Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: win7: Kasperski Web-Anti-Virus blockt: obession.co.ua/loader/loadit.exe

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 23.08.2014, 22:44   #1
extradry3
 
win7: Kasperski Web-Anti-Virus blockt: obession.co.ua/loader/loadit.exe - Icon32

win7: Kasperski Web-Anti-Virus blockt: obession.co.ua/loader/loadit.exe



Hallo erstmal!

Der geöffnete Kaspersky meldet alle 5 Minuten: gefährliche URL-Adresse wurde gesperrt. Drunter noch die URL: hxxp://obession.co.ua/loader/loadit.exe. Ich hab "obession.co.ua" gegoogelt und hab bei euch gleich einen Beitrag zu diesem Thema entdeckt.

Jetzt gehts mir drum,
1. zu erfahren, wie gefährlich diese Seite ist,
2. warum sich diese Seite dauernd öffnen will,
3. wer dahinter steckt und
4. wie ich diesen dauernden Ladeauftrag vom System runterkriege.

Ich betreibe ein kleines Akoya-Netbook mit win7-Starter und bitte um Support.

LG extradry3

P.S.: Hab jetzt noch das Progi ComboFix heruntergeladen. Soll ich es drüberlaufen lassen?

Code:
ATTFilter
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 22:13 on 23/08/2014 (*******)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...
SPTD -> Already disabled


-=E.O.F=-
         
FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:22-08-2014
Ran by ******* (administrator) on *******-NETBOOK on 23-08-2014 15:59:13
Running from C:\Users\*******\Desktop
Platform: Windows 7 Starter Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(SANDBOXIE L.T.D) C:\Program Files\Sandboxie\SbieSvc.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Realtek) C:\Program Files\PEARL\11n USB Wireless LAN Utility\RtlService.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
() C:\Program Files\NETGEAR\WNA3100M\WifiSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Sentelic Corporation) C:\Program Files\FSP\FspUip.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(APN LLC.) C:\Users\*******\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Realtek Semiconductor Corp.) C:\Program Files\PEARL\11n USB Wireless LAN Utility\RtWLan.exe
(SANDBOXIE L.T.D) C:\Program Files\Sandboxie\SbieCtrl.exe
() C:\Program Files\NETGEAR\WNA3100M\WNA3100M.exe
() C:\Usedown\wizard\RAR.Repair.Advanced.RAR.Repair.v1.0.Retail-ZWT - (\RAR.Repair.Advanced.RAR.Repair.v1.0.Retail-ZWT.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\klwtblfs.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8120864 2009-11-25] (Realtek Semiconductor)
HKLM\...\Run: [fspuip] => C:\Program Files\FSP\fspuip.exe [3342336 2009-11-10] (Sentelic Corporation)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM\...\Run: [ApnTBMon] => C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1957784 2014-08-01] (APN)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
HKU\S-1-5-21-1968336941-2077682222-3779713142-1000\...\Run: [UseNeXT] => C:\Program Files\UseNeXT\UseNeXT.exe [4418048 2013-10-16] ()
HKU\S-1-5-21-1968336941-2077682222-3779713142-1000\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [409320 2011-03-24] (SANDBOXIE L.T.D)
HKU\S-1-5-21-1968336941-2077682222-3779713142-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-1968336941-2077682222-3779713142-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
AppInit_DLLs: c:\progra~2\bprote~1\22463~1.83\protec~1.dll => c:\progra~2\bprote~1\22463~1.83\protec~1.dll File Not Found
AppInit_DLLs:  c:\progra~2\bprote~1\22463~1.83\protec~1.dll => c:\progra~2\bprote~1\22463~1.83\protec~1.dll File Not Found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNA3100M Genie.lnk
ShortcutTarget: NETGEAR WNA3100M Genie.lnk -> C:\Program Files\NETGEAR\WNA3100M\WNA3100M.exe ()
Startup: C:\Users\*******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutoStarter.lnk
ShortcutTarget: AutoStarter.lnk -> C:\Usedown\wizard\RAR.Repair.Advanced.RAR.Repair.v1.0.Retail-ZWT - (\RAR.Repair.Advanced.RAR.Repair.v1.0.Retail-ZWT.exe ()
GroupPolicyUsers\S-1-5-21-1968336941-2077682222-3779713142-1001\User: Group Policy restriction detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.search.ask.com/?tpid=ORJ-SPE&o=APN11406&pf=V7&trgb=IE&p2=%5EBBE%5EOSJ000%5EYY%5EAT&gct=hp&apn_ptnrs=BBE&apn_dtid=%5EOSJ000%5EYY%5EAT&apn_dbr=ie_11.0.9600.17126&apn_uid=1031D334-E487-431B-A6AE-58ACAF69C53E&itbv=12.15.5.30&doi=2014-08-12&psv=&pt=tb
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=MDNB&bmod=MDNB
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://banking.raiffeisen.at/logincenter/login.wf;jsessionid=2A506E608020AAC8C8100EC2F3D38E87.rlogincenter-2_b2p03?execution=e1s1
URLSearchHook: HKLM - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
URLSearchHook: HKLM - appbario2 Toolbar - {cdf97ee2-ded0-4369-835e-99dd08225fa5} - C:\Program Files\appbario2\prxtbapp0.dll (Conduit Ltd.)
URLSearchHook: HKCU - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
URLSearchHook: HKCU - appbario2 Toolbar - {cdf97ee2-ded0-4369-835e-99dd08225fa5} - C:\Program Files\appbario2\prxtbapp0.dll (Conduit Ltd.)
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - DefaultScope {4A42A73F-DDBD-4DAA-9341-F20A64E89FFE} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {01F8BC68-4065-4403-BD6E-3F663305D49B} URL = hxxp://www.youtube.com/results?search_query={searchTerms}
SearchScopes: HKCU - {0B0973FF-92D6-424D-BA40-695FC6DDA5DF} URL = hxxp://www.computerbild.de/suche/index.html?s_text={searchTerms}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=109035&babsrc=SP_ss&mntrId=b6514f6b0000000000001c4bd6ea8657
SearchScopes: HKCU - {0FE68ABF-0D0F-49D5-870E-E71385D9A04A} URL = hxxp://de.wikipedia.org/w/index.php?title=Spezial:Suche&search={searchTerms}
SearchScopes: HKCU - {26BAE79F-B63D-4674-98D3-715097F3234B} URL = hxxp://www.youtube.com/results?search_query={searchTerms}
SearchScopes: HKCU - {29A57772-F485-4723-A1D0-14CA9DB795CF} URL = hxxp://www.search.ask.com/web?tpid=ORJ-SPE&o=APN11406&pf=V7&p2=%5EBBE%5EOSJ000%5EYY%5EAT&gct=&itbv=12.15.5.30&apn_uid=1031D334-E487-431B-A6AE-58ACAF69C53E&apn_ptnrs=BBE&apn_dtid=%5EOSJ000%5EYY%5EAT&apn_dbr=ie_11.0.9600.17126&doi=2014-08-12&trgb=IE&q={searchTerms}&psv=
SearchScopes: HKCU - {2DAA52D3-974E-4005-8CFA-456B99E6E914} URL = hxxp://www.dict.cc/?s={searchTerms}
SearchScopes: HKCU - {41D65A26-6CDD-4624-B8D6-52EB67A297C1} URL = hxxp://rover.ebay.com/rover/1/707-37276-23097-0/4?satitle={searchTerms}
SearchScopes: HKCU - {4A42A73F-DDBD-4DAA-9341-F20A64E89FFE} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {6DA932D1-64A8-4799-BF86-D5BA491BE5F7} URL = hxxp://www.google.at/search?q={searchTerms}
SearchScopes: HKCU - {846CEF4B-EBE3-4716-923C-7EABEF93F1E8} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3227975
SearchScopes: HKCU - {99A68893-A2A7-4A34-A2AC-B349A20B3F92} URL = hxxp://start.funmoods.com/results.php?f=4&a=nv1&q={searchTerms}
SearchScopes: HKCU - {AA66FDDD-71C1-446C-A97E-CADE2B39022B} URL = hxxp://www.youtube.de/results?search_query={searchTerms}
SearchScopes: HKCU - {DFC88724-25B4-4A33-9C31-2ABB953C2D5E} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}
SearchScopes: HKCU - {E38F75F6-A81C-475C-AB73-BCDEE81D7768} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=amznsearch.de.ms-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
BHO: 2YourFace Addon -> {1185823F-F22F-4027-80E5-4F68ACD5DE5E} -> C:\Program Files\2YourFace\bho.dll ()
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: CBAbzockschutz.InitToolbarBHO -> {2e250b90-0e7a-42a3-9d65-e39f9f227fa4} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: Babylon toolbar helper -> {2EECD738-5844-4a99-B4B6-146BF802613B} -> C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO)
BHO: Conduit Engine -> {30F9B915-B755-4826-820B-08FBA6BD249D} -> C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
BHO: Search App by Ask -> {4F524A2D-5350-4500-76A7-7A786E7484D7} -> C:\Program Files\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll (APN LLC.)
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: DVDVideoSoftTB Toolbar -> {872b5b88-9db5-4310-bdd0-ac189557e5f5} -> C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: appbario2 Toolbar -> {cdf97ee2-ded0-4369-835e-99dd08225fa5} -> C:\Program Files\appbario2\prxtbapp0.dll (Conduit Ltd.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
Toolbar: HKLM - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
Toolbar: HKLM - Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
Toolbar: HKLM - COMPUTERBILD-Abzockschutz - {353e2a48-6254-4bd3-88f4-3b51a0ca7870} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM - Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll No File
Toolbar: HKLM - appbario2 Toolbar - {cdf97ee2-ded0-4369-835e-99dd08225fa5} - C:\Program Files\appbario2\prxtbapp0.dll (Conduit Ltd.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Search App by Ask - {4F524A2D-5350-4500-76A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll (APN LLC.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - appbario2 Toolbar - {CDF97EE2-DED0-4369-835E-99DD08225FA5} - C:\Program Files\appbario2\prxtbapp0.dll (Conduit Ltd.)
Toolbar: HKCU - No Name - {41564952-412D-5637-4300-7A786E7484D7} -  No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Users\*******\AppData\Roaming\Mozilla\Firefox\Profiles\wyo9gq0o.default-1385061442503
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1165635.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Users\*******\AppData\Roaming\Mozilla\Firefox\Profiles\wyo9gq0o.default-1385061442503\searchplugins\ilovevitaly.xml
FF SearchPlugin: C:\Users\*******\AppData\Roaming\Mozilla\Firefox\Profiles\wyo9gq0o.default-1385061442503\searchplugins\privatelee-https.xml
FF SearchPlugin: C:\Users\*******\AppData\Roaming\Mozilla\Firefox\Profiles\wyo9gq0o.default-1385061442503\searchplugins\youtube.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: YouTube Unblocker - C:\Users\*******\AppData\Roaming\Mozilla\Firefox\Profiles\wyo9gq0o.default-1385061442503\Extensions\youtubeunblocker@unblocker.yt [2014-01-23]
FF Extension: Adblock Plus - C:\Users\*******\AppData\Roaming\Mozilla\Firefox\Profiles\wyo9gq0o.default-1385061442503\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-11-22]
FF HKLM\...\Firefox\Extensions: [fbphotozoom@installdaddy.com] - C:\Program Files\fbphotozoom\fbphotozoom13.xpi
FF Extension: FBPhotoZoom - C:\Program Files\fbphotozoom\fbphotozoom13.xpi [2012-03-08]
FF HKLM\...\Firefox\Extensions: [support@2yourface.com] - C:\Program Files\2YourFace\ffextension
FF Extension: 2YourFace - C:\Program Files\2YourFace\ffextension [2012-04-28]
FF HKLM\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff [2013-12-01]
FF HKLM\...\Firefox\Extensions:  - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: ???????? - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-04-03]
FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: ???? - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-04-03]
FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: ??????? - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-04-03]
FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Ch?n qu?ng cáo - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-04-03]
FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-04-03]
FF HKCU\...\Firefox\Extensions: [support@2yourface.com] - C:\Program Files\2YourFace\ffextension

