0922)
???????????? Windows Live (x32 Version: 15.4.3502.0922)
6000E609_eDocs (x32 Version: 1.00.0000)
6000E609_Help (x32 Version: 1.00.0000)
6000E609a (x32 Version: 140.0.000.000)
64 Bit HP CIO Components Installer (Version: 6.2.2)
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
ActiveX ???????? ?? Windows Live Mesh ?? ?????????? ?????? (x32 Version: 15.4.5722.2)
ActiveX-kontroll f?r fj?rranslutningar f?r Windows Live Mesh (x32 Version: 15.4.5722.2)
Adobe AIR (x32 Version: 2.5.1.17730)
Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224)
Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224)
Adobe Reader X (10.1.7) MUI (x32 Version: 10.1.7)
Alps Pointing-device for VAIO
Amazon MP3 Downloader 1.0.9 (x32)
Amazon MP3-Downloader 1.0.9 (x32)
A-PDF Number freeware 1.3 (x32)
ArcSoft Magic-i Visual Effects 2 (x32 Version: 2.0.1.142)
ArcSoft WebCam Companion 4 (x32 Version: 4.0.21.392)
BBC iPlayer Desktop (x32 Version: 3.0.11)
Bing Bar (x32 Version: 7.0.610.0)
Bluetooth Win7 Suite (64) (Version: 7.3.0.100)
BPDSoftware (x32 Version: 140.0.000.000)
BPDSoftware_Ini (x32 Version: 1.00.0000)
BufferChm (x32 Version: 140.0.213.000)
calibre (x32 Version: 0.9.29)
CCleaner (Version: 4.03)
Citavi (x32 Version: 3.4.0.2)
Common Desktop Agent (Version: 1.53.0)
Conexant HD Audio (Version: 8.54.0.53)
Control ActiveX Windows Live Mesh pentru conexiuni la distan?? (x32 Version: 15.4.5722.2)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2)
Controlo ActiveX do Windows Live Mesh para Ligaç?es Remotas (x32 Version: 15.4.5722.2)
Coptic Unicode (Version: 1.0.3.40)
D3DX10 (x32 Version: 15.4.2368.0902)
Deutsch (Orientalistik) (Version: 1.0.3.40)
DeviceDiscovery (x32 Version: 140.0.213.000)
Dropbox (HKCU Version: 2.0.22)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obs?ug? po??cze? zdalnych (x32 Version: 15.4.5722.2)
Free Audio CD to MP3 Converter version 1.3.12.1228 (x32 Version: 1.3.12.1228)
Free YouTube to MP3 Converter version 3.11.22.508 (x32 Version: 3.11.22.508)
Freecorder 6 (x32 Version: 2.1.10)
Freecorder 6 Add-on for Firefox (x32 Version: 2.1.9)
Freecorder 6 Applications (6.0.0.36) (x32 Version: 6.0.0.36)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922)
Galeria fotografii us?ugi Windows Live (x32 Version: 15.4.3502.0922)
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922)
Galerie foto Windows Live (x32 Version: 15.4.3502.0922)
Google Talk Plugin (x32 Version: 4.1.3.13728)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0)
Google Toolbar for Internet Explorer (x32 Version: 7.5.4209.2358)
Google Update Helper (x32 Version: 1.3.21.145)
GPBaseService2 (x32 Version: 140.0.212.000)
HP Customer Participation Program 14.0 (Version: 14.0)
HP Imaging Device Functions 14.0 (Version: 14.0)
HP Officejet 6000 E609 Series (Version: 14.0)
HP Photo Creations (x32 Version: 1.0.0.5192)
HP Photosmart 5510 series Basic Device Software (Version: 25.0.621.0)
HP Photosmart 5510 series Help (x32 Version: 140.0.2.2)
HP Photosmart 5510 series Product Improvement Study (Version: 25.0.621.0)
HP Smart Web Printing 4.60 (Version: 4.60)
HP Solution Center 14.0 (Version: 14.0)
HP Update (x32 Version: 5.003.000.004)
HPProductAssistant (x32 Version: 140.0.213.000)
HPSSupply (x32 Version: 140.0.212.000)
iDRS(tm) OCR Software by I.R.I.S (x32 Version: 1.00.13.00)
Intel(R) Control Center (x32 Version: 1.2.1.1007)
Intel(R) Management Engine Components (x32 Version: 7.0.0.1144)
Intel(R) Processor Graphics (x32 Version: 8.15.10.2291)
Intel(R) Rapid Storage Technology (x32 Version: 10.0.0.1046)
Java 7 Update 25 (x32 Version: 7.0.250)
Java 7 Update 9 (64-bit) (Version: 7.0.90)
Java Auto Updater (x32 Version: 2.1.9.5)
Java(TM) 6 Update 22 (64-bit) (Version: 6.0.220)
Java(TM) 6 Update 22 (x32 Version: 6.0.220)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
MarketResearch (x32 Version: 140.0.214.000)
Media Gallery (Version: 1.5.0.16020)
Mesh Runtime (x32 Version: 15.4.5722.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 21.0 (x86 en-US) (x32 Version: 21.0)
Mozilla Maintenance Service (x32 Version: 17.0.7)
Mozilla Thunderbird 17.0.7 (x86 en-US) (x32 Version: 17.0.7)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0)
Network64 (Version: 140.0.215.000)
OpenOffice.org 3.4.1 (x32 Version: 3.41.9593)
Ovl?dac? prvek ActiveX platformy Windows Live Mesh pro vzd?len? p?ipojen? (x32 Version: 15.4.5722.2)
Ovl?dac? prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (x32 Version: 15.4.5722.2)
PDF24 Creator 5.4.0 (x32)
PMB (x32 Version: 5.5.02.12220)
PMB VAIO Edition Plug-in (Version: 1.5.10.05300)
PMB VAIO Edition Plug-in (x32 Version: 1.6.00.06010)
Poczta us?ugi Windows Live (x32 Version: 15.4.3502.0922)
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922)
ProductContext (x32 Version: 140.0.000.000)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922)
Realtek PCIE Card Reader (x32 Version: 6.1.7600.77)
Remote Keyboard (x32 Version: 1.1.1.03020)
Remote Play with PlayStation 3 (x32 Version: 1.1.0.15070)
Samsung Easy Printer Manager (x32 Version: 1.02.06.10)
Samsung Network PC Fax (x32 Version: 1.05.29.00)
Samsung Printer Live Update (x32 Version: 1.01.00.04)
Samsung Scan Assistant (x32 Version: 1.04.45.00)
Samsung SCX-3400 Series (x32 Version: 1.08 (07/05/2012))
SetIP (x32 Version: 1.05.03.00)
Shared Add-in Extensibility Update for Microsoft .NET Framework 2.0 (KB908002) (x32 Version: 1.0.0)
Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002) (x32 Version: 1.0.0)
Shop for HP Supplies (Version: 14.0)
Skype Click to Call (x32 Version: 5.9.9216)
Skype™ 6.1 (x32 Version: 6.1.129)
SmarThru Office (x32 Version: 2.08.018)
SmartWebPrinting (x32 Version: 140.0.213.000)
SolutionCenter (x32 Version: 140.0.214.000)
Sony Corporation (Version: 1.0.0)
Sophos Anti-Virus (x32 Version: 10.2.8)
Sophos AutoUpdate (x32 Version: 2.9.0.344)
Sophos Virus Removal Tool (x32 Version: 2.3)
Spybot - Search & Destroy (x32 Version: 2.0.12)
SSLx64 (Version: 1.0.0)
SSLx86 (x32 Version: 1.0.0)
Status (x32 Version: 140.0.256.000)
Toolbox (x32 Version: 140.0.428.000)
TrayApp (x32 Version: 140.0.213.000)
Update for 2007 Microsoft Office System (KB967642) (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft Office 2007 Help for Common Features (KB963673) (x32)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32)
Update for Microsoft Office Excel 2007 Help (KB963678) (x32)
Update for Microsoft Office OneNote 2007 Help (KB963670) (x32)
Update for Microsoft Office Powerpoint 2007 Help (KB963669) (x32)
Update for Microsoft Office Script Editor Help (KB963671) (x32)
Update for Microsoft Office Word 2007 Help (KB963665) (x32)
Uzak Ba?lant?lar ?çin Windows Live Mesh ActiveX Denetimi (x32 Version: 15.4.5722.2)
VAIO - Media Gallery (x32 Version: 1.5.0.16020)
VAIO - PMB VAIO Edition Guide (x32 Version: 1.6.00.06030)
VAIO - PMB VAIO Edition Plug-in (x32 Version: 1.6.00.06140)
VAIO - Remote Keyboard (x32 Version: 1.0.1.03020)
VAIO - Remote Play with PlayStation®3 (x32 Version: 1.1.0.15070)
VAIO Care (x32 Version: 6.4.0.15030)
VAIO Control Center (x32 Version: 4.5.0.03040)
VAIO Data Restore Tool (x32 Version: 1.6.0.13140)
VAIO Easy Connect (x32 Version: 1.0.0.03050)
VAIO Event Service (x32 Version: 5.5.0.03040)
VAIO Gate (x32 Version: 2.3.0.11090)
VAIO Gate Default (x32 Version: 2.4.0.03240)
VAIO Hardware Diagnostics (x32 Version: 4.2.0.14280)
VAIO Hero Screensaver - Summer 2011 Screensaver (x32)
VAIO Improvement (x32 Version: 1.0.0.14150)
VAIO Improvement Validation (Version: 1.0.4.01190)
VAIO Manual (x32 Version: 2.0.0.02250)
VAIO Quick Web Access (x32 Version: 1.4.5.3)
VAIO Sample Contents (x32 Version: 1.4.2.09010)
VAIO Smart Network (x32 Version: 3.5.0.02280)
VAIO Transfer Support (x32 Version: 1.4.0.14230)
VAIO Update (x32 Version: 5.4.0.15300)
VCCx86 (x32 Version: 1.0.0)
VESx64 (Version: 1.0.0)
VESx86 (x32 Version: 1.0.0)
VIx64 (Version: 1.0.0)
VIx86 (x32 Version: 1.0.0)
VLC media player 2.0.7 (x32 Version: 2.0.7)
VoipBuster (x32 Version: 4.12 build 689)
VSNx64 (Version: 1.0.0)
VWSTx86 (x32 Version: 1.0.0)
WebReg (x32 Version: 140.0.213.017)
Willi 2.120 (x32)
WinDjView 2.0.2 (Version: 2.0.2)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3508.1109)
Windows Live Fot?t?r (x32 Version: 15.4.3502.0922)
Windows Live Foto?raf Galerisi (x32 Version: 15.4.3502.0922)
Windows Live Fotogaléria (x32 Version: 15.4.3502.0922)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live Fotogalleri (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3508.1109)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-objekt til fjernforbindelser (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-vezérl? t?voli kapcsolatokhoz (x32 Version: 15.4.5722.2)
Windows Live Meshin et?yhteyksien ActiveX-komponentti (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
Windows Liven asennusty?kalu (x32 Version: 15.4.3502.0922)
Windows Liven s?hk?posti (x32 Version: 15.4.3502.0922)
Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922)
XMind 2012 (v3.3.1) (x32 Version: 3.3.1.201212250029)

==================== Restore Points  =========================

11-06-2013 23:25:24 Windows Update
12-06-2013 07:47:22 Windows Update
16-06-2013 10:35:40 Windows Update
19-06-2013 06:06:53 Installed Java 7 Update 25
21-06-2013 06:21:23 Windows Update
26-06-2013 04:28:26 Windows Update
02-07-2013 08:54:50 Windows Update

==================== Hosts content: ==========================
127.0.0.1	www.007guard.com
127.0.0.1	007guard.com
127.0.0.1	008i.com
127.0.0.1	www.008k.com
127.0.0.1	008k.com
127.0.0.1	www.00hq.com
127.0.0.1	00hq.com
127.0.0.1	010402.com
127.0.0.1	www.032439.com
127.0.0.1	032439.com
127.0.0.1	www.0scan.com
127.0.0.1	0scan.com
127.0.0.1	www.1000gratisproben.com
127.0.0.1	1000gratisproben.com
127.0.0.1	1001namen.com
127.0.0.1	www.1001namen.com
127.0.0.1	100888290cs.com
127.0.0.1	www.100888290cs.com
127.0.0.1	www.100sexlinks.com
127.0.0.1	100sexlinks.com
127.0.0.1	www.10sek.com
127.0.0.1	10sek.com
127.0.0.1	www.1-2005-search.com
127.0.0.1	1-2005-search.com
127.0.0.1	www.123fporn.info
127.0.0.1	123fporn.info
127.0.0.1	123haustiereundmehr.com
127.0.0.1	www.123haustiereundmehr.com
127.0.0.1	123moviedownload.com

There are more than 1000 lines.