Chrome: 
=======
CHR HomePage: hxxp://search.babylon.com/?affID=109035&babsrc=HP_ss&mntrId=b6514f6b0000000000001c4bd6ea8657
CHR StartupUrls: "hxxp://search.babylon.com/?affID=109035&babsrc=HP_ss&mntrId=b6514f6b0000000000001c4bd6ea8657", "hxxp://google.at/", "hxxp://search.babylon.com/?affID=109035&babsrc=HP_ss&mntrId=b6514f6b0000000000001c4bd6ea8657"
CHR DefaultSearchKeyword: babylon.com
CHR DefaultSearchProvider: Search the web (Babylon)
CHR DefaultSearchURL: hxxp://search.babylon.com/?q={searchTerms}&tt=010412_crm&babsrc=SP_crm
CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\34.0.1847.116\pdf.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\34.0.1847.116\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (2YourFace Util) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmblfngognklgemafekefcdjcnkdhmdm\1.0_0\2YourFace_Util.dll (2YourFace.com)
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Winamp Application Detector) - C:\Program Files\Mozilla Firefox\plugins\npwachk.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll No File
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Extension: (Kaspersky Protection) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\blbkdnmdcafmfhinpmnlhhddbepgkeaa [2014-04-03]
CHR Extension: (Modul zur Link-Untersuchung) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-04-03]
CHR Extension: (Type Scout) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\fedokkaolmkkoeedicihicdeppjjeamj [2011-10-28]
CHR Extension: (Avira Browser Safety) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-03-22]
CHR Extension: (IP-Adresse) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjndloejlcbpkholmagjbddfkjmmploh [2011-10-28]
CHR Extension: (2YourFace) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmblfngognklgemafekefcdjcnkdhmdm [2012-05-01]
CHR Extension: (FBPHOTOZOOM) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpieaakhacmfleokhjcjnpcnmnmpfkid [2012-03-11]
CHR Extension: (Google Wallet) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-29]
CHR Extension: (Anti-Banner) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-04-03]
CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [2014-04-03]
CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17]
CHR HKLM\...\Chrome\Extension: [fdloijijlkoblmigdofommgnheckmaki] - C:\Program Files\Funmoods\funmoods\1.5.11.16\funmoodsOEM.crx [2013-10-17]
CHR HKLM\...\Chrome\Extension: [ieadcoanfjloocmfafkebdnfefmohngj] - C:\Program Files\BonanzaDeals\BonanzaDeals.crx [2013-10-17]
CHR HKLM\...\Chrome\Extension: [lmblfngognklgemafekefcdjcnkdhmdm] - C:\Program Files\2YourFace\2YourFace.crx [2011-12-14]
CHR HKLM\...\Chrome\Extension: [mpieaakhacmfleokhjcjnpcnmnmpfkid] - C:\Program Files\fbphotozoom\fbphotozoom13.crx [2012-03-08]
CHR HKLM\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [165784 2014-08-01] (APN LLC.)
R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
R2 RealtekCU; C:\Program Files\PEARL\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek) [File not signed]
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [72936 2011-03-24] (SANDBOXIE L.T.D)
R2 WSWNA3100M; C:\Program Files\NETGEAR\WNA3100M\WifiSvc.exe [307456 2012-02-24] ()
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 ACPIService; C:\Windows\system32\DRIVERS\ATKACPI.SYS [16456 2009-06-09] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2012-02-07] (DT Soft Ltd)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-04-03] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [94304 2014-04-03] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576608 2014-04-03] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-04-03] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2014-04-03] (Kaspersky Lab ZAO)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [107736 2014-04-03] (Malwarebytes Corporation)
S3 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
S3 RTL8192cu; C:\Windows\System32\DRIVERS\rtwlanu.sys [863336 2012-02-10] (Realtek Semiconductor Corporation                           )
S3 rtlss; C:\Windows\System32\Drivers\rtlss.sys [23144 2010-06-21] (Realtek Semiconductor Corporation)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [126542 2011-03-24] (SANDBOXIE L.T.D) [File not signed]
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [473656 2012-02-07] (Duplex Secure Ltd.)
S3 ss_bbus; C:\Windows\System32\DRIVERS\ss_bbus.sys [98432 2009-09-19] (MCCI)
S3 ss_bmdfl; C:\Windows\System32\DRIVERS\ss_bmdfl.sys [14848 2009-09-19] (MCCI Corporation)
S3 ss_bmdm; C:\Windows\System32\DRIVERS\ss_bmdm.sys [123648 2009-09-19] (MCCI Corporation)
S3 wna3100m; C:\Windows\System32\DRIVERS\wna3100m.sys [949864 2011-12-30] (NETGEAR Corporation                           )
S1 ddttdzdz; \??\C:\Windows\system32\drivers\ddttdzdz.sys [X]
S3 lmimirr; system32\DRIVERS\lmimirr.sys [X]
S1 nonnebpn; \??\C:\Windows\system32\drivers\nonnebpn.sys [X]
S1 pafrjylv; \??\C:\Windows\system32\drivers\pafrjylv.sys [X]
S1 sjbewkyu; \??\C:\Windows\system32\drivers\sjbewkyu.sys [X]
S1 whmeluhn; \??\C:\Windows\system32\drivers\whmeluhn.sys [X]
U3 kxxiiaow; \??\C:\Users\*******\AppData\Local\Temp\kxxiiaow.sys [X]