==================== Scheduled Tasks (whitelisted) =============

Task: {007BF961-35D6-4997-8668-9B21A46AB1EA} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdate.exe No File
Task: {0F00A5B5-10B7-4CB4-BDC0-0E943EEBE9C4} - System32\Tasks\Sony Corporation\VAIO Improvement\VAIOImprovementUploader => C:\Program Files\Sony\VAIO Improvement\viuploader.exe [2011-02-15] (Sony Corporation)
Task: {12C233F7-78E0-49C1-884C-7C7C3AA6E686} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27] (Google Inc.)
Task: {193F5D68-B659-45B1-B9B3-13053757E9B7} - System32\Tasks\{79AE494A-B00F-4E51-9D02-806671315170} => C:\DISK1\_MSSETUP.EXE No File
Task: {20433116-3838-4598-A8C8-32E3CE8F5A33} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {3813C30A-E783-4F16-839B-37BF74D535C0} - System32\Tasks\{C8099E57-DB19-44A3-9811-99FF52A6DB76} => C:\DISK1\SETUP.EXE No File
Task: {3F4DD9FF-74EB-45B0-9B17-DB32709EB2AA} - System32\Tasks\Sony Corporation\VAIO Smart Network\VSN Logon Start => C:\Program Files\Sony\VAIO Smart Network\VSNClient No File
Task: {400EC6C2-FB40-444D-8F2C-92DC643BC27A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDScan.exe No File
Task: {4140F79D-C63D-41AD-A02D-12BA3CE145D9} - System32\Tasks\{A23A174C-68F5-40CA-B941-FDC1289EB290} => C:\DISK1\SETUP.EXE No File
Task: {506A37A0-548C-4545-9782-20845E993604} - System32\Tasks\{379DF08F-7A5B-40E4-A6C9-BF55B02B91FA} => C:\DISK1\SETUP.EXE No File
Task: {51D461DA-22E9-441B-8384-2D30FA940668} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: {5483E0E3-3A4F-48EA-8175-582EBDB71603} - System32\Tasks\Sony Corporation\VAIO Improvement Validation\VAIO Improvement Validation => C:\Program Files\Sony\VAIO Improvement Validation\viv.exe [2011-01-20] (Sony Corporation)
Task: {59FFB27E-68A5-46AB-9334-ADE36FD089D3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated)
Task: {5A6454FA-9FF5-42AF-9655-25EBCB00A014} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation)
Task: {69B5207D-6704-4205-AAD9-78074959E958} - System32\Tasks\{0819DC4F-BECD-4FDA-B9E0-B16466E48BF5} => C:\DISK1\_MSSETUP.EXE No File
Task: {6FD03CBD-0AF3-4D88-B06F-D9DC145AF713} - System32\Tasks\{0754E513-E313-47B3-B55E-F56D009DB678} => C:\DISK1\SETUP.EXE No File
Task: {726180E2-6A8E-42AC-B602-40066AFEE225} - System32\Tasks\{BC3BFA7F-7C59-413D-9DA1-B7D3F9A5CCA8} => C:\DISK1\SETUP.EXE No File
Task: {952F479D-6606-43BA-9F59-F073D5B3BA16} - System32\Tasks\{22A55328-89D4-43AA-9BD6-97C07E551919} => C:\DISK1\SETUP.EXE No File
Task: {9CDA80ED-4A92-4A36-8374-5A4452287999} - System32\Tasks\{019D57EB-6012-42C2-B389-E900B529DED9} => C:\DISK1\SETUP.EXE No File
Task: {A389D2A1-B14E-4975-BC69-515565B77A59} - System32\Tasks\SONY\VAIO Gate\StartExecuteProxy => C:\Program Files\Sony\VAIO Gate\ExecutionProxy.exe [2010-11-16] (Sony Corporation)
Task: {A4573A20-64C3-48F9-823C-A35856C347D4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-28] (Google Inc.)
Task: {AC899129-C248-4F9C-89A1-599035721B77} - System32\Tasks\HP Photo Creations Messager => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-02-15] ()
Task: {BA8DCE2D-E731-4726-A808-77995317348B} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update 5 => C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe [2011-03-30] (Sony Corporation)
Task: {BE482682-93CD-460A-B2A1-C762BBB33684} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation)
Task: {C4AE742F-5E88-468C-915D-D354017594D2} - System32\Tasks\{5CE0363D-A773-4F22-986E-E5749604663D} => C:\DISK1\SETUP.EXE No File
Task: {C70B2CF8-D882-4075-94B1-0A64FA67997D} - System32\Tasks\{5F4BD8CD-A5F6-4489-BA38-BDEA07419348} => C:\DISK1\SETUP.EXE No File
Task: {CB65759A-6A9E-4176-A807-B58ABD497F64} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd)
Task: {D24C2055-9D96-4E63-910F-B86BDA8DB7CF} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDImmunize.exe No File
Task: {D3F7629C-0745-4E82-9309-2CECD6619BA2} - System32\Tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896} => C:\Windows\system32\msfeedssync.exe [2013-05-31] (Microsoft Corporation)
Task: {D45A9D9B-2AAC-4113-B249-779F7C7823C6} - System32\Tasks\User_Feed_Synchronization-{F8F9D594-1F59-4874-8B7E-773D45408B09} => C:\Windows\system32\msfeedssync.exe [2013-05-31] (Microsoft Corporation)
Task: {DF4D8943-C503-473F-835B-F61D9227C79C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27] (Google Inc.)
Task: {EC433C01-59C3-4645-A5CD-942EE01664F4} - System32\Tasks\HPCustParticipation HP Photosmart 5510 series => C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPCustPartic.exe [2011-09-16] (Hewlett-Packard Co.)
Task: {ECB25488-1BEF-461F-9480-51C9C7FE112E} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2010-11-16] (Sony Corporation)
Task: {F831395A-A7F0-4603-9820-68D2996C9E95} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-28] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core.job => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA.job => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HP Photo Creations Messager.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe

==================== Faulty Device Manager Devices =============

Name: Officejet 6000 E609a
Description: Officejet 6000 E609a
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Photosmart 5510 series
Description: Photosmart 5510 series
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service: 
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/02/2013 03:57:51 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/02/2013 03:40:26 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/02/2013 01:47:26 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/01/2013 01:47:33 PM) (Source: Application Error) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16611, time stamp: 0x5191e7aa
Faulting module name: igd10umd32.dll, version: 8.15.10.2291, time stamp: 0x4d41a0db
Exception code: 0xc0000005
Fault offset: 0x000e3331
Faulting process id: 0xd14
Faulting application start time: 0xIEXPLORE.EXE0
Faulting application path: IEXPLORE.EXE1
Faulting module path: IEXPLORE.EXE2
Report Id: IEXPLORE.EXE3

Error: (06/30/2013 05:27:21 PM) (Source: Application Error) (User: )
Description: Faulting application name: firefox.exe, version: 21.0.0.4879, time stamp: 0x518ec3cc
Faulting module name: xul.dll, version: 21.0.0.4879, time stamp: 0x518ec306
Exception code: 0xc0000005
Fault offset: 0x001c9789
Faulting process id: 0x3240
Faulting application start time: 0xfirefox.exe0
Faulting application path: firefox.exe1
Faulting module path: firefox.exe2
Report Id: firefox.exe3

Error: (06/30/2013 04:00:16 PM) (Source: Application Hang) (User: )
Description: The program IEXPLORE.EXE version 10.0.9200.16611 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 2344

Start Time: 01ce759858fda6b9

Termination Time: 34

Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Report Id:

Error: (06/30/2013 03:11:35 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/28/2013 11:44:14 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/28/2013 04:47:46 PM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e
Exception code: 0xc0000005
Fault offset: 0x0000000000021cca
Faulting process id: 0x3b8
Faulting application start time: 0xsvchost.exe0
Faulting application path: svchost.exe1
Faulting module path: svchost.exe2
Report Id: svchost.exe3

Error: (06/28/2013 10:16:11 AM) (Source: Application Error) (User: )
Description: Faulting application name: swi_service.exe, version: 3.2.101.0, time stamp: 0x510feb76
Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec49b8f
Exception code: 0xc0000005
Fault offset: 0x00065fe4
Faulting process id: 0xd18
Faulting application start time: 0xswi_service.exe0
Faulting application path: swi_service.exe1
Faulting module path: swi_service.exe2
Report Id: swi_service.exe3


System errors:
=============
Error: (07/02/2013 03:58:56 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (07/02/2013 03:58:50 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)

Error: (07/02/2013 03:57:38 PM) (Source: BTHUSB) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (07/02/2013 03:41:35 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (07/02/2013 03:41:26 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)

Error: (07/02/2013 03:40:14 PM) (Source: BTHUSB) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (07/02/2013 01:48:31 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (07/02/2013 01:48:25 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)

Error: (07/02/2013 01:46:15 PM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (07/02/2013 10:43:16 AM) (Source: BTHUSB) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.


Microsoft Office Sessions:
=========================
Error: (09/02/2012 05:32:29 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 5308 seconds with 1020 seconds of active time.  This session ended with a crash.

Error: (07/17/2012 09:38:23 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 17791 seconds with 5040 seconds of active time.  This session ended with a crash.


==================== Memory info =========================== 

Percentage of memory in use: 43%
Total physical RAM: 8139.86 MB
Available physical RAM: 4600.7 MB
Total Pagefile: 16277.9 MB
Available Pagefile: 12702.95 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:452.18 GB) (Free:349.93 GB) NTFS (Disk=0 Partition=3)

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: A920C8D1)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=452 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
Ich habe jetzt auch bemerkt, dass defogger eine txt-Datei auf dem Desktop plaziert hatte. Die war mir zunächst nicht aufgefallen. Auch hiervon die log-Datei, keine sehr lange:

Code:
ATTFilter
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 17:07 on 02/07/2013 (Daniel)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-
         
Vielen Dank,

piristibulus

PS: sollte ich während dieser Diagnose-Phase etwas beachten, was das Verschicken von Mails mit word-Dokumente an andere etc. betrifft?
Vielen Dank
__________________

Alt 02.07.2013, 18:16   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!
Downloade dir bitte Combofix vom folgenden Downloadspiegel

Link 1


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 02.07.2013, 19:01   #5
Piristibulus
 
Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Lieber Schrauber, vielen Dank!

Habe das Programm runtergelanden und mein wireless ausgeschaltet,
dann Sophos und Windows Defender abgestellt und ebenso - dachte ich jedenfalls - Spybot. Dann kam jedoch ein pop-up, dass Spybot noch immer im Hintergrund am laufen sei.

Ich habe dann "versucht", dieses über den Taskmanager abzuschalten. Ob es geklappt hat, weiss ich nicht. ComboFix gab die Meldung, es würde dennoch auf eigene Gefahr weiterlaufen.

Hier ist das Log (einen Re-start hat das Programm nicht ausgeführt):