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-23 15:59 - 2014-08-23 16:02 - 00031696 _____ () C:\Users\*******\Desktop\FRST.txt
2014-08-23 15:50 - 2014-08-23 15:50 - 01094656 _____ (Farbar) C:\Users\*******\Desktop\FRST.exe
2014-08-23 15:43 - 2014-08-23 15:45 - 00000000 ____D () C:\Users\*******\Desktop\E-book Reader
2014-08-23 15:40 - 2014-08-23 15:40 - 00000000 ____D () C:\Users\*******\Desktop\WLAN-Dongles
2014-08-23 15:10 - 2014-08-23 15:10 - 00380416 _____ () C:\Users\*******\Desktop\Gmer-19357.exe
2014-08-23 14:48 - 2014-08-23 14:49 - 00000586 _____ () C:\Windows\system32\defogger_disable.log
2014-08-23 14:48 - 2014-08-23 14:49 - 00000020 _____ () C:\Users\*******\defogger_reenable
2014-08-23 13:13 - 2014-08-23 16:00 - 00000000 ____D () C:\FRST
2014-08-23 12:09 - 2014-08-23 14:50 - 00593960 _____ () C:\Users\*******\Documents\UseNeXT_krypt (14-01-06) (Automatisch gespeichert).xlsx
2014-08-21 16:05 - 2014-08-21 17:55 - 00000000 ____D () C:\Users\*******\AppData\Roaming\GrabIt
2014-08-19 18:07 - 2014-08-19 18:07 - 00262144 _____ () C:\Windows\system32\config\elam
2014-08-19 10:18 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-19 10:18 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-19 10:18 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-19 10:18 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-19 10:17 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-19 10:17 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-19 10:17 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-19 10:16 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-19 10:16 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-14 10:47 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-14 10:47 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-14 10:47 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-14 10:46 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-14 10:08 - 2014-08-14 10:08 - 00295851 _____ () C:\Users\*******\Downloads\e5d3f108808273f52160873b8a92e02f.par2.nzb
2014-08-13 05:32 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-13 05:32 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-13 05:32 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-13 05:32 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-13 05:32 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-13 05:32 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-13 05:32 - 2014-07-25 14:10 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-13 05:32 - 2014-07-25 13:59 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 05:32 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-13 05:32 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 05:32 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-13 05:32 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-13 05:32 - 2014-07-14 03:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-13 05:32 - 2014-06-16 03:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-13 05:32 - 2014-06-16 03:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-08-13 05:32 - 2014-06-16 03:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-08-13 05:31 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-13 05:31 - 2014-07-25 15:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 05:31 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-13 05:31 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-13 05:31 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-13 05:31 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-13 05:31 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-13 05:31 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-13 05:31 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-13 05:31 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-13 05:31 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-13 05:31 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-13 05:31 - 2014-07-25 13:09 - 00663040 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-13 05:31 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-13 05:31 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-13 05:31 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-13 05:31 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-13 05:31 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-13 05:29 - 2014-07-16 04:47 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-13 05:29 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-13 05:29 - 2014-07-16 03:47 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-13 05:28 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-08-13 05:28 - 2014-06-03 11:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-13 05:28 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-13 05:28 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-13 05:28 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-13 05:27 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-08-13 05:27 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-08-13 05:27 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-08-13 05:27 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-08-13 05:27 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-08-13 05:27 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-08-13 05:27 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-08-13 05:27 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-08-13 05:27 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-08-13 05:26 - 2014-08-07 03:43 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-13 05:26 - 2014-08-07 03:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-13 05:26 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-13 05:26 - 2014-06-05 16:26 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-08-13 05:25 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-13 05:25 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-13 05:25 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-13 05:25 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-13 05:25 - 2014-07-09 03:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-13 05:25 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-13 00:38 - 2014-08-13 00:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-08-13 00:34 - 2014-08-13 00:38 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-08-13 00:34 - 2014-08-13 00:34 - 00000000 ____D () C:\Program Files\iPod
2014-08-12 22:03 - 2014-08-12 22:03 - 00007864 _____ () C:\Users\*******\Documents\NETGEAR-Genie_Sysinfo.txt
2014-08-12 21:31 - 2014-08-12 21:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NETGEAR WNA3100M Genie
2014-08-12 21:31 - 2014-08-12 21:31 - 00000000 ____D () C:\Program Files\NETGEAR
2014-08-12 21:31 - 2011-12-30 15:23 - 00949864 _____ (NETGEAR Corporation ) C:\Windows\system32\Drivers\wna3100m.sys
2014-08-12 21:18 - 2014-08-12 21:18 - 00000000 ____D () C:\Users\*******\AppData\Local\AskPartnerNetwork
2014-08-12 21:18 - 2014-08-12 21:18 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork
2014-08-12 21:18 - 2014-08-12 21:18 - 00000000 ____D () C:\Program Files\AskPartnerNetwork
2014-08-12 21:17 - 2014-08-12 21:17 - 00000000 ____D () C:\Users\*******\AppData\Roaming\InstallShield
2014-08-12 21:14 - 2014-08-12 21:14 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-08-12 21:14 - 2014-07-25 12:49 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-12 21:13 - 2014-08-12 21:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-12 21:13 - 2014-07-25 12:55 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-08-12 21:13 - 2014-07-25 12:49 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-12 21:13 - 2014-07-25 12:49 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-12 21:10 - 2014-08-12 21:13 - 00004611 _____ () C:\Windows\system32\jupdate-1.7.0_67-b01.log
2014-08-12 21:07 - 2014-08-12 21:07 - 00000000 ____D () C:\Users\*******\Downloads\NETGEAR