Code:
ATTFilter
ComboFix 13-07-02.03 - Daniel 02/07/2013  19:46:29.1.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1256.966.1033.18.8140.5182 [GMT 2:00]
Running from: c:\users\Daniel\Desktop\ComboFix.exe
AV: Sophos Anti-Virus *Disabled/Updated* {65FBD860-96D8-75EF-C7ED-7BE27E6C498A}
SP: Sophos Anti-Virus *Disabled/Updated* {DE9A3984-B0E2-7A61-FD5D-409005EB0337}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Daniel\AppData\Local\assembly\tmp
c:\users\Daniel\AppData\Roaming\Waeged
c:\users\Daniel\AppData\Roaming\Waeged\ihurp.exe
c:\users\Daniel\Documents\~WRL0005.tmp
c:\windows\IsUn0407.exe
.
.
(((((((((((((((((((((((((   Files Created from 2013-06-02 to 2013-07-02  )))))))))))))))))))))))))))))))
.
.
2013-07-02 17:51 . 2013-07-02 17:51	--------	d-----w-	c:\users\Default\AppData\Local\temp
2013-07-02 15:48 . 2013-07-02 15:48	--------	d-----w-	C:\FRST
2013-07-02 08:55 . 2013-06-12 03:08	9552976	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{7C9A529E-5E06-4E86-9532-509BACFD89BD}\mpengine.dll
2013-07-01 11:13 . 2013-07-01 19:43	--------	d-----w-	c:\users\Daniel\AppData\Roaming\Vyde
2013-07-01 11:13 . 2013-07-01 11:13	--------	d-----w-	c:\users\Daniel\AppData\Roaming\Qiebu
2013-06-26 12:28 . 2013-06-26 14:02	--------	d-----w-	c:\program files (x86)\Mozilla Thunderbird
2013-06-19 06:08 . 2013-06-12 19:47	96168	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-06-12 07:49 . 2013-05-17 01:25	257536	----a-w-	c:\program files (x86)\Internet Explorer\ieproxy.dll
2013-06-11 23:28 . 2013-05-08 06:39	1910632	----a-w-	c:\windows\system32\drivers\tcpip.sys
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-12 19:48 . 2012-12-07 15:18	867240	----a-w-	c:\windows\SysWow64\npDeployJava1.dll
2013-06-12 19:48 . 2012-02-06 12:56	789416	----a-w-	c:\windows\SysWow64\deployJava1.dll
2013-06-12 15:51 . 2012-04-30 19:30	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-12 15:51 . 2012-04-30 19:30	692104	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2013-06-12 07:49 . 2012-03-24 16:57	75825640	----a-w-	c:\windows\system32\MRT.exe
2013-05-31 01:26 . 2013-05-31 01:26	1054720	----a-w-	c:\windows\system32\MsSpellCheckingFacility.exe
2013-05-31 01:26 . 2013-05-31 01:26	719360	----a-w-	c:\windows\SysWow64\mshtmlmedia.dll
2013-05-31 01:26 . 2013-05-31 01:26	523264	----a-w-	c:\windows\SysWow64\vbscript.dll
2013-05-31 01:26 . 2013-05-31 01:26	226304	----a-w-	c:\windows\system32\elshyph.dll
2013-05-31 01:26 . 2013-05-31 01:26	185344	----a-w-	c:\windows\SysWow64\elshyph.dll
2013-05-31 01:26 . 2013-05-31 01:26	158720	----a-w-	c:\windows\SysWow64\msls31.dll
2013-05-31 01:26 . 2013-05-31 01:26	150528	----a-w-	c:\windows\SysWow64\iexpress.exe
2013-05-31 01:26 . 2013-05-31 01:26	138752	----a-w-	c:\windows\SysWow64\wextract.exe
2013-05-31 01:26 . 2013-05-31 01:26	73728	----a-w-	c:\windows\SysWow64\SetIEInstalledDate.exe
2013-05-31 01:26 . 2013-05-31 01:26	61952	----a-w-	c:\windows\SysWow64\tdc.ocx
2013-05-31 01:26 . 2013-05-31 01:26	48640	----a-w-	c:\windows\SysWow64\mshtmler.dll
2013-05-31 01:26 . 2013-05-31 01:26	38400	----a-w-	c:\windows\SysWow64\imgutil.dll
2013-05-31 01:26 . 2013-05-31 01:26	361984	----a-w-	c:\windows\SysWow64\html.iec
2013-05-31 01:26 . 2013-05-31 01:26	137216	----a-w-	c:\windows\SysWow64\ieUnatt.exe
2013-05-31 01:26 . 2013-05-31 01:26	12800	----a-w-	c:\windows\SysWow64\mshta.exe
2013-05-31 01:26 . 2013-05-31 01:26	110592	----a-w-	c:\windows\SysWow64\IEAdvpack.dll
2013-05-31 01:26 . 2013-05-31 01:26	81408	----a-w-	c:\windows\system32\icardie.dll
2013-05-31 01:26 . 2013-05-31 01:26	762368	----a-w-	c:\windows\system32\ieapfltr.dll
2013-05-31 01:26 . 2013-05-31 01:26	452096	----a-w-	c:\windows\system32\dxtmsft.dll
2013-05-31 01:26 . 2013-05-31 01:26	441856	----a-w-	c:\windows\system32\html.iec
2013-05-31 01:26 . 2013-05-31 01:26	281600	----a-w-	c:\windows\system32\dxtrans.dll
2013-05-31 01:26 . 2013-05-31 01:26	23040	----a-w-	c:\windows\SysWow64\licmgr10.dll
2013-05-31 01:26 . 2013-05-31 01:26	216064	----a-w-	c:\windows\system32\msls31.dll
2013-05-31 01:26 . 2013-05-31 01:26	197120	----a-w-	c:\windows\system32\msrating.dll
2013-05-31 01:26 . 2013-05-31 01:26	1441280	----a-w-	c:\windows\SysWow64\inetcpl.cpl
2013-05-31 01:26 . 2013-05-31 01:26	1400416	----a-w-	c:\windows\system32\ieapfltr.dat
2013-05-31 01:26 . 2013-05-31 01:26	97280	----a-w-	c:\windows\system32\mshtmled.dll
2013-05-31 01:26 . 2013-05-31 01:26	92160	----a-w-	c:\windows\system32\SetIEInstalledDate.exe
2013-05-31 01:26 . 2013-05-31 01:26	905728	----a-w-	c:\windows\system32\mshtmlmedia.dll
2013-05-31 01:26 . 2013-05-31 01:26	77312	----a-w-	c:\windows\system32\tdc.ocx
2013-05-31 01:26 . 2013-05-31 01:26	62976	----a-w-	c:\windows\system32\pngfilt.dll
2013-05-31 01:26 . 2013-05-31 01:26	599552	----a-w-	c:\windows\system32\vbscript.dll
2013-05-31 01:26 . 2013-05-31 01:26	52224	----a-w-	c:\windows\system32\msfeedsbs.dll
2013-05-31 01:26 . 2013-05-31 01:26	51200	----a-w-	c:\windows\system32\imgutil.dll
2013-05-31 01:26 . 2013-05-31 01:26	48640	----a-w-	c:\windows\system32\mshtmler.dll
2013-05-31 01:26 . 2013-05-31 01:26	27648	----a-w-	c:\windows\system32\licmgr10.dll
2013-05-31 01:26 . 2013-05-31 01:26	270848	----a-w-	c:\windows\system32\iedkcs32.dll
2013-05-31 01:26 . 2013-05-31 01:26	247296	----a-w-	c:\windows\system32\webcheck.dll
2013-05-31 01:26 . 2013-05-31 01:26	235008	----a-w-	c:\windows\system32\url.dll
2013-05-31 01:26 . 2013-05-31 01:26	173568	----a-w-	c:\windows\system32\ieUnatt.exe
2013-05-31 01:26 . 2013-05-31 01:26	167424	----a-w-	c:\windows\system32\iexpress.exe
2013-05-31 01:26 . 2013-05-31 01:26	1509376	----a-w-	c:\windows\system32\inetcpl.cpl
2013-05-31 01:26 . 2013-05-31 01:26	149504	----a-w-	c:\windows\system32\occache.dll
2013-05-31 01:26 . 2013-05-31 01:26	144896	----a-w-	c:\windows\system32\wextract.exe
2013-05-31 01:26 . 2013-05-31 01:26	13824	----a-w-	c:\windows\system32\mshta.exe
2013-05-31 01:26 . 2013-05-31 01:26	136192	----a-w-	c:\windows\system32\iepeers.dll
2013-05-31 01:26 . 2013-05-31 01:26	135680	----a-w-	c:\windows\system32\IEAdvpack.dll
2013-05-31 01:26 . 2013-05-31 01:26	12800	----a-w-	c:\windows\system32\msfeedssync.exe
2013-05-31 01:26 . 2013-05-31 01:26	102912	----a-w-	c:\windows\system32\inseng.dll
2013-05-31 01:03 . 2013-05-31 01:03	9728	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	5632	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	4096	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	4096	---ha-w-	c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	3072	---ha-w-	c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	3072	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	9728	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	604160	----a-w-	c:\windows\SysWow64\d3d10level9.dll
2013-05-31 01:03 . 2013-05-31 01:03	5632	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	5632	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	5632	---ha-w-	c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	522752	----a-w-	c:\windows\system32\XpsGdiConverter.dll
2013-05-31 01:03 . 2013-05-31 01:03	465920	----a-w-	c:\windows\system32\WMPhoto.dll
2013-05-31 01:03 . 2013-05-31 01:03	417792	----a-w-	c:\windows\SysWow64\WMPhoto.dll
2013-05-31 01:03 . 2013-05-31 01:03	3928064	----a-w-	c:\windows\system32\d2d1.dll
2013-05-31 01:03 . 2013-05-31 01:03	364544	----a-w-	c:\windows\SysWow64\XpsGdiConverter.dll
2013-05-31 01:03 . 2013-05-31 01:03	363008	----a-w-	c:\windows\system32\dxgi.dll
2013-05-31 01:03 . 2013-05-31 01:03	3584	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	3584	---ha-w-	c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	3419136	----a-w-	c:\windows\SysWow64\d2d1.dll
2013-05-31 01:03 . 2013-05-31 01:03	333312	----a-w-	c:\windows\system32\d3d10_1core.dll
2013-05-31 01:03 . 2013-05-31 01:03	3072	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	3072	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	296960	----a-w-	c:\windows\system32\d3d10core.dll
2013-05-31 01:03 . 2013-05-31 01:03	2776576	----a-w-	c:\windows\system32\msmpeg2vdec.dll
2013-05-31 01:03 . 2013-05-31 01:03	2565120	----a-w-	c:\windows\system32\d3d10warp.dll
2013-05-31 01:03 . 2013-05-31 01:03	2560	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	2560	---ha-w-	c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	249856	----a-w-	c:\windows\SysWow64\d3d10_1core.dll
2013-05-31 01:03 . 2013-05-31 01:03	245248	----a-w-	c:\windows\system32\WindowsCodecsExt.dll
2013-05-31 01:03 . 2013-05-31 01:03	2284544	----a-w-	c:\windows\SysWow64\msmpeg2vdec.dll
2013-05-31 01:03 . 2013-05-31 01:03	220160	----a-w-	c:\windows\SysWow64\d3d10core.dll
2013-05-31 01:03 . 2013-05-31 01:03	207872	----a-w-	c:\windows\SysWow64\WindowsCodecsExt.dll
2013-05-31 01:03 . 2013-05-31 01:03	194560	----a-w-	c:\windows\system32\d3d10_1.dll
2013-05-31 01:03 . 2013-05-31 01:03	1682432	----a-w-	c:\windows\system32\XpsPrint.dll
2013-05-31 01:03 . 2013-05-31 01:03	1643520	----a-w-	c:\windows\system32\DWrite.dll
2013-05-31 01:03 . 2013-05-31 01:03	161792	----a-w-	c:\windows\SysWow64\d3d10_1.dll
2013-05-31 01:03 . 2013-05-31 01:03	1247744	----a-w-	c:\windows\SysWow64\DWrite.dll
2013-05-31 01:03 . 2013-05-31 01:03	1238528	----a-w-	c:\windows\system32\d3d10.dll
2013-05-31 01:03 . 2013-05-31 01:03	1175552	----a-w-	c:\windows\system32\FntCache.dll
2013-05-31 01:03 . 2013-05-31 01:03	1158144	----a-w-	c:\windows\SysWow64\XpsPrint.dll
2013-05-31 01:03 . 2013-05-31 01:03	1080832	----a-w-	c:\windows\SysWow64\d3d10.dll
2013-05-31 01:03 . 2013-05-31 01:03	10752	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	10752	---ha-w-	c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	648192	----a-w-	c:\windows\system32\d3d10level9.dll
2013-05-31 01:03 . 2013-05-31 01:03	293376	----a-w-	c:\windows\SysWow64\dxgi.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{6B34ACCF-1B63-4E1A-8633-461917C75544}"= "c:\program files (x86)\Freecorder 6\tbcore3.dll" [2012-08-01 2711928]
.
[HKEY_CLASSES_ROOT\clsid\{6b34accf-1b63-4e1a-8633-461917c75544}]
[HKEY_CLASSES_ROOT\TBSB00808.TBSB00808.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB00808.TBSB00808]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	130736	----a-w-	c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	130736	----a-w-	c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	130736	----a-w-	c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-03-27 39408]
"HP Photosmart 5510 series (NET)"="c:\program files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" [2011-09-16 2676584]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"VoipBuster"="c:\program files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe" [2013-06-25 19378496]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-01-08 18705664]
"Spybot-S&D Cleaning"="c:\program files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" [2012-11-13 3713032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-13 283160]
"ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2011-02-15 2757312]
"PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-27 648032]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-03-24 49208]
"STO Backup Service"="c:\program files (x86)\SmarThru Office\BackUpSvr.exe" [2012-01-13 199760]
"STO Launcher Service"="c:\program files (x86)\SmarThru Office\x64\LegacyLauncher.exe" [2012-01-13 405584]
"SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2012-11-13 3825176]
"Sophos AutoUpdate Monitor"="c:\program files (x86)\Sophos\AutoUpdate\almon.exe" [2013-04-03 929272]
"PDFPrint"="c:\program files (x86)\PDF24\pdf24.exe" [2013-03-20 162856]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
c:\users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968]
OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2010-5-28 276328]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~2\sophos_detoured.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute	REG_MULTI_SZ   	autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 swi_update_64;Sophos Web Intelligence Update;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe [x]
R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
R3 btath_avdt;Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x]
R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1y60x64.sys [x]
R3 sdcfilter;sdcfilter;c:\windows\system32\DRIVERS\sdcfilter.sys;c:\windows\SYSNATIVE\DRIVERS\sdcfilter.sys [x]
R3 SOHCImp;VAIO Content Importer;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [x]
R3 SOHDs;VAIO Device Searcher;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [x]
R3 SpfService;VAIO Entertainment Common Service;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [x]
R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [x]
R3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [x]
R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys;c:\windows\SYSNATIVE\DRIVERS\SophosBootDriver.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S1 SAVOnAccess;SAVOnAccess;c:\windows\system32\DRIVERS\savonaccess.sys;c:\windows\SYSNATIVE\DRIVERS\savonaccess.sys [x]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [x]
S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe;c:\program files\Sony\VAIO Care\VCPerfService.exe [x]
S2 Samsung Network Fax Server;Samsung Network Fax Server;c:\windows\system32\spool\drivers\x64\3\NetFaxServer64.exe;c:\windows\SYSNATIVE\spool\drivers\x64\3\NetFaxServer64.exe [x]
S2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [x]
S2 SAVService;Sophos Anti-Virus;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [x]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x]
S2 Sophos Web Control Service;Sophos Web Control Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [x]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys;c:\windows\SYSNATIVE\Drivers\SSPORT.sys [x]
S2 swi_service;Sophos Web Intelligence Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [x]
S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe;c:\program files\Sony\VAIO Smart Network\VSNService.exe [x]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftKsUFilter.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys;c:\windows\SYSNATIVE\DRIVERS\SFEP.sys [x]
S3 VCService;VCService;c:\program files\Sony\VAIO Care\VCService.exe;c:\program files\Sony\VAIO Care\VCService.exe [x]
S3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update 5\VUAgent.exe;c:\program files\Sony\VAIO Update 5\VUAgent.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt	REG_MULTI_SZ   	hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2013-07-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-30 15:51]
.
2013-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27 17:42]
.
2013-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27 17:42]
.
2013-07-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core.job
- c:\users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-04 22:53]
.
2013-07-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA.job
- c:\users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-04 22:53]
.
2013-07-02 c:\windows\Tasks\HP Photo Creations Messager.job
- c:\programdata\HP Photo Creations\MessageCheck.exe [2011-02-15 10:11]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2011-03-29 518784]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-04-29 790688]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-04-29 657568]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-29 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-29 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-29 418328]
"CDAServer"="c:\program files\Common Files\Common Desktop Agent\CDASrv.exe" [2010-12-17 438784]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~2\sophos_detoured_x64.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.wikipedia.org/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\users\Daniel\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
LSP: c:\programdata\Sophos\Web Intelligence\swi_ifslsp.dll
TCP: DhcpNameServer = 192.168.178.1
TCP: Interfaces\{F6BFC1EA-082D-4450-A95B-BF5334CE4940}: NameServer = 141.2.22.74,141.2.149.10
FF - ProfilePath - c:\users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.bl.uk/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?q=
FF - ExtSQL: !HIDDEN! 2012-05-11 13:13; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-Cilehaze - c:\users\Daniel\AppData\Roaming\Waeged\ihurp.exe
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
Notify-SDWinLogon - SDWinLogon.dll
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
WebBrowser-{6B34ACCF-1B63-4E1A-8633-461917C75544} - (no file)
HKLM-Run-Apoint - c:\program files (x86)\Apoint\Apoint.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SampleCollector]
"ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=c:\programdata\Sony Corporation\VAIO Care\inteldata\""
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-07-02  19:53:32
ComboFix-quarantined-files.txt  2013-07-02 17:53
.
Pre-Run: 375,567,732,736 bytes free
Post-Run: 375,206,096,896 bytes free
.
- - End Of File - - B0D7EB9FC6935241137B2955187EDD93
D41D8CD98F00B204E9800998ECF8427E
         
Vielen Dank,

Piristibulus


Alt 03.07.2013, 07:13   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Hi,

Combofix-Skript
WARNUNG für die MITLESER:
Folgendes ComboFix Skript ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

  • Lösche die vorhandene Combofix.exe von deinem Desktop und lade das Programm von folgenden Download-Spiegel neu herunter: Link
  • Speichere es erneut auf dem Desktop (nicht woanders hin, das ist wichtig)!
  • Drücke die Windows + R Taste --> notepad (hinein schreiben) --> OK
  • Kopiere nun den Text aus der folgenden Codebox komplett in das leere Textdokument.
    Code:
    ATTFilter
    Folder::
    c:\users\Daniel\AppData\Roaming\Vyde
    c:\users\Daniel\AppData\Roaming\Qiebu
             
  • Speichere dies als CFScript.txt auf deinem Desktop.
  • Wichtig: Stelle deine Anti Viren Software temporär ab. Dies kann ComboFix nämlich bei der Arbeit behindern.
    Danach wieder anstellen nicht vergessen!
  • Schließe alle laufenden Programme damit ComboFix ungehindert arbeiten kann.
  • Ziehe CFScript.txt in die ComboFix.exe wie in diesem Bild:
  • Mache nichts am Computer, bewege nicht die Maus über das ComboFix-Fenster oder klicke in dieses hinein. Dies kann dazu führen, dass ComboFix sich aufhängt.
  • Wenn ComboFix fertig ist wird es ein Log erstellen: C:\ComboFix.txt
    Bitte füge es hier als Antwort (in CODE-Tags mit dem #-Button des Editors) ein.