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-23 16:02 - 2014-08-23 15:59 - 00031696 _____ () C:\Users\*******\Desktop\FRST.txt
2014-08-23 16:00 - 2014-08-23 13:13 - 00000000 ____D () C:\FRST
2014-08-23 16:00 - 2014-04-03 12:11 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-08-23 15:50 - 2014-08-23 15:50 - 01094656 _____ (Farbar) C:\Users\*******\Desktop\FRST.exe
2014-08-23 15:45 - 2014-08-23 15:43 - 00000000 ____D () C:\Users\*******\Desktop\E-book Reader
2014-08-23 15:45 - 2011-08-10 18:34 - 00000000 ___RD () C:\Users\*******\Desktop\Browser + Player + Brennstoff + Editor
2014-08-23 15:40 - 2014-08-23 15:40 - 00000000 ____D () C:\Users\*******\Desktop\WLAN-Dongles
2014-08-23 15:33 - 2013-05-21 11:52 - 00000000 ____D () C:\Users\*******\Desktop\Konverter + En- u. Decoder, Splitter
2014-08-23 15:21 - 2011-07-14 15:06 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-23 15:20 - 2012-12-12 22:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-23 15:10 - 2014-08-23 15:10 - 00380416 _____ () C:\Users\*******\Desktop\Gmer-19357.exe
2014-08-23 15:08 - 2009-07-14 06:34 - 00016160 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-23 15:08 - 2009-07-14 06:34 - 00016160 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-23 15:04 - 2011-07-15 00:05 - 02082819 _____ () C:\Windows\WindowsUpdate.log
2014-08-23 15:01 - 2011-08-04 19:09 - 00000000 ____D () C:\Users\*******\AppData\Roaming\UseNeXT
2014-08-23 15:00 - 2012-01-09 20:14 - 00000000 ____D () C:\Usedown
2014-08-23 15:00 - 2010-09-21 18:42 - 01630924 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-23 14:57 - 2011-07-14 15:06 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-23 14:56 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-23 14:56 - 2009-07-14 06:39 - 00102807 _____ () C:\Windows\setupact.log
2014-08-23 14:56 - 2009-07-14 06:33 - 00412440 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-23 14:50 - 2014-08-23 12:09 - 00593960 _____ () C:\Users\*******\Documents\UseNeXT_krypt (14-01-06) (Automatisch gespeichert).xlsx
2014-08-23 14:49 - 2014-08-23 14:48 - 00000586 _____ () C:\Windows\system32\defogger_disable.log
2014-08-23 14:49 - 2014-08-23 14:48 - 00000020 _____ () C:\Users\*******\defogger_reenable
2014-08-23 14:48 - 2011-07-14 15:10 - 00000000 ____D () C:\Users\*******
2014-08-23 12:48 - 2011-07-24 20:32 - 00000000 ____D () C:\Users\*******\AppData\Roaming\vlc
2014-08-23 01:16 - 2013-11-29 13:48 - 00592476 _____ () C:\Users\*******\Documents\UseNeXT_krypt (14-01-06).xlsx
2014-08-22 22:28 - 2011-08-10 19:30 - 00000000 ____D () C:\Users\*******\AppData\Local\QuickPar
2014-08-22 18:14 - 2012-04-16 00:14 - 00002102 _____ () C:\Windows\Sandboxie.ini
2014-08-22 18:06 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-08-21 17:55 - 2014-08-21 16:05 - 00000000 ____D () C:\Users\*******\AppData\Roaming\GrabIt
2014-08-21 15:57 - 2014-06-04 15:00 - 00000000 ____D () C:\Program Files\GrabIt
2014-08-19 18:07 - 2014-08-19 18:07 - 00262144 _____ () C:\Windows\system32\config\elam
2014-08-19 10:22 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-08-18 10:03 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-08-18 09:57 - 2010-05-21 22:10 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE
2014-08-16 15:00 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-08-15 22:47 - 2014-06-27 13:19 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-08-15 22:28 - 2011-07-14 17:49 - 01158970 _____ () C:\Windows\PFRO.log
2014-08-15 22:28 - 2010-09-21 20:27 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-08-15 14:20 - 2014-06-13 10:03 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-15 00:28 - 2013-11-29 13:48 - 00591521 _____ () C:\Users\*******\Documents\4333026B.tmp
2014-08-14 12:33 - 2011-07-14 18:29 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-14 12:08 - 2013-08-21 19:25 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-14 10:28 - 2010-09-21 20:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-08-14 10:08 - 2014-08-14 10:08 - 00295851 _____ () C:\Users\*******\Downloads\e5d3f108808273f52160873b8a92e02f.par2.nzb
2014-08-13 22:04 - 2013-08-30 23:41 - 00000000 ____D () C:\Users\*******\AppData\Local\CrashDumps
2014-08-13 00:38 - 2014-08-13 00:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-08-13 00:38 - 2014-08-13 00:34 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-08-13 00:38 - 2011-07-25 16:55 - 00000000 ____D () C:\Program Files\iTunes
2014-08-13 00:34 - 2014-08-13 00:34 - 00000000 ____D () C:\Program Files\iPod
2014-08-13 00:34 - 2011-07-19 16:56 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-08-12 22:22 - 2012-04-06 09:14 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-08-12 22:22 - 2011-07-14 19:39 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-08-12 22:03 - 2014-08-12 22:03 - 00007864 _____ () C:\Users\*******\Documents\NETGEAR-Genie_Sysinfo.txt
2014-08-12 21:31 - 2014-08-12 21:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NETGEAR WNA3100M Genie
2014-08-12 21:31 - 2014-08-12 21:31 - 00000000 ____D () C:\Program Files\NETGEAR
2014-08-12 21:31 - 2010-09-21 19:25 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-08-12 21:18 - 2014-08-12 21:18 - 00000000 ____D () C:\Users\*******\AppData\Local\AskPartnerNetwork
2014-08-12 21:18 - 2014-08-12 21:18 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork
2014-08-12 21:18 - 2014-08-12 21:18 - 00000000 ____D () C:\Program Files\AskPartnerNetwork
2014-08-12 21:17 - 2014-08-12 21:17 - 00000000 ____D () C:\Users\*******\AppData\Roaming\InstallShield
2014-08-12 21:15 - 2013-10-16 20:31 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-12 21:14 - 2014-08-12 21:14 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-08-12 21:13 - 2014-08-12 21:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-12 21:13 - 2014-08-12 21:10 - 00004611 _____ () C:\Windows\system32\jupdate-1.7.0_67-b01.log
2014-08-12 21:13 - 2010-09-21 13:46 - 00000000 ____D () C:\Program Files\Java
2014-08-12 21:07 - 2014-08-12 21:07 - 00000000 ____D () C:\Users\*******\Downloads\NETGEAR
2014-08-07 03:43 - 2014-08-13 05:26 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-07 03:39 - 2014-08-13 05:26 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-05 09:20 - 2010-09-21 20:27 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-01 01:16 - 2014-08-13 05:32 - 00307384 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-31 23:42 - 2010-09-21 21:04 - 96303304 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-25 15:51 - 2014-08-13 05:31 - 17524224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-25 15:04 - 2014-08-13 05:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-25 15:03 - 2014-08-13 05:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-25 14:34 - 2014-08-13 05:31 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-25 14:34 - 2014-08-13 05:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-25 14:33 - 2014-08-13 05:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-25 14:30 - 2014-08-13 05:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-25 14:21 - 2014-08-13 05:31 - 02184704 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-25 14:18 - 2014-08-13 05:32 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-25 14:17 - 2014-08-13 05:32 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-25 14:12 - 2014-08-13 05:31 - 00438784 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-25 14:10 - 2014-08-13 05:32 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-25 14:10 - 2014-08-13 05:32 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-25 14:08 - 2014-08-13 05:31 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-25 14:06 - 2014-08-13 05:31 - 04204032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-25 13:59 - 2014-08-13 05:32 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-25 13:52 - 2014-08-13 05:32 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-25 13:43 - 2014-08-13 05:32 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-25 13:36 - 2014-08-13 05:31 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-25 13:34 - 2014-08-13 05:31 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-25 13:29 - 2014-08-13 05:31 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-25 13:13 - 2014-08-13 05:32 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-25 13:09 - 2014-08-13 05:31 - 00663040 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-25 13:07 - 2014-08-13 05:31 - 02001920 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-25 13:07 - 2014-08-13 05:31 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-25 13:03 - 2014-08-13 05:31 - 11772928 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-25 12:55 - 2014-08-12 21:13 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-07-25 12:49 - 2014-08-12 21:14 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-07-25 12:49 - 2014-08-12 21:13 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-07-25 12:49 - 2014-08-12 21:13 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-07-25 12:09 - 2014-08-13 05:31 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-25 12:05 - 2014-08-13 05:31 - 01792512 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-25 12:00 - 2014-08-13 05:32 - 01169920 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll

Some content of TEMP:
====================
C:\Users\d*****a\AppData\Local\Temp\AskSLib.dll
C:\Users\d*****a\AppData\Local\Temp\avgnt.exe
C:\Users\*******\AppData\Local\Temp\APNSetup.exe
C:\Users\*******\AppData\Local\Temp\avgnt.exe
C:\Users\*******\AppData\Local\Temp\DivXSetup.exe
C:\Users\*******\AppData\Local\Temp\install_flashplayer14x32au_gtbd_awe_aih.exe
C:\Users\*******\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\*******\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\*******\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\*******\AppData\Local\Temp\uc_german.exe
C:\Users\*******\AppData\Local\Temp\ultra.exe
C:\Users\*******\AppData\Local\Temp\vlc-2.1.1-win32.exe
C:\Users\*******\AppData\Local\Temp\vlc-2.1.3-win32.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-08-18 12:10