Hinweis:
Suspect:: und Collect::
Falls im Skript diese Anweisungen enthalten sind, sollen Dateien zur Analyse eingeschickt werden. Es erscheint eine Message-Box, nachdem Combofix fertig ist. Klicke OK und folge den Aufforderungen/Anweisungen, um die Dateien hochzuladen. Teile mir unbedingt mit, ob der Upload geklappt hat!



Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST Log bitte. Noch Probleme?
__________________
--> Sophosmeldung: Troj/ZbotMem-B im Memory

Alt 03.07.2013, 20:45   #7
Piristibulus
 
Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Lieber Schrauber,

vielen Dank für die Hilfe. Vorab erstmal, es scheint schon einiges bewirkt zu haben. Die Akzente und Sonderzeichen der fremdsprachlichen Tastaturbelegungen funktionieren wieder einwandfrei, und Akzente werden auch nicht mehr doppelt geschrieben.

Hier nun die Logs:

1. ComboFix.txt:

Code:
ATTFilter
ComboFix 13-07-02.03 - Daniel 03/07/2013  10:23:36.2.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1256.966.1033.18.8140.5708 [GMT 2:00]
Running from: c:\users\Daniel\Desktop\ComboFix.exe
Command switches used :: c:\users\Daniel\Desktop\CFScript.txt
AV: Sophos Anti-Virus *Disabled/Updated* {65FBD860-96D8-75EF-C7ED-7BE27E6C498A}
SP: Sophos Anti-Virus *Disabled/Updated* {DE9A3984-B0E2-7A61-FD5D-409005EB0337}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Daniel\AppData\Roaming\Qiebu
c:\users\Daniel\AppData\Roaming\Qiebu\azgo.xik
c:\users\Daniel\AppData\Roaming\Vyde
.
.
(((((((((((((((((((((((((   Files Created from 2013-06-03 to 2013-07-03  )))))))))))))))))))))))))))))))
.
.
2013-07-03 08:27 . 2013-07-03 08:27	--------	d-----w-	c:\users\Default\AppData\Local\temp
2013-07-02 15:48 . 2013-07-02 15:48	--------	d-----w-	C:\FRST
2013-07-02 08:55 . 2013-06-12 03:08	9552976	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{7C9A529E-5E06-4E86-9532-509BACFD89BD}\mpengine.dll
2013-06-26 12:28 . 2013-06-26 14:02	--------	d-----w-	c:\program files (x86)\Mozilla Thunderbird
2013-06-19 06:08 . 2013-06-12 19:47	96168	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-06-12 07:49 . 2013-05-17 01:25	257536	----a-w-	c:\program files (x86)\Internet Explorer\ieproxy.dll
2013-06-11 23:28 . 2013-05-08 06:39	1910632	----a-w-	c:\windows\system32\drivers\tcpip.sys
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-12 19:48 . 2012-12-07 15:18	867240	----a-w-	c:\windows\SysWow64\npDeployJava1.dll
2013-06-12 19:48 . 2012-02-06 12:56	789416	----a-w-	c:\windows\SysWow64\deployJava1.dll
2013-06-12 15:51 . 2012-04-30 19:30	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-12 15:51 . 2012-04-30 19:30	692104	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2013-06-12 07:49 . 2012-03-24 16:57	75825640	----a-w-	c:\windows\system32\MRT.exe
2013-05-31 01:26 . 2013-05-31 01:26	1054720	----a-w-	c:\windows\system32\MsSpellCheckingFacility.exe
2013-05-31 01:26 . 2013-05-31 01:26	719360	----a-w-	c:\windows\SysWow64\mshtmlmedia.dll
2013-05-31 01:26 . 2013-05-31 01:26	523264	----a-w-	c:\windows\SysWow64\vbscript.dll
2013-05-31 01:26 . 2013-05-31 01:26	226304	----a-w-	c:\windows\system32\elshyph.dll
2013-05-31 01:26 . 2013-05-31 01:26	185344	----a-w-	c:\windows\SysWow64\elshyph.dll
2013-05-31 01:26 . 2013-05-31 01:26	158720	----a-w-	c:\windows\SysWow64\msls31.dll
2013-05-31 01:26 . 2013-05-31 01:26	150528	----a-w-	c:\windows\SysWow64\iexpress.exe
2013-05-31 01:26 . 2013-05-31 01:26	138752	----a-w-	c:\windows\SysWow64\wextract.exe
2013-05-31 01:26 . 2013-05-31 01:26	73728	----a-w-	c:\windows\SysWow64\SetIEInstalledDate.exe
2013-05-31 01:26 . 2013-05-31 01:26	61952	----a-w-	c:\windows\SysWow64\tdc.ocx
2013-05-31 01:26 . 2013-05-31 01:26	48640	----a-w-	c:\windows\SysWow64\mshtmler.dll
2013-05-31 01:26 . 2013-05-31 01:26	38400	----a-w-	c:\windows\SysWow64\imgutil.dll
2013-05-31 01:26 . 2013-05-31 01:26	361984	----a-w-	c:\windows\SysWow64\html.iec
2013-05-31 01:26 . 2013-05-31 01:26	137216	----a-w-	c:\windows\SysWow64\ieUnatt.exe
2013-05-31 01:26 . 2013-05-31 01:26	12800	----a-w-	c:\windows\SysWow64\mshta.exe
2013-05-31 01:26 . 2013-05-31 01:26	110592	----a-w-	c:\windows\SysWow64\IEAdvpack.dll
2013-05-31 01:26 . 2013-05-31 01:26	81408	----a-w-	c:\windows\system32\icardie.dll
2013-05-31 01:26 . 2013-05-31 01:26	762368	----a-w-	c:\windows\system32\ieapfltr.dll
2013-05-31 01:26 . 2013-05-31 01:26	452096	----a-w-	c:\windows\system32\dxtmsft.dll
2013-05-31 01:26 . 2013-05-31 01:26	441856	----a-w-	c:\windows\system32\html.iec
2013-05-31 01:26 . 2013-05-31 01:26	281600	----a-w-	c:\windows\system32\dxtrans.dll
2013-05-31 01:26 . 2013-05-31 01:26	23040	----a-w-	c:\windows\SysWow64\licmgr10.dll
2013-05-31 01:26 . 2013-05-31 01:26	216064	----a-w-	c:\windows\system32\msls31.dll
2013-05-31 01:26 . 2013-05-31 01:26	197120	----a-w-	c:\windows\system32\msrating.dll
2013-05-31 01:26 . 2013-05-31 01:26	1441280	----a-w-	c:\windows\SysWow64\inetcpl.cpl
2013-05-31 01:26 . 2013-05-31 01:26	1400416	----a-w-	c:\windows\system32\ieapfltr.dat
2013-05-31 01:26 . 2013-05-31 01:26	97280	----a-w-	c:\windows\system32\mshtmled.dll
2013-05-31 01:26 . 2013-05-31 01:26	92160	----a-w-	c:\windows\system32\SetIEInstalledDate.exe
2013-05-31 01:26 . 2013-05-31 01:26	905728	----a-w-	c:\windows\system32\mshtmlmedia.dll
2013-05-31 01:26 . 2013-05-31 01:26	77312	----a-w-	c:\windows\system32\tdc.ocx
2013-05-31 01:26 . 2013-05-31 01:26	62976	----a-w-	c:\windows\system32\pngfilt.dll
2013-05-31 01:26 . 2013-05-31 01:26	599552	----a-w-	c:\windows\system32\vbscript.dll
2013-05-31 01:26 . 2013-05-31 01:26	52224	----a-w-	c:\windows\system32\msfeedsbs.dll
2013-05-31 01:26 . 2013-05-31 01:26	51200	----a-w-	c:\windows\system32\imgutil.dll
2013-05-31 01:26 . 2013-05-31 01:26	48640	----a-w-	c:\windows\system32\mshtmler.dll
2013-05-31 01:26 . 2013-05-31 01:26	27648	----a-w-	c:\windows\system32\licmgr10.dll
2013-05-31 01:26 . 2013-05-31 01:26	270848	----a-w-	c:\windows\system32\iedkcs32.dll
2013-05-31 01:26 . 2013-05-31 01:26	247296	----a-w-	c:\windows\system32\webcheck.dll
2013-05-31 01:26 . 2013-05-31 01:26	235008	----a-w-	c:\windows\system32\url.dll
2013-05-31 01:26 . 2013-05-31 01:26	173568	----a-w-	c:\windows\system32\ieUnatt.exe
2013-05-31 01:26 . 2013-05-31 01:26	167424	----a-w-	c:\windows\system32\iexpress.exe
2013-05-31 01:26 . 2013-05-31 01:26	1509376	----a-w-	c:\windows\system32\inetcpl.cpl
2013-05-31 01:26 . 2013-05-31 01:26	149504	----a-w-	c:\windows\system32\occache.dll
2013-05-31 01:26 . 2013-05-31 01:26	144896	----a-w-	c:\windows\system32\wextract.exe
2013-05-31 01:26 . 2013-05-31 01:26	13824	----a-w-	c:\windows\system32\mshta.exe
2013-05-31 01:26 . 2013-05-31 01:26	136192	----a-w-	c:\windows\system32\iepeers.dll
2013-05-31 01:26 . 2013-05-31 01:26	135680	----a-w-	c:\windows\system32\IEAdvpack.dll
2013-05-31 01:26 . 2013-05-31 01:26	12800	----a-w-	c:\windows\system32\msfeedssync.exe
2013-05-31 01:26 . 2013-05-31 01:26	102912	----a-w-	c:\windows\system32\inseng.dll
2013-05-31 01:03 . 2013-05-31 01:03	9728	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	5632	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	4096	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	4096	---ha-w-	c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	3072	---ha-w-	c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	3072	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	9728	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	604160	----a-w-	c:\windows\SysWow64\d3d10level9.dll
2013-05-31 01:03 . 2013-05-31 01:03	5632	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	5632	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	5632	---ha-w-	c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	522752	----a-w-	c:\windows\system32\XpsGdiConverter.dll
2013-05-31 01:03 . 2013-05-31 01:03	465920	----a-w-	c:\windows\system32\WMPhoto.dll
2013-05-31 01:03 . 2013-05-31 01:03	417792	----a-w-	c:\windows\SysWow64\WMPhoto.dll
2013-05-31 01:03 . 2013-05-31 01:03	3928064	----a-w-	c:\windows\system32\d2d1.dll
2013-05-31 01:03 . 2013-05-31 01:03	364544	----a-w-	c:\windows\SysWow64\XpsGdiConverter.dll
2013-05-31 01:03 . 2013-05-31 01:03	363008	----a-w-	c:\windows\system32\dxgi.dll
2013-05-31 01:03 . 2013-05-31 01:03	3584	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	3584	---ha-w-	c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	3419136	----a-w-	c:\windows\SysWow64\d2d1.dll
2013-05-31 01:03 . 2013-05-31 01:03	333312	----a-w-	c:\windows\system32\d3d10_1core.dll
2013-05-31 01:03 . 2013-05-31 01:03	3072	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	3072	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	296960	----a-w-	c:\windows\system32\d3d10core.dll
2013-05-31 01:03 . 2013-05-31 01:03	2776576	----a-w-	c:\windows\system32\msmpeg2vdec.dll
2013-05-31 01:03 . 2013-05-31 01:03	2565120	----a-w-	c:\windows\system32\d3d10warp.dll
2013-05-31 01:03 . 2013-05-31 01:03	2560	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	2560	---ha-w-	c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	249856	----a-w-	c:\windows\SysWow64\d3d10_1core.dll
2013-05-31 01:03 . 2013-05-31 01:03	245248	----a-w-	c:\windows\system32\WindowsCodecsExt.dll
2013-05-31 01:03 . 2013-05-31 01:03	2284544	----a-w-	c:\windows\SysWow64\msmpeg2vdec.dll
2013-05-31 01:03 . 2013-05-31 01:03	220160	----a-w-	c:\windows\SysWow64\d3d10core.dll
2013-05-31 01:03 . 2013-05-31 01:03	207872	----a-w-	c:\windows\SysWow64\WindowsCodecsExt.dll
2013-05-31 01:03 . 2013-05-31 01:03	194560	----a-w-	c:\windows\system32\d3d10_1.dll
2013-05-31 01:03 . 2013-05-31 01:03	1682432	----a-w-	c:\windows\system32\XpsPrint.dll
2013-05-31 01:03 . 2013-05-31 01:03	1643520	----a-w-	c:\windows\system32\DWrite.dll
2013-05-31 01:03 . 2013-05-31 01:03	161792	----a-w-	c:\windows\SysWow64\d3d10_1.dll
2013-05-31 01:03 . 2013-05-31 01:03	1247744	----a-w-	c:\windows\SysWow64\DWrite.dll
2013-05-31 01:03 . 2013-05-31 01:03	1238528	----a-w-	c:\windows\system32\d3d10.dll
2013-05-31 01:03 . 2013-05-31 01:03	1175552	----a-w-	c:\windows\system32\FntCache.dll
2013-05-31 01:03 . 2013-05-31 01:03	1158144	----a-w-	c:\windows\SysWow64\XpsPrint.dll
2013-05-31 01:03 . 2013-05-31 01:03	1080832	----a-w-	c:\windows\SysWow64\d3d10.dll
2013-05-31 01:03 . 2013-05-31 01:03	10752	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	10752	---ha-w-	c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-05-31 01:03 . 2013-05-31 01:03	648192	----a-w-	c:\windows\system32\d3d10level9.dll
2013-05-31 01:03 . 2013-05-31 01:03	293376	----a-w-	c:\windows\SysWow64\dxgi.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{6B34ACCF-1B63-4E1A-8633-461917C75544}"= "c:\program files (x86)\Freecorder 6\tbcore3.dll" [2012-08-01 2711928]
.
[HKEY_CLASSES_ROOT\clsid\{6b34accf-1b63-4e1a-8633-461917c75544}]
[HKEY_CLASSES_ROOT\TBSB00808.TBSB00808.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB00808.TBSB00808]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	130736	----a-w-	c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	130736	----a-w-	c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	130736	----a-w-	c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-03-27 39408]
"HP Photosmart 5510 series (NET)"="c:\program files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" [2011-09-16 2676584]
"VoipBuster"="c:\program files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe" [2013-06-25 19378496]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-01-08 18705664]
"Spybot-S&D Cleaning"="c:\program files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" [2012-11-13 3713032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-13 283160]
"ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2011-02-15 2757312]
"PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-27 648032]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-03-24 49208]
"STO Backup Service"="c:\program files (x86)\SmarThru Office\BackUpSvr.exe" [2012-01-13 199760]
"STO Launcher Service"="c:\program files (x86)\SmarThru Office\x64\LegacyLauncher.exe" [2012-01-13 405584]
"SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2012-11-13 3825176]
"Sophos AutoUpdate Monitor"="c:\program files (x86)\Sophos\AutoUpdate\almon.exe" [2013-04-03 929272]
"PDFPrint"="c:\program files (x86)\PDF24\pdf24.exe" [2013-03-20 162856]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
c:\users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968]
OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2010-5-28 276328]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~2\sophos_detoured.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute	REG_MULTI_SZ   	autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 swi_update_64;Sophos Web Intelligence Update;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe [x]
R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
R3 btath_avdt;Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x]
R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1y60x64.sys [x]
R3 sdcfilter;sdcfilter;c:\windows\system32\DRIVERS\sdcfilter.sys;c:\windows\SYSNATIVE\DRIVERS\sdcfilter.sys [x]
R3 SOHCImp;VAIO Content Importer;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [x]
R3 SOHDs;VAIO Device Searcher;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [x]
R3 SpfService;VAIO Entertainment Common Service;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [x]
R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [x]
R3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [x]
R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys;c:\windows\SYSNATIVE\DRIVERS\SophosBootDriver.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S1 SAVOnAccess;SAVOnAccess;c:\windows\system32\DRIVERS\savonaccess.sys;c:\windows\SYSNATIVE\DRIVERS\savonaccess.sys [x]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [x]
S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe;c:\program files\Sony\VAIO Care\VCPerfService.exe [x]
S2 Samsung Network Fax Server;Samsung Network Fax Server;c:\windows\system32\spool\drivers\x64\3\NetFaxServer64.exe;c:\windows\SYSNATIVE\spool\drivers\x64\3\NetFaxServer64.exe [x]
S2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [x]
S2 SAVService;Sophos Anti-Virus;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [x]
S2 Sophos Web Control Service;Sophos Web Control Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [x]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys;c:\windows\SYSNATIVE\Drivers\SSPORT.sys [x]
S2 swi_service;Sophos Web Intelligence Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [x]
S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe;c:\program files\Sony\VAIO Smart Network\VSNService.exe [x]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftKsUFilter.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys;c:\windows\SYSNATIVE\DRIVERS\SFEP.sys [x]
S3 VCService;VCService;c:\program files\Sony\VAIO Care\VCService.exe;c:\program files\Sony\VAIO Care\VCService.exe [x]
S3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update 5\VUAgent.exe;c:\program files\Sony\VAIO Update 5\VUAgent.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt	REG_MULTI_SZ   	hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2013-07-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-30 15:51]
.
2013-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27 17:42]
.
2013-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27 17:42]
.
2013-07-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core.job
- c:\users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-04 22:53]
.
2013-07-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA.job
- c:\users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-04 22:53]
.
2013-07-03 c:\windows\Tasks\HP Photo Creations Messager.job
- c:\programdata\HP Photo Creations\MessageCheck.exe [2011-02-15 10:11]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2011-03-29 518784]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-04-29 790688]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-04-29 657568]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-29 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-29 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-29 418328]
"Apoint"="c:\program files (x86)\Apoint\Apoint.exe" [BU]
"CDAServer"="c:\program files\Common Files\Common Desktop Agent\CDASrv.exe" [2010-12-17 438784]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~2\sophos_detoured_x64.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.wikipedia.org/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\users\Daniel\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
LSP: c:\programdata\Sophos\Web Intelligence\swi_ifslsp.dll
TCP: DhcpNameServer = 192.168.178.1
TCP: Interfaces\{F6BFC1EA-082D-4450-A95B-BF5334CE4940}: NameServer = 141.2.22.74,141.2.149.10
FF - ProfilePath - c:\users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.bl.uk/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?q=
FF - ExtSQL: !HIDDEN! 2012-05-11 13:13; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
Notify-SDWinLogon - SDWinLogon.dll
WebBrowser-{6B34ACCF-1B63-4E1A-8633-461917C75544} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SampleCollector]
"ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=c:\programdata\Sony Corporation\VAIO Care\inteldata\""
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-07-03  10:30:00
ComboFix-quarantined-files.txt  2013-07-03 08:29
ComboFix2.txt  2013-07-02 17:53
.
Pre-Run: 374,696,648,704 bytes free
Post-Run: 374,614,482,944 bytes free
.
- - End Of File - - 849EECEAA11D9362AAFE6FBEF3CFEF45
D41D8CD98F00B204E9800998ECF8427E
         
Anmerkungen: Ich dachte, ich hätte Spybot vorher erfolgreich abgeschaltet gehabt. Allerdings tauchte die Meldung auf, es sei noch am Laufen. Diesmal konnte ich es aber wirklich dann ausschalten. Ich hoffe, es hat ComboFix nicht zu Fehlanalysen verleitet.

2. AdwCleaner:

Code:
ATTFilter
# AdwCleaner v2.303 - Logfile created 07/03/2013 at 10:48:46
# Updated 08/06/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Daniel - SOFERMAHIR
# Boot Mode : Normal
# Running from : C:\Users\Daniel\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\extensions\browserprotect@browserprotect.com.xpi
Folder Deleted : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB

***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com
Key Deleted : HKLM\Software\DeviceVM
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AFB904C4-C255-4540-B97E-A75A34F1FFB0}

***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16611

[OK] Registry is clean.

-\\ Mozilla Firefox v21.0 (en-US)

File : C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\prefs.js

C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\user.js ... Deleted !

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [19015 octets] - [27/03/2013 02:57:18]
AdwCleaner[R2].txt - [19135 octets] - [28/03/2013 21:41:05]
AdwCleaner[R3].txt - [19196 octets] - [28/03/2013 21:41:53]
AdwCleaner[S1].txt - [324 octets] - [27/03/2013 02:57:50]
AdwCleaner[S2].txt - [19913 octets] - [28/03/2013 21:42:02]
AdwCleaner[S3].txt - [1575 octets] - [03/07/2013 10:48:46]

########## EOF - C:\AdwCleaner[S3].txt - [1635 octets] ##########
         
3. JRT.txt:

Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 7 Home Premium x64
Ran by Daniel on 03/07/2013 at 11:11:08.86
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\\URL



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\Daniel\appdata\local\{3B5F6094-95AD-4B35-B413-E16D39E0C013}
Successfully deleted: [Empty Folder] C:\Users\Daniel\appdata\local\{46567E52-EAB1-4414-9BCD-43C6348F99C8}
Successfully deleted: [Empty Folder] C:\Users\Daniel\appdata\local\{5E521E1D-8E66-4E99-A05E-178569C823AC}
Successfully deleted: [Empty Folder] C:\Users\Daniel\appdata\local\{82B199CB-9F19-41FA-A999-6E26721021F6}
Successfully deleted: [Empty Folder] C:\Users\Daniel\appdata\local\{B636F192-E4D2-4279-848E-BBD2F30B56B0}
Successfully deleted: [Empty Folder] C:\Users\Daniel\appdata\local\{F3B2E688-FFDD-4715-8118-48FC49BB049C}



~~~ FireFox

Emptied folder: C:\Users\Daniel\AppData\Roaming\mozilla\firefox\profiles\16xncyrs.default\minidumps [187 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03/07/2013 at 11:16:25.72
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
4. Eset log:

Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=b8f46c7edbe67b4aa18d407f31e20020
# engine=14244
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-07-03 05:42:46
# local_time=2013-07-03 07:42:46 (+0100, W. Europe Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 34448 124503216 0 0
# compatibility_mode=8450 16777213 85 99 29323 7897465 0 0
# scanned=269401
# found=2
# cleaned=0
# scan_time=28857
sh=15133AE329D0B132CC4DD7A19DBAA4648A0E4DFC ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\6bddbdd6-50147857"
sh=6D349F0A3BAEDE0999E5744595E97291BE26ABC6 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-401bb4c0"
         
Anmerkung: der Scan hat fast 9 Stunden gedauert. Allerdings hatte ich 2 USB Stick, eine externe HD und einen USB-Musikhörer dran.

5: checkup.txt:

Code:
ATTFilter
 Results of screen317's Security Check version 0.99.68  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 10  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
 Windows Firewall Disabled!  
Sophos Anti-Virus   
 WMI entry may not exist for antivirus; attempting automatic update. 
`````````Anti-malware/Other Utilities Check:````````` 
 Spybot - Search & Destroy 
 Java(TM) 6 Update 22  
 Java 7 Update 25  
 Adobe Flash Player 11.7.700.224  
 Adobe Reader 10.1.7 Adobe Reader out of Date!  
 Mozilla Firefox 21.0 Firefox out of Date!  
 Mozilla Thunderbird (17.0.7) 
````````Process Check: objlist.exe by Laurent````````  
 Spybot Teatimer.exe is disabled! 
 Sophos Sophos Anti-Virus SavService.exe  
 Sophos Sophos Anti-Virus SAVAdminService.exe  
 Sophos Sophos Anti-Virus Web Control swc_service.exe 
 Sophos Sophos Anti-Virus Web Intelligence swi_service.exe 
 Sophos Sophos Anti-Virus SavMain.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 0% 
````````````````````End of Log``````````````````````
         
6.: und noch das neues FRST:


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-07-2013
Ran by Daniel (administrator) on 03-07-2013 21:19:00
Running from C:\Users\Daniel\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Sony Corporation) c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe
(Samsung Electronics Co., Ltd.) C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe
(VoipBuster) C:\Program Files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apntex.exe
(ALPS) C:\Program Files\Apoint\Apvfb.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SmarThru Office\BackUpSvr.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SmarThru Office\x64\LegacyLauncher.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Dropbox, Inc.) C:\Users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavMain.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update 5\VUAgent.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\Admload.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicator.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [518784 2011-03-29] (Conexant Systems, Inc.)
HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [790688 2011-04-29] (Atheros Commnucations)
HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [657568 2011-04-29] (Atheros Commnucations)
HKLM\...\Run: [Apoint] %ProgramFiles%\Apoint\Apoint.exe [226672 2011-02-17] (Alps Electric Co., Ltd.)
HKLM\...\Run: [CDAServer] C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [438784 2010-12-17] ()
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-03-27] (Google Inc.)
HKCU\...\Run: [HP Photosmart 5510 series (NET)] "C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN175050KX05NR:NW" -scfn "HP Photosmart 5510 series (NET)" -AutoStart 1 [2676584 2011-09-16] (Hewlett-Packard Co.)
HKCU\...\Run: [VoipBuster] "C:\Program Files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe" -nosplash -minimized [19378496 2013-06-25] (VoipBuster)
HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18705664 2013-01-08] (Skype Technologies S.A.)
HKCU\...\Run: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean [3713032 2012-11-13] (Safer-Networking Ltd.)
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [2757312 2011-02-15] (Sony Corporation)
HKLM-x32\...\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)
HKLM-x32\...\Run: []  [x]
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard)
HKLM-x32\...\Run: [STO Backup Service] C:\Program Files (x86)\SmarThru Office\BackUpSvr.exe [199760 2012-01-13] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [STO Launcher Service] C:\Program Files (x86)\SmarThru Office\x64\LegacyLauncher.exe /autorun [405584 2012-01-13] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [929272 2013-04-03] (Sophos Limited)
HKLM-x32\...\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~2\sophos_detoured_x64.dll [218256 2013-04-03] (Sophos Limited)
AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~2\sophos_detoured.dll [221840 2013-04-03] (Sophos Limited)
Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.wikipedia.org/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKCU - {623BD34C-6486-4770-B994-92555203C850} URL = hxxp://rover.ebay.com/rover/1/710-42480-16445-33/4?mpre=hxxp://shop.ebay.co.uk/?oemInLn=ieSrch-Q311&_nkw={searchTerms}
SearchScopes: HKCU - {8C1B1A63-658F-4F07-BDC0-B7765C458695} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Freecorder 6 - {6B34ACCF-1B63-4E1A-8633-461917C75544} - C:\Program Files (x86)\Freecorder 6\tbcore3.dll ()
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {6B34ACCF-1B63-4E1A-8633-461917C75544} -  No File
DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 20 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 20 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{F6BFC1EA-082D-4450-A95B-BF5334CE4940}: [NameServer]141.2.22.74,141.2.149.10

FireFox:
========
FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default
FF NewTab: www.bl.uk
FF SearchEngine: Google
FF Homepage: hxxp://www.bl.uk/
FF Keyword.URL: hxxp://www.google.com/search?q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF Extension: Visualisateur 3D de 20-20 - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\2020Player_IKEA@2020Technologies.com
FF Extension: Deutsches W?rterbuch - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\de-DE@dictionaries.addons.mozilla.org
FF Extension: Freecorder 6 - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{132E58DE-22BF-44CA-A061-7FCE1E8BA1EC}
FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.xpi
FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{e8f509f0-b677-11de-8a39-0800200c9a66}.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: SmartPrintButton - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: <?xml version="1.0"?>

<RDF xmlns="hxxp://www.w3.org/1999/02/22-rdf-syntax-ns#"
     xmlns:em="hxxp://www.mozilla.org/2004/em-rdf#">
  <Description about="urn:mozilla:install-manifest">
    <em:id>smartwebprinting@hp.com</em:id>
    <em:version>4.60</em:version>

    <em:targetApplication>
      <!-- Firefox -->
      <Description>
        <em:id>{ec8030f7-c20a-464f-9b0e-13a3a9e97384}</em:id>
        <em:minVersion>3.5.0.0</em:minVersion>
        <em:maxVersion>3.5.*.*</em:maxVersion>
      </Description>
    </em:targetApplication>

    <!-- front-end metadata -->
    <em:name>HP Smart Web Printing</em:name>
    <em:description>Print what you want, how you want.</em:description>
    <em:creator>hp.com</em:creator>
    <em:homepageURL>hxxp://www.hp.com/go/smartwebprinting</em:homepageURL>
    