==================== End Of Log ============================
         
--- --- ---

--- --- ---

--- --- ---

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x86) Version:22-08-2014
Ran by ******* at 2014-08-23 16:04:39
Running from C:\Users\*******\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
1ClickDownload (HKLM\...\1ClickDownload) (Version: 2.1 Build 26473 - 1ClickDownload)
2YourFace 1.0 (HKLM\...\2YourFace) (Version: 1.0 - 2YourFace.com)
7-Zip 9.20 (HKLM\...\7-Zip) (Version:  - )
Adobe AIR (HKLM\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe AIR (Version: 1.5.0.7220 - Adobe Systems Inc.) Hidden
Adobe Flash Player 14 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Flash Player 14 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 MUI (HKLM\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM\...\Adobe Shockwave Player) (Version: 11.6.5.635 - Adobe Systems, Inc.)
Android SDK Tools (HKLM\...\Android SDK Tools) (Version: 1.16 - Google Inc.)
appbario2 Toolbar (HKLM\...\appbario2 Toolbar) (Version: 6.8.10.0 - appbario2)
Apple Application Support (HKLM\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{941B4CE7-3F5D-443E-A8B7-56A420D2EAFD}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM\...\{C6579A65-9CAE-4B31-8B6B-3306E0630A66}) (Version: 2.1.3.127 - Apple Inc.)
Ashampoo Burning Studio 11 v.11.0.2 (HKLM\...\Ashampoo Burning Studio 11_is1) (Version: 11.0.2 - Ashampoo GmbH & Co. KG)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.17 - Atheros Communications Inc.)
Audiobook Cutter Free Edition (HKLM\...\{B4D5287E-762E-4B80-8BA7-09D804BAF786}) (Version: 1.8.1 - Audiobook Software)
AVS Audio Converter version 7 (HKLM\...\AVS Audio Converter_is1) (Version:  - Online Media Technologies Ltd.)
Babylon toolbar on IE (HKLM\...\BabylonToolbar) (Version:  - ) <==== ATTENTION
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
burnatonce (HKLM\...\burnatonce_is1) (Version:  - )
calibre (HKLM\...\{E357C7B4-E337-4E43-84F1-8FDAF1EF4038}) (Version: 0.9.32 - Kovid Goyal)
Canon LBP6000/LBP6018 (HKLM\...\Canon LBP6000/LBP6018) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform)
Cisco EAP-FAST Module (HKLM\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Codec 8.4 (HKLM\...\Codec_is1) (Version:  - )
COMPUTERBILD-Abzockschutz (HKLM\...\{7ACB3CAB-68EC-4DCE-8597-50B4DC558F94}) (Version: 1.0.40 - J3S)
Conduit Engine (HKLM\...\conduitEngine) (Version:  - Conduit Ltd.) <==== ATTENTION
CyberLink YouCam (HKLM\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.0.2626 - CyberLink Corp.)
CyberLink YouCam (Version: 3.0.2626 - CyberLink Corp.) Hidden
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.45.2.0287 - DT Soft Ltd)
Digitale Bibliothek 4 (HKLM\...\Digitale Bibliothek 4) (Version:  - )
DivX-Setup (HKLM\...\DivX Setup) (Version: 2.6.1.87 - DivX, LLC)
FileViewPro (HKLM\...\{29938C06-6962-4C27-A94C-25E4F424A665}_is1) (Version: 1.5 - Solvusoft Corporation)
Finger Sensing Pad Driver (HKLM\...\{E86906FF-C63D-4EAF-ACE7-5F8D55FBEA9A}) (Version: 8.5.7.7 - Sentelic)
FLAC To MP3 V4.0.4 (HKLM\...\FLAC To MP3_is1) (Version:  - FLAC To MP3, Inc.)
Free Studio version 5.1.7 (HKLM\...\Free Studio_is1) (Version:  - DVDVideoSoft Ltd.)
Free YouTube Download version 3.2.18.1128 (HKLM\...\Free YouTube Download_is1) (Version: 3.2.18.1128 - DVDVideoSoft Ltd.)
Google Chrome (HKLM\...\Google Chrome) (Version: 36.0.1985.143 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden
GrabIt 1.7.2 Beta 6 (build 1008) (HKLM\...\GrabIt_is1) (Version:  - Ilan Shemes)
HiDownloadPlatinum (HKLM\...\HiDownload Platinum_is1) (Version:  - )
Hotkey (HKLM\...\{5A627DFB-EA4C-4FFA-B711-69E849FB40D8}) (Version: 1.0.0.5 - Pegatron)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.14.10.2230 - Intel Corporation)
iTunes (HKLM\...\{86D04316-F49A-4AF2-B3F1-A1E943886CE7}) (Version: 11.3.1.2 - Apple Inc.)
Java 7 Update 67 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.670 - Oracle)
Java Auto Updater (Version: 2.1.67.1 - Oracle, Inc.) Hidden
JPS Viewer (HKLM\...\{053F4F6C-8680-45AE-AA2A-FC85D2E2D5FD}) (Version: 1.00.0000 - JAVAD GNSS)
Junk Mail filter update (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Kaspersky Internet Security (HKLM\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab)
Kaspersky Internet Security (Version: 14.0.0.4651 - Kaspersky Lab) Hidden
Kernel For PDF Repair Evaluation ver 9.11.01 (HKLM\...\Kernel For PDF Repair Evaluation version_is1) (Version:  - Nucleus Data Recovery .com)
K-Lite Codec Pack 10.1.5 Full (HKLM\...\KLiteCodecPack_is1) (Version: 10.1.5 - )
MediaCoder 2011 (HKLM\...\MediaCoder) (Version: 2011 - Broad Intelligence)
Medieval CUE Splitter (HKLM\...\{B96D2269-568B-4CBF-9332-12FAE8B158F7}) (Version: 1.2.0 - Medieval Software)
Medion Home Cinema (HKLM\...\InstallShield_{AB770FDE-8087-4C98-9A85-BD64262C104C}) (Version: 6.0.0000 - CyberLink Corp.)
Medion Home Cinema (Version: 6.0.0000 - CyberLink Corp.) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Choice Guard (Version: 2.0.48.0 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (Version:  - Microsoft) Hidden
Microsoft Office 2010 (HKLM\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel 2007 Schnellstartleiste (HKLM\...\{AB706D91-2242-4E1D-B4D0-1ED35387F5A7}) (Version: 12.0.0 - Microsoft Corporation)
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Klick-und-Los 2010 (HKLM\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint 2007 Schnellstartleiste (HKLM\...\{5AE5DB70-5CE6-4876-A83E-8246CC36FC28}) (Version: 12.0.0 - Microsoft Corporation)
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Starter 2010 - Deutsch (HKLM\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Word 2007 Schnellstartleiste (HKLM\...\{68B52EFD-86CC-486E-A8D0-A3A1554CB5BC}) (Version: 12.0.0 - Microsoft Corporation)
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Search Enhancement Pack (Version: 3.0.127.0 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [DEU] (HKLM\...\{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 31.0 (x86 de) (HKLM\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla)
MSVCRT (Version: 14.0.1468.721 - Microsoft) Hidden
NETGEAR WNA3100M N300 Wireless USB Adapter (HKLM\...\{D3580358-0F78-402A-BE53-2E9D06383E04}) (Version: 1.0.0.17 - NETGEAR)
PdfGrabber 7.0 (32bit) (HKLM\...\{01517A48-9217-431B-821C-F89F53918E3D}) (Version: 7.0 - PixelPlanet)
PEARL Wireless LAN Driver and Utility (HKLM\...\{9C049499-055C-4A0C-A916-1D12314F45EB}) (Version: 1.00.0187 - PEARL)
Philips Songbird (HKLM\...\Philips Songbird) (Version: 2.4 (Build: 5.0.1902; Revision: 503) (1902) - Koninklijke Philips Electronics N.V.)
PixelPlanet PdfPrinter 6 (32bit) (HKLM\...\{B8E88489-A304-45F1-9717-242035DE167D}) (Version: 6.03.23 - PixelPlanet)
PlayReady PC Runtime x86 (HKLM\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Quest3D Viewers 3.0e (HKLM\...\Quest3D Viewers 3.0e_is1) (Version: 3.0e - Act-3D B.V.)
QuickPar 0.9 (HKLM\...\QuickPar) (Version: 0.9 - Peter B. Clements)
QuickTime (HKLM\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.)
ratDVD 0.76.1408 (HKLM\...\ratDVD) (Version: 0.76.1408 - ratDVD)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5989 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM\...\{9D3D8C60-A55F-4fed-B2B9-173F09590E16}) (Version: 1.00.0148 - REALTEK Semiconductor Corp.)
Safari (HKLM\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Sandboxie 3.54 (32-bit) (HKLM\...\Sandboxie) (Version:  - )
Search App by Ask (HKLM\...\{4F524A2D-5350-4500-76A7-A758B70C0F05}) (Version: 12.15.5.30 - APN, LLC)
SES Driver (HKLM\...\{0673654C-5296-453B-9798-B61CD7E03FEB}) (Version: 1.0.0 - Western Digital)
Software Informer 1.2 (HKLM\...\Software Informer_is1) (Version:  - Informer Technologies, Inc.)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
The KMPlayer (remove only) (HKLM\...\The KMPlayer) (Version:  - )
TrueCrypt (HKLM\...\TrueCrypt) (Version: 7.0a - TrueCrypt Foundation)
TuneUp Utilities Language Pack (en-US) (Version: 10.0.4500.46 - TuneUp Software) Hidden
TuxGuitar (HKLM\...\{03534DA5-2F88-4B8E-A978-849B979E1B8F}) (Version: 1.2 - Herac)
UltraEdit (HKLM\...\InstallShield_{635A6AF2-63AF-4C1C-AF57-BDC8AF6D397D}) (Version: 21.00.1030 - IDM Computer Solutions, Inc.)
UltraEdit (Version: 21.00.1030 - IDM Computer Solutions, Inc.) Hidden
Uninstall 1.0.0.1 (HKLM\...\Uninstall_is1) (Version:  - )
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2883097) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{B2260BC9-D561-46EE-B33D-739CF760A2A9}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
UseNeXT by Tangysoft (HKLM\...\UseNeXT by Tangysoft_is1) (Version:  - Tangysoft Ltd.)
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden
VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Vuzix JPS Viewer (HKLM\...\{B5EE99C3-4265-4744-A8FD-2CF27448224F}) (Version: 1.2.0 - Vuzix Corporation)
WIDCOMM Bluetooth Software (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.1.800 - Broadcom Corporation)
Winamp (HKLM\...\Winamp) (Version: 5.666  - Nullsoft, Inc)
Windows Driver Package - Broadcom Bluetooth  (05/27/2009 6.1.7100.0) (HKLM\...\97CEB8209F0BC014131F0864966F5B9C9345570E) (Version: 05/27/2009 6.1.7100.0 - Broadcom)
Windows Driver Package - Broadcom Bluetooth  (09/11/2009 6.2.0.9407) (HKLM\...\755087041320E005CB1E8A67C5C55A260EB81B90) (Version: 09/11/2009 6.2.0.9407 - Broadcom)
Windows Driver Package - Broadcom HIDClass  (07/28/2009 6.2.0.9800) (HKLM\...\BF20603967CFDCB2BBF91950E8A56DFBC5C833FE) (Version: 07/28/2009 6.2.0.9800 - Broadcom)
Windows Live Anmelde-Assistent (HKLM\...\{52B97218-98CB-4B8B-9283-D213C85E1AA4}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Call (Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live Communications Platform (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Essentials (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Windows Live Mail (Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live Movie Maker (Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live Writer (Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live-Uploadtool (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
WinPcap 4.1.3 (HKLM\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.01 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
XnView 2.04 (HKLM\...\XnView_is1) (Version: 2.04 - Gougelet Pierre-e)
YTD Video Downloader 4.7.1 (HKLM\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.7.1 - GreenTree Applications SRL)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-1968336941-2077682222-3779713142-1000_Classes\CLSID\{b5eedee0-c06e-11cf-8c56-444553540000}\InprocServer32 -> C:\Program Files\IDM Computer Solutions\UltraEdit\ue32ctmn.dll ()