    <em:aboutURL>chrome://hpsmartwebprinting/content/about.xul</em:aboutURL>
    <em:iconURL>chrome://hpsmartwebprinting/skin/toolbar-icon-normal-24.png</em:iconURL>
    <em:targetPlatform>WINNT_x86-msvc</em:targetPlatform>
  </Description>
</RDF>
 - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: <?xml version="1.0"?>

<RDF xmlns="hxxp://www.w3.org/1999/02/22-rdf-syntax-ns#"
     xmlns:em="hxxp://www.mozilla.org/2004/em-rdf#">
  <Description about="urn:mozilla:install-manifest">
    <em:id>smartwebprinting@hp.com</em:id>
    <em:version>4.60</em:version>

    <em:targetApplication>
      <!-- Firefox -->
      <Description>
        <em:id>{ec8030f7-c20a-464f-9b0e-13a3a9e97384}</em:id>
        <em:minVersion>3.5.0.0</em:minVersion>
        <em:maxVersion>3.5.*.*</em:maxVersion>
      </Description>
    </em:targetApplication>

    <!-- front-end metadata -->
    <em:name>HP Smart Web Printing</em:name>
    <em:description>Print what you want, how you want.</em:description>
    <em:creator>hp.com</em:creator>
    <em:homepageURL>hxxp://www.hp.com/go/smartwebprinting</em:homepageURL>
    
    <em:aboutURL>chrome://hpsmartwebprinting/content/about.xul</em:aboutURL>
    <em:iconURL>chrome://hpsmartwebprinting/skin/toolbar-icon-normal-24.png</em:iconURL>
    <em:targetPlatform>WINNT_x86-msvc</em:targetPlatform>
  </Description>
</RDF>
 - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

==================== Services (Whitelisted) =================

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-04-29] (Atheros)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation)
R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe [231936 2012-03-22] (Samsung Electronics Co., Ltd.)
R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [217592 2013-04-03] (Sophos Limited)
R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [159296 2013-04-03] (Sophos Limited)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [237048 2013-04-03] (Sophos Limited)
R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [357400 2013-04-03] (Sophos Limited)
R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2890232 2013-04-03] (Sophos Limited)
S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2010688 2013-04-03] (Sophos Limited)
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.)
R3 VUAgent; C:\Program Files\Sony\VAIO Update 5\VUAgent.exe [1021112 2011-03-30] (Sony Corporation)

==================== Drivers (Whitelisted) ====================

R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [154952 2013-04-03] (Sophos Limited)
S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [36640 2013-04-03] (Sophos Limited)
S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [25608 2013-04-03] (Sophos Plc)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-03 21:17 - 2013-07-03 21:17 - 00001294 ____A C:\Users\Daniel\Desktop\checkup.txt
2013-07-03 21:09 - 2013-07-03 21:09 - 00890988 ____A C:\Users\Daniel\Desktop\SecurityCheck.exe
2013-07-03 11:30 - 2013-07-03 11:30 - 02347384 ____A (ESET) C:\Users\Daniel\Desktop\esetsmartinstaller_enu.exe
2013-07-03 11:16 - 2013-07-03 11:16 - 00001722 ____A C:\Users\Daniel\Desktop\JRT.txt
2013-07-03 11:11 - 2013-07-03 11:11 - 00000000 ____D C:\Windows\ERUNT
2013-07-03 11:11 - 2013-07-03 11:11 - 00000000 ____D C:\JRT
2013-07-03 11:08 - 2013-07-03 11:09 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Daniel\Desktop\JRT.exe
2013-07-03 10:50 - 2013-07-03 10:50 - 00000988 ____A C:\Windows\PFRO.log
2013-07-03 10:48 - 2013-07-03 10:48 - 00001704 ____A C:\AdwCleaner[S3].txt
2013-07-03 10:44 - 2013-07-03 10:45 - 00648201 ____A C:\Users\Daniel\Desktop\adwcleaner.exe
2013-07-03 10:30 - 2013-07-03 10:30 - 00034657 ____A C:\ComboFix.txt
2013-07-03 10:22 - 2013-07-03 10:30 - 00000000 ____D C:\ComboFix
2013-07-03 10:04 - 2013-07-03 10:05 - 05084414 ____R (Swearware) C:\Users\Daniel\Desktop\ComboFix.exe
2013-07-02 20:03 - 2013-07-02 19:53 - 00035060 ____A C:\Users\Daniel\Desktop\ComboFix.txt
2013-07-02 19:45 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe
2013-07-02 19:45 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe
2013-07-02 19:45 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2013-07-02 19:45 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2013-07-02 19:45 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2013-07-02 19:45 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe
2013-07-02 19:45 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe
2013-07-02 19:45 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe
2013-07-02 19:40 - 2013-07-03 10:30 - 00000000 ____D C:\Qoobox
2013-07-02 19:40 - 2013-07-02 19:51 - 00000000 ____D C:\Windows\erdnt
2013-07-02 17:49 - 2013-07-02 17:50 - 00031125 ____A C:\Users\Daniel\Desktop\Addition.txt
2013-07-02 17:48 - 2013-07-02 17:48 - 00000000 ____D C:\FRST
2013-07-02 17:44 - 2013-07-02 17:44 - 01933556 ____A (Farbar) C:\Users\Daniel\Desktop\FRST64.exe
2013-07-02 17:06 - 2013-07-02 17:07 - 00000474 ____A C:\Users\Daniel\Desktop\defogger_disable.log
2013-07-02 17:06 - 2013-07-02 17:06 - 00000000 ____A C:\Users\Daniel\defogger_reenable
2013-07-02 17:04 - 2013-07-02 17:04 - 00050477 ____A C:\Users\Daniel\Desktop\Defogger.exe
2013-07-02 16:04 - 2013-07-02 16:04 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-07-02 16:02 - 2013-07-02 16:03 - 04396440 ____A (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup403.exe
2013-07-01 15:40 - 2013-07-01 15:47 - 00001434 ____A C:\Users\Daniel\Downloads\Antrag auf Ausstellung einer Bescheinigung für den Lohnsteuerabzug 2013.xml
2013-06-26 14:28 - 2013-06-26 16:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-06-25 14:34 - 2013-06-25 14:34 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk
2013-06-21 11:47 - 2013-06-21 11:47 - 00150406 ____A C:\Users\Daniel\Documents\1662.ppsx
2013-06-19 08:08 - 2013-06-12 21:47 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-19 08:08 - 2013-06-12 21:43 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-19 08:08 - 2013-06-12 21:43 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-19 08:07 - 2013-06-19 08:08 - 00004802 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log
2013-06-19 08:07 - 2013-06-12 21:43 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-17 23:38 - 2013-06-17 23:42 - 00084339 ____A C:\Users\Daniel\Desktop\Briefvorlage-Birnstiel.dotx
2013-06-16 12:36 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-16 12:36 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-16 12:36 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-16 12:36 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-16 12:36 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-16 12:36 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-16 12:36 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-16 12:36 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-16 12:36 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-16 12:36 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-16 12:36 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-16 12:36 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-14 10:17 - 2013-06-20 15:13 - 00016101 ____A C:\Users\Daniel\Documents\Korrespondenztabelle.xlsx
2013-06-12 17:54 - 2013-06-20 10:32 - 00011854 ____A C:\Users\Daniel\Desktop\PruefungstermineSoSe2013.xlsx
2013-06-12 09:49 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-12 09:49 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 09:49 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-12 09:49 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-12 09:49 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-12 09:49 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-12 01:28 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-12 01:28 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-12 01:28 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-12 01:28 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-12 01:28 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-12 01:28 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-12 01:28 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-12 01:28 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-12 01:28 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-12 01:28 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-12 01:28 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 01:28 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 01:28 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-12 01:28 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 01:28 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-12 01:28 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-12 01:28 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-12 01:28 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-12 01:28 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-06-11 22:38 - 2013-07-03 12:40 - 00010012 ____A C:\Windows\setupact.log
2013-06-11 22:38 - 2013-06-11 22:38 - 00000000 ____A C:\Windows\setuperr.log
2013-06-11 15:06 - 2013-06-11 15:06 - 00000165 ___AH C:\Users\Daniel\Desktop\~$pruefungen.xlsx
2013-06-10 18:25 - 2013-06-13 10:16 - 00012345 ____A C:\Users\Daniel\Desktop\pruefungen.xlsx
2013-06-10 16:58 - 2013-06-10 16:58 - 00000000 ____D C:\Users\Daniel\Documents\maiko_doc

==================== One Month Modified Files and Folders =======

2013-07-03 21:17 - 2013-07-03 21:17 - 00001294 ____A C:\Users\Daniel\Desktop\checkup.txt
2013-07-03 21:16 - 2012-04-04 15:20 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA.job
2013-07-03 21:10 - 2012-02-06 14:45 - 01726655 ____A C:\Windows\WindowsUpdate.log
2013-07-03 21:09 - 2013-07-03 21:09 - 00890988 ____A C:\Users\Daniel\Desktop\SecurityCheck.exe
2013-07-03 21:01 - 2012-04-06 15:34 - 00000258 ____A C:\Windows\Tasks\HP Photo Creations Messager.job
2013-07-03 20:51 - 2013-01-21 11:26 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-03 20:39 - 2012-03-27 19:43 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-03 12:40 - 2013-06-11 22:38 - 00010012 ____A C:\Windows\setupact.log
2013-07-03 11:36 - 2009-07-14 07:13 - 00778834 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-03 11:35 - 2009-07-14 06:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-03 11:35 - 2009-07-14 06:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-03 11:30 - 2013-07-03 11:30 - 02347384 ____A (ESET) C:\Users\Daniel\Desktop\esetsmartinstaller_enu.exe
2013-07-03 11:30 - 2012-04-15 21:33 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Skype
2013-07-03 11:30 - 2012-03-26 15:06 - 00000000 ___RD C:\Users\Daniel\Dropbox
2013-07-03 11:30 - 2012-03-26 14:58 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Dropbox
2013-07-03 11:27 - 2012-03-27 19:43 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-03 11:27 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-03 11:16 - 2013-07-03 11:16 - 00001722 ____A C:\Users\Daniel\Desktop\JRT.txt
2013-07-03 11:11 - 2013-07-03 11:11 - 00000000 ____D C:\Windows\ERUNT
2013-07-03 11:11 - 2013-07-03 11:11 - 00000000 ____D C:\JRT
2013-07-03 11:09 - 2013-07-03 11:08 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Daniel\Desktop\JRT.exe
2013-07-03 10:50 - 2013-07-03 10:50 - 00000988 ____A C:\Windows\PFRO.log
2013-07-03 10:48 - 2013-07-03 10:48 - 00001704 ____A C:\AdwCleaner[S3].txt
2013-07-03 10:45 - 2013-07-03 10:44 - 00648201 ____A C:\Users\Daniel\Desktop\adwcleaner.exe
2013-07-03 10:30 - 2013-07-03 10:30 - 00034657 ____A C:\ComboFix.txt
2013-07-03 10:30 - 2013-07-03 10:22 - 00000000 ____D C:\ComboFix
2013-07-03 10:30 - 2013-07-02 19:40 - 00000000 ____D C:\Qoobox
2013-07-03 10:27 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini
2013-07-03 10:22 - 2013-03-28 21:55 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-07-03 10:05 - 2013-07-03 10:04 - 05084414 ____R (Swearware) C:\Users\Daniel\Desktop\ComboFix.exe
2013-07-03 06:16 - 2012-04-04 15:20 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core.job
2013-07-02 19:53 - 2013-07-02 20:03 - 00035060 ____A C:\Users\Daniel\Desktop\ComboFix.txt
2013-07-02 19:53 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default
2013-07-02 19:51 - 2013-07-02 19:40 - 00000000 ____D C:\Windows\erdnt
2013-07-02 17:50 - 2013-07-02 17:49 - 00031125 ____A C:\Users\Daniel\Desktop\Addition.txt
2013-07-02 17:48 - 2013-07-02 17:48 - 00000000 ____D C:\FRST
2013-07-02 17:44 - 2013-07-02 17:44 - 01933556 ____A (Farbar) C:\Users\Daniel\Desktop\FRST64.exe
2013-07-02 17:07 - 2013-07-02 17:06 - 00000474 ____A C:\Users\Daniel\Desktop\defogger_disable.log
2013-07-02 17:06 - 2013-07-02 17:06 - 00000000 ____A C:\Users\Daniel\defogger_reenable
2013-07-02 17:06 - 2012-03-12 21:09 - 00000000 ____D C:\users\Daniel
2013-07-02 17:04 - 2013-07-02 17:04 - 00050477 ____A C:\Users\Daniel\Desktop\Defogger.exe
2013-07-02 16:04 - 2013-07-02 16:04 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-07-02 16:03 - 2013-07-02 16:02 - 04396440 ____A (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup403.exe
2013-07-02 16:03 - 2012-06-13 23:11 - 00000000 ____D C:\Program Files\CCleaner
2013-07-02 15:42 - 2013-05-02 00:35 - 00000000 ____D C:\Users\Daniel\Documents\shamela-r1
2013-07-02 15:42 - 2012-03-29 01:43 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\shamela
2013-07-01 15:47 - 2013-07-01 15:40 - 00001434 ____A C:\Users\Daniel\Downloads\Antrag auf Ausstellung einer Bescheinigung für den Lohnsteuerabzug 2013.xml
2013-07-01 13:47 - 2012-03-25 16:55 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps
2013-06-28 16:48 - 2012-03-24 20:21 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Mozilla
2013-06-28 12:30 - 2013-02-22 22:33 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\vlc
2013-06-28 12:11 - 2012-11-22 16:29 - 00000099 ____A C:\Users\Public\LMDebug.log
2013-06-27 08:44 - 2013-05-28 12:59 - 00177947 ____A C:\test.xml
2013-06-26 17:33 - 2012-04-24 23:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-06-26 16:02 - 2013-06-26 14:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-06-26 13:54 - 2012-04-26 19:34 - 00000000 ____D C:\Users\Daniel\Documents\Citavi 3
2013-06-26 00:00 - 2012-07-25 18:26 - 00000000 ____D C:\Users\Daniel\Documents\Calibre Library
2013-06-25 14:34 - 2013-06-25 14:34 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk
2013-06-25 09:17 - 2012-03-27 19:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\Google
2013-06-21 16:32 - 2012-07-07 22:14 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\dvdcss
2013-06-21 11:47 - 2013-06-21 11:47 - 00150406 ____A C:\Users\Daniel\Documents\1662.ppsx
2013-06-20 15:13 - 2013-06-14 10:17 - 00016101 ____A C:\Users\Daniel\Documents\Korrespondenztabelle.xlsx
2013-06-20 14:30 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF
2013-06-20 10:32 - 2013-06-12 17:54 - 00011854 ____A C:\Users\Daniel\Desktop\PruefungstermineSoSe2013.xlsx
2013-06-19 08:08 - 2013-06-19 08:07 - 00004802 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log
2013-06-19 08:08 - 2012-02-06 14:56 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-17 23:42 - 2013-06-17 23:38 - 00084339 ____A C:\Users\Daniel\Desktop\Briefvorlage-Birnstiel.dotx
2013-06-15 13:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-06-13 10:16 - 2013-06-10 18:25 - 00012345 ____A C:\Users\Daniel\Desktop\pruefungen.xlsx
2013-06-12 21:48 - 2012-12-07 17:18 - 00867240 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-06-12 21:48 - 2012-02-06 14:56 - 00789416 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-06-12 21:47 - 2013-06-19 08:08 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-12 21:43 - 2013-06-19 08:08 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-12 21:43 - 2013-06-19 08:08 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-12 21:43 - 2013-06-19 08:07 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-12 17:51 - 2012-04-30 21:30 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-12 17:51 - 2012-04-30 21:30 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-12 12:44 - 2011-02-11 00:48 - 00000000 ____D C:\Windows\Panther
2013-06-12 09:49 - 2012-03-24 18:57 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-11 22:38 - 2013-06-11 22:38 - 00000000 ____A C:\Windows\setuperr.log
2013-06-11 20:26 - 2009-07-14 07:08 - 00032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-11 15:06 - 2013-06-11 15:06 - 00000165 ___AH C:\Users\Daniel\Desktop\~$pruefungen.xlsx
2013-06-10 16:58 - 2013-06-10 16:58 - 00000000 ____D C:\Users\Daniel\Documents\maiko_doc
2013-06-08 16:08 - 2013-06-16 12:36 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-08 16:07 - 2013-06-16 12:36 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-08 16:06 - 2013-06-16 12:36 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-08 16:06 - 2013-06-16 12:36 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-08 16:06 - 2013-06-16 12:36 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-08 14:28 - 2013-06-16 12:36 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-08 13:42 - 2013-06-16 12:36 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-08 13:40 - 2013-06-16 12:36 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-08 13:40 - 2013-06-16 12:36 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-08 13:40 - 2013-06-16 12:36 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-08 13:40 - 2013-06-16 12:36 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-08 13:13 - 2013-06-16 12:36 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-07 23:02 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries
2013-06-07 09:58 - 2012-02-06 14:44 - 00000000 ____D C:\ProgramData\Sony Corporation

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-03 20:07

==================== End Of Log ============================
         
--- --- ---


3 Anmerkungen noch:

* Teilweise has Sophos beim Runterladen der Scanner auf den Desktop zunächst den Zugriff auf die Seite verweigert - dort sei Spyware. Die Meldung war:

"Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe""

* Mittendrin, als ich so weit ich weiss auf keinen anderen Seiten als Trojanerbord online war, schlug Sophos Alarm und packte ein "NirCmd" in Quarantäne. Deklariert es als Adware oder PUA

* Ebenso meldete Sophos (ich glaube ich las Nachrichten online) "Virus/spyware 'Mal/ExpJS-BE' has been detected at "ccgpqtrnqhjoid.servebbs.net/acjcjlgky"

Kann es sein, dass Sophos etwas überreagiert?

Wie sollte ich nach der Reinigung meinen PC am Besten warten?

Vielen Dank schon mal im Voraus,
beste Grüße,

Piristibulus

Alt 03.07.2013, 20:52   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Ja das sind alles Fehlmeldungen über unsere Tools. Die müssen ähnlich wie Malware arbeiten um sie entfernen zu können, daher die Erkennung

Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop.
Schließe nun alle offenen Programme und trenne Dich von dem Internet.
Doppelklick auf die TFC.exe und drücke auf Start.
Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen.


Fertig

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.


Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 04.07.2013, 21:31   #9
Piristibulus
 
Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Hallo Schrauber,

vielen Dank.
Das hat alles wunderbar gefunzt. Hier nur vorsorglich noch einmal das log von DelFix:

Code:
ATTFilter
# DelFix v10.3 - Logfile created 04/07/2013 at 18:28:59
# Updated 08/06/2013 by Xplode
# Username : Daniel - SOFERMAHIR
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Activating UAC ... OK

~ Removing disinfection tools ...

Deleted : C:\Qoobox
Deleted : C:\JRT
Deleted : C:\Combofix
Deleted : C:\FRST
Deleted : C:\AdwCleaner[R1].txt
Deleted : C:\AdwCleaner[R2].txt
Deleted : C:\AdwCleaner[R3].txt
Deleted : C:\AdwCleaner[S1].txt
Deleted : C:\AdwCleaner[S2].txt
Deleted : C:\AdwCleaner[S3].txt
Deleted : C:\ComboFix.txt
Deleted : C:\Users\Daniel\Desktop\adwcleaner.exe
Deleted : C:\Users\Daniel\Desktop\ComboFix.txt
Deleted : C:\Users\Daniel\Desktop\Defogger.exe
Deleted : C:\Users\Daniel\Desktop\defogger_disable.log
Deleted : C:\Users\Daniel\Desktop\defogger_enable.log
Deleted : C:\Users\Daniel\Desktop\esetsmartinstaller_enu.exe
Deleted : C:\Users\Daniel\Desktop\FRST.txt
Deleted : C:\Users\Daniel\Desktop\FRST64.exe
Deleted : C:\Users\Daniel\Desktop\JRT.txt
Deleted : C:\Users\Daniel\Desktop\SecurityCheck.exe
Deleted : C:\Users\Daniel\Desktop\TFC.exe
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware

~ Creating registry backup ... OK

~ Cleaning system restore ...


New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########
         
Das System funktioniert wieder voll. Habe auch schon Sophos abgedated und Windows updates gleich auf den neuesten Stand gebracht, wollte damit nicht bis zum nächtlichen täglichen automatischen Termin warten.

Ich habe jetzt nur noch ein paar Fragen:

* Ist Sophos ein gutes Antivir-programm oder soll ich mich lieber nach einem anderen Virenscanner umsehen?
* Firewall: Genügt die von Windows?
*Windows Defender - laufen lassen oder abschalten?
* Ich habe auch SpyBot Search & Destroy - soll ich das entfernen oder funktioniert das gut mit Malwarebytes zusammen?
* Ich verwende ccleaner - soll ich es behalten oder durch TFC ersetzen?
* TFC verwende ich als reguläres Programm genauso wie oben beschrieben?

Vielen lieben Dank und beste Grüße,

Pristibulus

Alt 05.07.2013, 07:44   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Zitat:
Ist Sophos ein gutes Antivir-programm oder soll ich mich lieber nach einem anderen Virenscanner umsehen?
* Firewall: Genügt die von Windows?
*Windows Defender - laufen lassen oder abschalten?
Win Firewall und Sophos i.o., wenn Sophos Defender nicht von alleine abschaltet lass ihn laufen.
Zitat:
Ich habe auch SpyBot Search & Destroy - soll ich das entfernen oder funktioniert das gut mit Malwarebytes zusammen?
* Ich verwende ccleaner - soll ich es behalten oder durch TFC ersetzen?
* TFC verwende ich als reguläres Programm genauso wie oben beschrieben?
Spybot und CCleaner weg, dafür TFC
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.07.2013, 07:34   #11
Piristibulus
 
Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Lieber Schrauber,

vielen Dank.

Ich war leider das Wochenende über mit einem Workshop beschäftigt und bin erst gestern dazu gekommen, die Ratschläge zu implementieren.

Allerdings - und da hatte ich nur Thunderbird und einige Uniwebseiten sowie das Trojanerbord offen - meinte der PC auf einmal er müsse wegen eines Fehlers neustarten.

Ich habe danach sofort Sophos laufen lassen, der hat nichts gefunden.
Aber der Windows Action Center erzählte mir auf einmal er habe den "Win32/Small.CA" gefunden. Gesehen hab ich die Message erst am Nachmittag, nochmal Sophos laufen lassen.

Kann es sein, dass das einfach ein Fehlalarm ist?

Vielen Dank und liebe Grüße,

Piristibulus

Alt 09.07.2013, 08:18   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Zeig mal bitte das Log bzw die komplette Meldung.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.07.2013, 08:37   #13
Piristibulus
 
Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Hallo,

vielen Dank für die Hilfe.
Die Meldung ist nur noch im Archiv des Action-Centers zugänglich:

Code:
ATTFilter
Remove the Win32/Small.CA virus from your PC
This problem was caused by Win32/Small.CA, a known computer virus.
         
Beste Grüße,
Piristibulus

Alt 09.07.2013, 08:38   #14
schrauber
/// the machine
/// TB-Ausbilder
 

Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Sehr aussagekräftig

Lass Dein AV mal nen Vollscan machen, poste das Logfile.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.07.2013, 09:26   #15
Piristibulus
 
Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Alles klar.
Hier ist das log von Sophos. Ich fürchte, evtl. auch nicht sehr aussagekräftig. Gefunden hat er wohl nichts:

Code:
ATTFilter
****************** Sophos Anti-Virus Log - 09/07/2013 08:24:28 **************