==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2013-11-02 00:34 - 00000994 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 secure.tune-up.com
127.0.0.1 order.tune-up.com 
127.0.0.1 tune-up.com 
127.0.0.1 tune-up.com/order 
127.0.0.1 registertuneup.com 
127.0.0.1 tuneup.de


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {07C4C0EF-AE93-4303-8D9A-7767E06B7742} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {1A289804-2D25-4FD9-852E-8CE7A1AC59A5} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-07-25] (Oracle Corporation)
Task: {27C2D42F-7803-4670-AD82-EDAB6E6CDDAF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-07-14] (Google Inc.)
Task: {2841D758-44E6-4A5B-9245-B143914FB5A4} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {34995584-B6DF-4319-9216-471C15CC2BC2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-12] (Adobe Systems Incorporated)
Task: {5248392A-04E7-4E45-BE87-715DF331E715} - System32\Tasks\Divx-Online-Aktualisierungsprogramm => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2013-08-29] ()
Task: {6F4B7A0C-6445-4F01-AE09-1B31D44F7C49} - System32\Tasks\Divx online update program => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2013-08-29] ()
Task: {7D81FF86-1DAB-413F-9B8C-EA669352E5C0} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {835D57BD-0D1A-4393-90A6-9D5C9D994A2A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-07-14] (Google Inc.)
Task: {C9220707-5352-4D3B-A1F0-D182E6CE838C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-08-12 21:31 - 2012-02-24 10:31 - 00307456 _____ () C:\Program Files\NETGEAR\WNA3100M\WifiSvc.exe
2014-08-12 21:31 - 2012-04-18 13:20 - 00413696 _____ () C:\Program Files\NETGEAR\WNA3100M\WifiLib.dll
2010-09-07 16:57 - 2009-11-10 14:42 - 00053248 _____ () C:\Program Files\FSP\KbdHook.dll
2010-09-07 16:57 - 2009-11-10 14:42 - 00073728 _____ () C:\Program Files\FSP\FspLib.dll
2014-06-27 13:20 - 2014-08-15 22:43 - 03800688 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2013-08-22 21:47 - 2009-12-09 21:20 - 00126976 _____ () C:\Program Files\PEARL\11n USB Wireless LAN Utility\EnumDevLib.dll
2014-08-12 21:31 - 2012-05-02 10:02 - 08253696 _____ () C:\Program Files\NETGEAR\WNA3100M\WNA3100M.exe
2014-08-12 21:31 - 2011-12-22 14:03 - 00278528 _____ () C:\Program Files\NETGEAR\WNA3100M\WifiSvcLib.dll
2014-06-04 13:20 - 2014-03-15 01:26 - 82785575 _____ () C:\Usedown\wizard\RAR.Repair.Advanced.RAR.Repair.v1.0.Retail-ZWT - (\RAR.Repair.Advanced.RAR.Repair.v1.0.Retail-ZWT.exe

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\d*****a\Desktop\Facebook.website:TASKICON_0news964078814
AlternateDataStreams: C:\Users\d*****a\Desktop\Facebook.website:TASKICON_1messages523453257
AlternateDataStreams: C:\Users\d*****a\Desktop\Facebook.website:TASKICON_2events-954496249
AlternateDataStreams: C:\Users\d*****a\Desktop\Facebook.website:TASKICON_3friends2073392651

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BsScanner => ""="Service"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: CNAP2 Launcher => C:\Windows\system32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE
MSCONFIG\startupreg: DivXMediaServer => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
MSCONFIG\startupreg: DivXUpdate => "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: mobilegeni daemon => C:\Program Files\Mobogenie\DaemonProcess.exe
MSCONFIG\startupreg: PixelPlanet PdfPrinter-Monitor => "C:\Program Files\Common Files\PixelPlanet\PdfPrinter 6\PdfPrinterMonitor.exe"

==================== Faulty Device Manager Devices =============

Could not list Devices. Check "winmgmt" service or repair WMI.


==================== Event log errors: =========================

Application errors:
==================
Error: (08/23/2014 02:22:10 PM) (Source: Microsoft Office 12) (EventID: 2001) (User: )
Description: Rejected Safe Mode action : Microsoft Office Outlook.

Error: (08/23/2014 00:32:13 PM) (Source: SideBySide) (EventID: 63) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.

Error: (08/23/2014 00:05:25 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - Fehler beim Initialisieren der Profilerstellungs-API-Anfügeinfrastruktur. Dieser Prozess ermöglicht einem Profiler das Anfügen nicht. HRESULT: 0x80004005.  Prozess-ID (dezimal): 4200. Meldungs-ID: [0x2509].

Error: (08/23/2014 00:04:56 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - Fehler beim Initialisieren der Profilerstellungs-API-Anfügeinfrastruktur. Dieser Prozess ermöglicht einem Profiler das Anfügen nicht. HRESULT: 0x80004005.  Prozess-ID (dezimal): 3956. Meldungs-ID: [0x2509].

Error: (08/22/2014 08:37:26 PM) (Source: SideBySide) (EventID: 63) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.

Error: (08/22/2014 06:02:53 PM) (Source: SideBySide) (EventID: 63) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.

Error: (08/21/2014 10:37:32 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm OUTLOOK.EXE, Version 12.0.6691.5000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 2b10

Startzeit: 01cfbd40d5109840

Endzeit: 22947

Anwendungspfad: C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE

Berichts-ID: 9c823b8e-2953-11e4-8af3-7071bc5383ef

Error: (08/20/2014 00:25:51 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 55349

Error: (08/20/2014 00:25:51 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 55349

Error: (08/20/2014 00:25:51 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


System errors:
=============
Error: (08/23/2014 03:59:00 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Kaspersky Anti-Virus Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (08/23/2014 03:28:03 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (08/23/2014 03:02:57 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \...\DR3 gefunden.

Error: (08/23/2014 02:56:55 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst RealtekCU erreicht.

Error: (08/23/2014 00:51:30 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk3\DR3 gefunden.

Error: (08/23/2014 00:45:49 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk3\DR3 gefunden.

Error: (08/23/2014 00:43:31 PM) (Source: WMPNetworkSvc) (EventID: 14365) (User: )
Description: 0x80004004-1

Error: (08/23/2014 11:59:48 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.

Error: (08/23/2014 11:54:49 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst RealtekCU erreicht.

Error: (08/23/2014 01:46:20 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}


Microsoft Office Sessions:
=========================
Error: (03/30/2014 10:14:11 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 516757 seconds with 2100 seconds of active time.  This session ended with a crash.

Error: (03/18/2014 08:47:52 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6680.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 68590 seconds with 780 seconds of active time.  This session ended with a crash.

Error: (11/17/2013 10:17:01 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6680.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 12997 seconds with 5400 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
  Date: 2014-08-22 20:45:31.438
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-08-22 20:45:31.428
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-08-22 20:45:31.418
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-08-22 20:45:31.096
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-08-22 20:45:30.906
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-08-22 20:45:30.839
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-08-22 20:45:29.826
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-08-22 20:45:29.776
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-08-22 20:45:29.696
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-08-22 20:45:29.586
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info =========================== 

Processor: Intel(R) Atom(TM) CPU N455 @ 1.66GHz
Percentage of memory in use: 67%
Total physical RAM: 2038.21 MB
Available physical RAM: 656.68 MB
Total Pagefile: 6114.21 MB
Available Pagefile: 3838.69 MB
Total Virtual: 2047.88 MB
Available Virtual: 1905.87 MB

==================== Drives ================================

Drive c: (Boot) (Fixed) (Total:201.78 GB) (Free:38.34 GB) NTFS
Drive d: (Recover) (Fixed) (Total:30 GB) (Free:1.52 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 232.9 GB) (Disk ID: 8A210AA2)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=201.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=30 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)

==================== End Of Log ============================
         
Code:
ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-08-23 21:22:31
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD2500BEVT-00A23T0 rev.01.01A01 232,89GB
Running: Gmer-19357.exe; Driver: C:\Users\*******\AppData\Local\Temp\kxxiiaow.sys


---- System - GMER 2.1 ----

SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwAdjustPrivilegesToken [0x8C2A0990]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwAlpcConnectPort [0x8C2511CE]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwAlpcSendWaitReceivePort [0x8C251400]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwConnectPort [0x8C250FC8]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwCreateSection [0x8C2A355C]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwCreateThread [0x8C2A298C]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwCreateThreadEx [0x8C2A2BD8]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwDebugActiveProcess [0x8C2A251E]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwDeviceIoControlFile [0x8C241640]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwDuplicateObject [0x8C2A0AD2]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwLoadDriver [0x8C2A05FE]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwMapViewOfSection [0x8C2A3312]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwOpenProcess [0x8C2A2052]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwOpenSection [0x8C2A378C]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwOpenThread [0x8C2A267E]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwQueueApcThread [0x8C2A31C6]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwRequestWaitReplyPort [0x8C2512D4]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwResumeThread [0x8C2A2EE2]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwSecureConnectPort [0x8C2510C8]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwSetContextThread [0x8C2A3048]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwSetInformationToken [0x8C241A5A]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwSetSystemInformation [0x8C2A0936]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwSuspendProcess [0x8C2A225A]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwSuspendThread [0x8C2A2D82]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwSystemDebugControl [0x8C241A6C]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwTerminateProcess [0x8C2A23C0]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwTerminateThread [0x8C2A2882]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwUnmapViewOfSection [0x8C2A3894]
SSDT            \SystemRoot\system32\DRIVERS\klif.sys                                                                               ZwWriteVirtualMemory [0x8C2A361E]

Code            AC148BFC                                                                                                            ZwTraceEvent
Code            AC148BFB                                                                                                            NtTraceEvent

---- Kernel code sections - GMER 2.1 ----

.text           ntkrnlpa.exe!ZwRollbackEnlistment + 142D                                                                            8204BA15 1 Byte  [06]
.text           ntkrnlpa.exe!KiDispatchInterrupt + 5A2                                                                              82085212 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text           ntkrnlpa.exe!KeRemoveQueueEx + 10D7                                                                                 8208C46C 4 Bytes  [90, 09, 2A, 8C]
.text           ntkrnlpa.exe!KeRemoveQueueEx + 10FF                                                                                 8208C494 4 Bytes  [CE, 11, 25, 8C]
.text           ntkrnlpa.exe!KeRemoveQueueEx + 1143                                                                                 8208C4D8 4 Bytes  [00, 14, 25, 8C]
.text           ntkrnlpa.exe!KeRemoveQueueEx + 1193                                                                                 8208C528 4 Bytes  [C8, 0F, 25, 8C] {ENTER 0x250f, 0x8c}
.text           ntkrnlpa.exe!KeRemoveQueueEx + 11F7                                                                                 8208C58C 4 Bytes  [5C, 35, 2A, 8C]
.text           ...                                                                                                                 
.text           ntkrnlpa.exe!NtTraceEvent                                                                                           820D5AE2 5 Bytes  JMP AC148C00 

---- User code sections - GMER 2.1 ----

?               C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe[1804] C:\Windows\SYSTEM32\ntdll.dll       time/date stamp mismatch; 
.text           C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe[1804] ntdll.dll!NtProtectVirtualMemory    77895F58 5 Bytes  JMP 6F701ED6 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ushata.dll
?               C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe[1804] C:\Windows\system32\kernel32.dll    time/date stamp mismatch; unknown module: KERNELBASE.dll
.text           C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe[1804] USER32.dll!NotifyWinEvent + 5B2     7779D570 4 Bytes  [0B, 26, 70, 6F] {OR ESP, [ESI]; JO 0x73}
.text           C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe[1804] USER32.dll!NotifyWinEvent + 6AE     7779D66C 4 Bytes  [1B, 2F, 70, 6F] {SBB EBP, [EDI]; JO 0x73}
?               C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe[1804] C:\Windows\system32\ole32.dll       time/date stamp mismatch; unknown module: CRYPTSP.dllunknown module: MPR.dllunknown module: msiltcfg.dllunknown module: CLBCatQ.DLLunknown module: OLEAUT32.dllunknown module: imagehlp.dllunknown module: KERNELBASE.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3960] ntdll.dll!NtCreateFile                                           77895608 5 Bytes  JMP 63BC3D20 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3960] ntdll.dll!NtFlushBuffersFile                                     77895998 5 Bytes  JMP 63BAC661 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3960] ntdll.dll!NtQueryFullAttributesFile                              77896028 5 Bytes  JMP 63BC3820 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3960] ntdll.dll!NtReadFile                                             778962F8 5 Bytes  JMP 63BAC750 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3960] ntdll.dll!NtReadFileScatter                                      77896308 5 Bytes  JMP 6444E1FF C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3960] ntdll.dll!NtWriteFile                                            77896AA8 5 Bytes  JMP 63BC43D0 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3960] ntdll.dll!NtWriteFileGather                                      77896AB8 5 Bytes  JMP 6444E1AE C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3960] ntdll.dll!LdrLoadDll                                             778B22AE 5 Bytes  JMP 677B1F4C C:\Program Files\Mozilla Firefox\mozglue.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3960] kernel32.dll!K32GetDeviceDriverBaseNameW + 5D                    763294E6 7 Bytes  JMP 643EF55F C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3960] kernel32.dll!QueryPerformanceCounter + 13                        7632C4E5 7 Bytes  JMP 643EF582 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3960] kernel32.dll!LoadAppInitDlls + 355                               7632F5A6 7 Bytes  JMP 63BC06F3 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3960] USER32.dll!GetWindowInfo                                         77794B5E 5 Bytes  JMP 642FE5A9 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3960] GDI32.dll!GetViewportOrgEx + 26C                                 7773884B 1 Byte  [E9]
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3960] GDI32.dll!GetViewportOrgEx + 26C                                 7773884B 7 Bytes  JMP 643EF4E0 C:\Program Files\Mozilla Firefox\xul.dll
?               C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe[5744] C:\Windows\system32\kernel32.dll  time/date stamp mismatch; unknown module: KERNELBASE.dll
?               C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe[5744] C:\Windows\system32\USER32.dll    time/date stamp mismatch; unknown module: CFGMGR32.dllunknown module: MSIMG32.dllunknown module: POWRPROF.dllunknown module: WINSTA.dll
.text           C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe[5744] USER32.dll!NotifyWinEvent + 5B2   7779D570 4 Bytes  [0B, 26, 70, 6F] {OR ESP, [ESI]; JO 0x73}
.text           C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe[5744] USER32.dll!NotifyWinEvent + 6AE   7779D66C 4 Bytes  [1B, 2F, 70, 6F] {SBB EBP, [EDI]; JO 0x73}