20130701 044536	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130701 044537	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197478 items.
20130701 044537	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130701 054528	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130701 054529	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197488 items.
20130701 054529	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130701 110323	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130701 110324	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197502 items.
20130701 110324	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130701 111337	File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-1dfd901e-temp" belongs to virus/spyware 'Troj/EncProc-K'.
20130701 111337	On-access scanner has denied access to location "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-1dfd901e-temp" for user SoferMahir\Daniel
20130701 111348	File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-1dfd901e-temp" belongs to virus/spyware 'Troj/EncProc-K'.
20130701 111353	File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-1dfd901e-temp" has been cleaned up.
20130701 111353	Virus/spyware 'Troj/EncProc-K' has been removed.
20130701 120311	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130701 120312	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197518 items.
20130701 120312	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130701 204258	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130701 204259	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197533 items.
20130701 204259	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130702 043908	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130702 043909	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197556 items.
20130702 043909	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130702 084347	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130702 084348	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197562 items.
20130702 084348	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130702 114717	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197562 items.
20130702 114717	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130702 134021	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197562 items.
20130702 134021	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130702 135745	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197562 items.
20130702 135746	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130702 141320	Scan 'Scan my computer' started.
20130702 141410	Virus/spyware 'Troj/ZbotMem-B' has been detected in "User Memory".
20130702 141410	'Troj/ZbotMem-B' must be cleaned up before scan can continue.
20130702 141410	Scan 'Scan my computer' aborted.
20130702 141410	Summary of results for scan 'Scan my computer':
		Items scanned: 2
		Errors: 1
		Items quarantined: 1
		Items dealt with: 0
20130702 150319	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130702 150320	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197568 items.
20130702 150320	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130702 151532	Scan 'Scan my computer' started.
20130702 151624	Virus/spyware 'Troj/ZbotMem-B' has been detected in "User Memory".
20130702 151624	'Troj/ZbotMem-B' must be cleaned up before scan can continue.
20130702 151624	Scan 'Scan my computer' aborted.
20130702 151624	Summary of results for scan 'Scan my computer':
		Items scanned: 2
		Errors: 1
		Items quarantined: 1
		Items dealt with: 0
20130702 154246	Blocked web request to "www.newzipopenerfun.com/gb/sag" (linked from "filepony.de/download-frst64/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 143200617.
20130702 154315	Blocked web request to "www.newzipopenerfun.com/gb/sab" (linked from "filepony.de/download-frst64/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 143200617.
20130702 170307	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130702 170307	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197600 items.
20130702 170307	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130702 173545	The automatic sending of file data for Sophos Live Protection is disabled.
20130702 173619	User (SoferMahir\Daniel) has stopped on-access scanning for this machine.
20130702 175417	User (SoferMahir\Daniel) has started on-access scanning for this machine.
20130702 175445	The automatic sending of file data for Sophos Live Protection is enabled.
20130702 192311	File "C:\Windows\NIRCMD.exe" belongs to adware or PUA 'NirCmd' (of type 5).
20130702 192311	On-access scanner has denied access to location "C:\Windows\NIRCMD.exe" for user NT AUTHORITY\SYSTEM
20130702 200306	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130702 200306	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197613 items.
20130702 200306	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130703 034945	Access to location "ccgpqtrnqhjoid.servebbs.net/acjcjlgky" was blocked for user SoferMahir\Daniel
20130703 034945	Virus/spyware 'Mal/ExpJS-BE' has been detected at "ccgpqtrnqhjoid.servebbs.net/acjcjlgky"
20130703 075650	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130703 075651	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197634 items.
20130703 075651	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130703 080653	User (SoferMahir\Daniel) has stopped on-access scanning for this machine.
20130703 080722	The automatic sending of file data for Sophos Live Protection is disabled.
20130703 084151	User (SoferMahir\Daniel) has started on-access scanning for this machine.
20130703 084216	The automatic sending of file data for Sophos Live Protection is enabled.
20130703 084400	Blocked web request to "general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner" (linked from "filepony.de/download-adwcleaner/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/Generic-L' has been found at this website, reference ID 112325898.
20130703 084616	User (SoferMahir\Daniel) has stopped on-access scanning for this machine.
20130703 084629	The automatic sending of file data for Sophos Live Protection is disabled.
20130703 085038	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197634 items.
20130703 085039	User (NT AUTHORITY\LOCAL SERVICE) has stopped on-access scanning for this machine.
20130703 085747	User (SoferMahir\Daniel) has started on-access scanning for this machine.
20130703 085804	The automatic sending of file data for Sophos Live Protection is enabled.
20130703 090233	User (SoferMahir\Daniel) has stopped on-access scanning for this machine.
20130703 090246	User (SoferMahir\Daniel) has started on-access scanning for this machine.
20130703 090425	Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel
20130703 090425	Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe"
20130703 090439	Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel
20130703 090439	Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe"
20130703 090505	Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel
20130703 090505	Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe"
20130703 090517	Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel
20130703 090517	Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe"
20130703 090551	Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel
20130703 090551	Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe"
20130703 090616	Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel
20130703 090616	Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe"
20130703 090631	Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel
20130703 090631	Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe"
20130703 090657	Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel
20130703 090657	Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe"
20130703 090837	User (SoferMahir\Daniel) has stopped on-access scanning for this machine.
20130703 091024	The automatic sending of file data for Sophos Live Protection is disabled.
20130703 092305	User (SoferMahir\Daniel) has started on-access scanning for this machine.
20130703 092741	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197634 items.
20130703 092741	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130703 092935	The automatic sending of file data for Sophos Live Protection is enabled.
20130703 093403	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130703 093403	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197644 items.
20130703 093403	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130703 093626	The automatic sending of file data for Sophos Live Protection is disabled.
20130703 093656	User (SoferMahir\Daniel) has stopped on-access scanning for this machine.
20130703 124007	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197662 items.
20130703 164008	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197672 items.
20130703 190147	User (SoferMahir\Daniel) has started on-access scanning for this machine.
20130703 190210	The automatic sending of file data for Sophos Live Protection is enabled.
20130703 191027	User (SoferMahir\Daniel) has stopped on-access scanning for this machine.
20130703 191044	The automatic sending of file data for Sophos Live Protection is disabled.
20130703 192100	The automatic sending of file data for Sophos Live Protection is enabled.
20130703 192112	User (SoferMahir\Daniel) has started on-access scanning for this machine.
20130703 194014	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130703 194015	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197685 items.
20130703 194015	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130704 013705	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130704 013705	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197697 items.
20130704 013705	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130704 014419	Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009.
20130704 014431	Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009.
20130704 014445	Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009.
20130704 014509	Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009.
20130704 014518	Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009.
20130704 015257	Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009.
20130704 015316	Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009.
20130704 015510	Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009.
20130704 015527	Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009.
20130704 044431	File "C:\Windows\NIRCMD.exe" belongs to adware or PUA 'NirCmd' (of type 5).
20130704 044431	On-access scanner has denied access to location "C:\Windows\NIRCMD.exe" for user NT AUTHORITY\SYSTEM
20130704 045753	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197697 items.
20130704 045754	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130704 070650	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197697 items.
20130704 070650	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130704 071245	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130704 071246	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197703 items.
20130704 071246	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130704 084659	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197703 items.
20130704 084659	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130704 101707	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197703 items.
20130704 101708	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130704 120010	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197703 items.
20130704 120011	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130704 120604	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130704 120605	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197714 items.
20130704 120605	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130704 123314	File "C:\Users\Daniel\Desktop\JRT.exe" belongs to virus/spyware 'Mal/Generic-S'.
20130704 123314	On-access scanner has denied access to location "C:\Users\Daniel\Desktop\JRT.exe" for user SoferMahir\Daniel
20130704 123323	File "C:\Users\Daniel\Desktop\JRT.exe" belongs to virus/spyware 'Mal/Generic-S'.
20130704 123323	Registry value "HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\AutoRestartShell" belongs to virus/spyware 'Mal/Generic-S'.
20130704 123323	Registry value "HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\AutoRestartShell" has been cleaned up.
20130704 123325	File "C:\Users\Daniel\Desktop\JRT.exe" has been cleaned up.
20130704 123325	Virus/spyware 'Mal/Generic-S' has been removed.
20130704 140822	Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009.
20130704 140857	Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009.
20130704 140944	Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009.
20130704 140958	Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009.
20130704 141047	User (SoferMahir\Daniel) has stopped on-access scanning for this machine.
20130704 141054	Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009.
20130704 141107	User (SoferMahir\Daniel) has started on-access scanning for this machine.
20130704 141311	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197714 items.
20130704 141311	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130704 141342	File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-401bb4c0" belongs to virus/spyware 'Troj/Java-ON'.
20130704 141342	On-access scanner has denied access to location "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-401bb4c0" for user SoferMahir\Daniel
20130704 141350	File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-401bb4c0" belongs to virus/spyware 'Troj/Java-ON'.
20130704 141350	File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\38db0252-6a676761" belongs to virus/spyware 'Mal/ExpJS-N'.
20130704 141350	On-access scanner has denied access to location "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\38db0252-6a676761" for user SoferMahir\Daniel
20130704 141352	File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-401bb4c0" has been cleaned up.
20130704 141352	Virus/spyware 'Troj/Java-ON' has been removed.
20130704 141352	File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\38db0252-6a676761" belongs to virus/spyware 'Mal/ExpJS-N'.
20130704 141352	On-access scanner has denied access to location "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\38db0252-6a676761" for user SoferMahir\Daniel
20130704 141355	File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\38db0252-6a676761" belongs to virus/spyware 'Mal/ExpJS-N'.
20130704 141357	File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\38db0252-6a676761" has been cleaned up.
20130704 141357	Virus/spyware 'Mal/ExpJS-N' has been removed.
20130704 141404	Process "C:\Users\Daniel\Desktop\TFC.exe" exhibiting suspicious behavior pattern 'HIPS/RegMod-009'. 
		No action taken. 
		If you are unsure whether the application can be authorized, please send a sample to Sophos.
20130704 141404	Process "C:\Users\Daniel\Desktop\TFC.exe" exhibiting suspicious behavior pattern 'HIPS/RegMod-009'. 
		No action taken. 
		If you are unsure whether the application can be authorized, please send a sample to Sophos.
20130704 162058	File "C:\32788R22FWJFW\NirCmd.3XE" belongs to adware or PUA 'NirCmd' (of type 5).
20130704 162059	File "C:\32788R22FWJFW\NirCmdC.3XE" belongs to adware or PUA 'NirCmd' (of type 5).
20130704 162100	File "C:\32788R22FWJFW\firefox.exe" belongs to adware or PUA 'NirCmd' (of type 5).
20130704 162101	File "C:\32788R22FWJFW\iexplore.exe" belongs to adware or PUA 'NirCmd' (of type 5).
20130704 162101	File "C:\32788R22FWJFW\nir.pif" belongs to adware or PUA 'NirCmd' (of type 5).
20130704 162116	File "C:\32788R22FWJFW\iexplore.exe" belongs to adware or PUA 'NirCmd' (of type 5).
20130704 162116	On-access scanner has denied access to location "C:\32788R22FWJFW\iexplore.exe" for user SoferMahir\Daniel
20130704 162259	User (SoferMahir\Daniel) has stopped on-access scanning for this machine.
20130704 162306	The automatic sending of file data for Sophos Live Protection is disabled.
20130704 162535	User (SoferMahir\Daniel) has started on-access scanning for this machine.
20130704 162547	The automatic sending of file data for Sophos Live Protection is enabled.
20130704 162901	File "C:\ComboFix\NircmdB.exe" belongs to adware or PUA 'NirCmd' (of type 5).
20130704 162901	On-access scanner has denied access to location "C:\ComboFix\NircmdB.exe" for user SoferMahir\Daniel
20130704 162926	Process "C:\Users\Daniel\Desktop\delfix.exe" exhibiting suspicious behavior pattern 'HIPS/RegMod-009'. 
		No action taken. 
		If you are unsure whether the application can be authorized, please send a sample to Sophos.
20130704 163647	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197714 items.
20130704 163647	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130704 164244	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130704 164245	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197754 items.
20130704 164245	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130704 164347	Scan 'Scan my computer' started.
20130704 165153	File "C:\ComboFix\NircmdB.exe" belongs to adware or PUA 'NirCmd' (of type 5).
20130704 172431	Adware or PUA 'NirCmd' has been detected.
20130704 172431	Scan 'Scan my computer' completed.
20130704 172431	Summary of results for scan 'Scan my computer':
		Items scanned: 155652
		Errors: 0
		Items quarantined: 1
		Items dealt with: 0
20130704 174841	File "C:\ComboFix\NircmdB.exe" belongs to adware or PUA 'NirCmd' (of type 5).
20130704 174841	Scanning "C:\Windows\NIRCMD.exe" returned SAV Interface error 0xa0040210: The file could not be accessed.
20130704 174841	Scanning "C:\32788R22FWJFW\firefox.exe" returned SAV Interface error 0xa0040210: The file could not be accessed.
20130704 174841	Scanning "C:\32788R22FWJFW\iexplore.exe" returned SAV Interface error 0xa0040210: The file could not be accessed.
20130704 174841	Scanning "C:\32788R22FWJFW\nir.pif" returned SAV Interface error 0xa0040210: The file could not be accessed.
20130704 174841	File "C:\ComboFix\NircmdB.exe" has been cleaned up.
20130704 174841	Adware or PUA 'NirCmd' has been removed.
20130704 174954	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197754 items.
20130704 174954	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130704 194627	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197754 items.
20130704 194627	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130704 195236	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130704 195237	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197764 items.
20130704 195237	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130704 201623	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197764 items.
20130704 201623	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130704 210029	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197764 items.
20130704 210029	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130704 211326	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197764 items.
20130704 211326	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130704 212137	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197764 items.
20130704 212137	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130704 222747	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130704 222747	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197767 items.
20130704 222747	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130705 085837	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130705 085838	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197774 items.
20130705 085838	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130705 094559	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197774 items.
20130705 094600	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130705 095248	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130705 095250	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197788 items.
20130705 095250	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 102043	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130705 104244	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197788 items.
20130705 104244	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130705 175331	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130705 175332	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197819 items.
20130705 175332	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130706 124553	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130706 124554	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197849 items.
20130706 124554	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130706 193613	Blocked web request to "wikimannia.org/Michael_Blume" (linked from "www.google.de/url") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 32839688.
20130706 203533	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130706 203534	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197860 items.
20130706 203534	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130707 073302	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130707 073309	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197873 items.
20130707 073309	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130707 075252	Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted.
20130708 082421	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197873 items.
20130708 082421	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130708 083042	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130708 083043	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197914 items.
20130708 083043	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130708 101902	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197914 items.
20130708 101902	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130708 102208	Scan 'Scan my computer' started.
20130708 111607	Scan 'Scan my computer' completed.
20130708 111607	Summary of results for scan 'Scan my computer':
		Items scanned: 166507
		Errors: 0
		Items quarantined: 0
		Items dealt with: 0
20130708 112451	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130708 112452	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197922 items.
20130708 112452	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130708 141318	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197922 items.
20130708 141318	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130708 141748	Scan 'Scan my computer' started.
20130708 151435	Scan 'Scan my computer' completed.
20130708 151435	Summary of results for scan 'Scan my computer':
		Items scanned: 167777
		Errors: 0
		Items quarantined: 0
		Items dealt with: 0
20130708 172340	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197922 items.
20130708 172340	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130708 173020	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130708 173020	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197943 items.
20130708 173021	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130708 201846	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130708 201846	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197960 items.
20130708 201846	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130709 042614	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130709 042614	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197980 items.
20130709 042614	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130709 062410	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197980 items.
20130709 062410	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130709 063035	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130709 063036	Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197992 items.
20130709 063036	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130709 074008	Scan 'Scan my computer' started.
20130709 082128	Scan 'Scan my computer' completed.
20130709 082128	Summary of results for scan 'Scan my computer':
		Items scanned: 162010
		Errors: 0
		Items quarantined: 0
		Items dealt with: 0
      (460 items)
         
Danke und LG,
Piristibulus

Antwort

Themen zu Sophosmeldung: Troj/ZbotMem-B im Memory
administrator, anleitung, anzeige, anzeigen, befall, beste grüße, bestimmte, cmd, defogger, desktop, detected, doppelt, entfernen, firefox, guten, log, meldung, problem, programme, scan, seite, sophos, strg, suche, troj/zbotmem-b, webseite, win, zeichen



Ähnliche Themen: Sophosmeldung: Troj/ZbotMem-B im Memory


  1. Troj.TR/Crypt.Zpack.151493+Troj.TR/Crypt.Xpack.138980 entfernen+daten entschlüsseln
    Log-Analyse und Auswertung - 27.08.2015 (27)
  2. Troj/ZbotMem-B
    Plagegeister aller Art und deren Bekämpfung - 04.01.2015 (13)
  3. Windows 7: Troj/ZbotMem-B Befall?
    Log-Analyse und Auswertung - 04.01.2015 (17)
  4. Troj/ZbotMem-B fund von Sophos, manuelle Reinigung erforderlich / Windows 7
    Log-Analyse und Auswertung - 15.12.2013 (11)
  5. troj/zbotmem-b in der Sophos Quarantaene und nur manuell zu bereinigen
    Log-Analyse und Auswertung - 28.11.2013 (23)
  6. Troj/ZbotMem-B, Sophos Quarantäne-Manager fordert manuelle Bereinigung
    Log-Analyse und Auswertung - 06.02.2013 (3)
  7. Troj/ZbotMem-B // gefunden mit Sophos
    Plagegeister aller Art und deren Bekämpfung - 28.12.2012 (13)
  8. Sophos meldet im Speicher: Troj/ZbotMem-B
    Plagegeister aller Art und deren Bekämpfung - 27.11.2012 (10)
  9. Habe ich Troj/zbotmem-b vollständig entfernt?
    Plagegeister aller Art und deren Bekämpfung - 07.11.2012 (1)
  10. Troj/ZbotMem-B bei Scan entdeckt, nach Sophos Meldung HIPS/RegMod-014 - Was tun?
    Plagegeister aller Art und deren Bekämpfung - 24.08.2012 (16)
  11. Troj/ExpJS-EG / Troj/ZbotMem-B / Trojan.Phex.THAGen6 - BA-BA-BA-BA-BANKÜBERFALL 2012
    Plagegeister aller Art und deren Bekämpfung - 19.08.2012 (19)
  12. Windows verschlüsselungstrojaner: out of memory?
    Log-Analyse und Auswertung - 21.06.2012 (1)
  13. Trojaner Troj/ZbotMem-B Zugriff auf Bankendaten - wie bereinigen?
    Log-Analyse und Auswertung - 10.08.2011 (6)
  14. program too big to fit in memory
    Log-Analyse und Auswertung - 01.02.2010 (1)
  15. Hijackthis = out of memory???
    Mülltonne - 12.08.2008 (0)
  16. mIRC wurm und Troj LADDER.A /Troj RAS.DLDR
    Plagegeister aller Art und deren Bekämpfung - 24.12.2004 (1)
  17. TROJ PROCKILLA / TROJ TARNO.A
    Plagegeister aller Art und deren Bekämpfung - 06.01.2004 (3)

Zum Thema Sophosmeldung: Troj/ZbotMem-B im Memory - Hallo und guten Abend, ich hoffe, dass Ihr mir helfen könnt. Ich habe heute bemerkt, dass die Funktionen der AltGr und der Strg Taste vertauscht zu sein schienen. Auch wurden - Sophosmeldung: Troj/ZbotMem-B im Memory...
Archiv
Du betrachtest: Sophosmeldung: Troj/ZbotMem-B im Memory auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.