---- User IAT/EAT - GMER 2.1 ----

IAT             C:\Windows\Explorer.EXE[2520] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                                     [7463249F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT             C:\Windows\Explorer.EXE[2520] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                                [74615652] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT             C:\Windows\Explorer.EXE[2520] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                               [74615710] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT             C:\Windows\Explorer.EXE[2520] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                                      [7463251A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT             C:\Windows\Explorer.EXE[2520] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                            [7462857E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT             C:\Windows\Explorer.EXE[2520] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                              [74624D32] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT             C:\Windows\Explorer.EXE[2520] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                             [746250D9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT             C:\Windows\Explorer.EXE[2520] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                            [746251AE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT             C:\Windows\Explorer.EXE[2520] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP]                   [746266DB] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT             C:\Windows\Explorer.EXE[2520] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                             [746282D5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT             C:\Windows\Explorer.EXE[2520] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]                        [74628824] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT             C:\Windows\Explorer.EXE[2520] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]                      [74629085] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT             C:\Windows\Explorer.EXE[2520] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                            [7462E228] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT             C:\Windows\Explorer.EXE[2520] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                                [74624C64] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll

---- Devices - GMER 2.1 ----

AttachedDevice  \Driver\tdx \Device\Tcp                                                                                             kltdi.sys
AttachedDevice  \Driver\tdx \Device\Udp                                                                                             kltdi.sys
AttachedDevice  \Driver\tdx \Device\RawIp                                                                                           kltdi.sys

---- Registry - GMER 2.1 ----

Reg             HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\1c4bd600708c                                         
Reg             HKLM\SYSTEM\CurrentControlSet\services\KLIF\Parameters@LastProcessedRevision                                        21232000
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                    
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                 C:\Program Files\DAEMON Tools Lite\
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                 0x00 0x00 0x00 0x00 ...
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                 0
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                              0x91 0xB7 0xC4 0x41 ...
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001                           
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                        0xA0 0x02 0x00 0x00 ...
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                     0x2C 0xBB 0xD4 0xF9 ...
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0                      
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                0xB0 0x4A 0xDA 0x04 ...
Reg             HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\1c4bd600708c (not active ControlSet)                     
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)                
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                     C:\Program Files\DAEMON Tools Lite\
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                     0x00 0x00 0x00 0x00 ...
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                     0
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                  0x91 0xB7 0xC4 0x41 ...
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)       
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                            0xA0 0x02 0x00 0x00 ...
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                         0x2C 0xBB 0xD4 0xF9 ...
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)  
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                    0xB0 0x4A 0xDA 0x04 ...

---- Disk sectors - GMER 2.1 ----

Disk            \Device\Harddisk0\DR0                                                                                               unknown MBR code

---- EOF - GMER 2.1 ----
         

Geändert von extradry3 (23.08.2014 um 23:33 Uhr)

Alt 24.08.2014, 06:01   #2
schrauber
/// the machine
/// TB-Ausbilder
 

win7: Kasperski Web-Anti-Virus blockt: obession.co.ua/loader/loadit.exe - Standard

win7: Kasperski Web-Anti-Virus blockt: obession.co.ua/loader/loadit.exe



hi,

Zitat:
127.0.0.1 secure.tune-up.com
127.0.0.1 order.tune-up.com
127.0.0.1 tune-up.com
127.0.0.1 tune-up.com/order
127.0.0.1 registertuneup.com
127.0.0.1 tuneup.de
alles von TuneUp deinstallieren da gecrackt.



Adware & Co. deinstallieren
  • Lade Dir bitte von hier Revo Uninstaller herunter.
  • Installiere und starte das Programm.
  • Suche im Uninstallerfeld nach den Programmen, die unter:

    diesen Zusatz haben:
  • Wähle die Programme nacheinander aus und klicke jedesmal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .





Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________

__________________

Antwort

Themen zu win7: Kasperski Web-Anti-Virus blockt: obession.co.ua/loader/loadit.exe
.exe, beitrag, block, blockt, dahinter, dauernd, dauernde, dvdvideosoft ltd., ebanking, entdeck, gefährliche, geöffnete, glaskugel, kasperski, kaspersky, kleines, loader, loadit.exe, melde, meldet, minute, minuten, obession.co.ua, seite, steckt, system, thema, warum, win, win7, öffnen




Ähnliche Themen: win7: Kasperski Web-Anti-Virus blockt: obession.co.ua/loader/loadit.exe


  1. loadit.exe als Virus taucht ständig auf !
    Plagegeister aller Art und deren Bekämpfung - 18.06.2015 (8)
  2. McAfee blockt alle paar minuten "loadit.exe"
    Log-Analyse und Auswertung - 27.02.2015 (11)
  3. http://obession.co.ua/loader/load.php?bid=root3&am
    Alles rund um Windows - 21.08.2014 (11)
  4. Anti Avira-Meldung TR/BProtector.Gen in Datei C:/ProgramData/Bitguard/2.7.1832.68/.../loader.dll
    Log-Analyse und Auswertung - 02.04.2014 (3)
  5. loadit.exe taucht dauernd wieder auf, glücklicherweise inkompatibel mit 64bit WIN7 aber nervt
    Log-Analyse und Auswertung - 06.03.2014 (5)
  6. obession.co.ua/loader/loadit.exe
    Log-Analyse und Auswertung - 24.01.2014 (5)
  7. Kasperski meldet c:\windows\system32\fsvk.exe.exe, Wartungscenter Befall Win32/Small.CA Virus
    Log-Analyse und Auswertung - 04.11.2013 (7)
  8. Win7: Nach Anti-Malware Scan beim Herunterfahren, Absturz. Virus?
    Plagegeister aller Art und deren Bekämpfung - 04.10.2013 (9)
  9. MalwareBytes Anti-Malware blockt 4.26.235.126
    Antiviren-, Firewall- und andere Schutzprogramme - 05.03.2013 (0)
  10. TR/Sirefef.BV.2 Ständiger Zugriffsversuch aufs Internet. Anti - Malware blockt, findet aber nichts
    Plagegeister aller Art und deren Bekämpfung - 21.03.2012 (9)
  11. W32.katusha.BN blockt alle Scanner inlkusive Malwarebytes Anti-Malware
    Plagegeister aller Art und deren Bekämpfung - 21.09.2011 (5)
  12. Trojaner blockt Anti-Viren Software
    Log-Analyse und Auswertung - 11.07.2011 (10)
  13. kasperski meldet firefox als virus
    Plagegeister aller Art und deren Bekämpfung - 27.06.2011 (11)
  14. Trojaner blockt win7- firewall? - Fehlercode 0x8007042c
    Log-Analyse und Auswertung - 31.05.2011 (7)
  15. Win7 Anti-Virus 2011 und Windows Recovery
    Plagegeister aller Art und deren Bekämpfung - 08.05.2011 (3)
  16. Irgendwas blockt Anti-Spyware-Seiten und kompromittiert Combofix
    Plagegeister aller Art und deren Bekämpfung - 27.10.2009 (5)
  17. PC blockt die Ausführung von Anti-Malware-Programmen und Virenscannern
    Plagegeister aller Art und deren Bekämpfung - 12.07.2009 (34)

Zum Thema win7: Kasperski Web-Anti-Virus blockt: obession.co.ua/loader/loadit.exe - Hallo erstmal! Der geöffnete Kaspersky meldet alle 5 Minuten: gefährliche URL-Adresse wurde gesperrt. Drunter noch die URL: hxxp://obession.co.ua/loader/loadit.exe. Ich hab "obession.co.ua" gegoogelt und hab bei euch gleich einen Beitrag zu - win7: Kasperski Web-Anti-Virus blockt: obession.co.ua/loader/loadit.exe...
Archiv
Du betrachtest: win7: Kasperski Web-Anti-Virus blockt: obession.co.ua/loader/loadit.exe auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.