Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Blockandsurf win7 nicht los zu kriegen

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 03.02.2015, 22:57   #1
hatzi
 
Blockandsurf win7 nicht los zu kriegen - Standard

Blockandsurf win7 nicht los zu kriegen



Guten Abend,

trotz Norton 360 leider BlockAndSurf gefangen.
Ich hoffe es kann mir jemand helfen.

FRST wirft folgendes aus:
FRST.txt

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-02-2015
Ran by Juergen (administrator) on JUERGEN-NETBOOK on 03-02-2015 22:38:43
Running from C:\Users\Juergen\Downloads
Loaded Profiles: Juergen (Available profiles: Juergen)
Platform: Microsoft Windows 7 Starter  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.6.0.27\ccsvchst.exe
() C:\Program Files\USBLogon\usblonsvc.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.6.0.27\ccsvchst.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
() C:\Windows\vsnpstd3.exe
() C:\Windows\tsnpstd3.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_TATIHTU.EXE
() C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
() C:\Program Files\ownCloud\owncloud.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [USBLogon] => C:\Program Files\USBLogon\usblondetect.exe [12288 2013-10-01] (Quadsoft)
HKLM\...\Run: [Nikon Message Center 2] => C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM\...\Run: [snpstd3] => C:\Windows\vsnpstd3.exe [835584 2007-05-10] ()
HKLM\...\Run: [tsnpstd3] => C:\Windows\tsnpstd3.exe [339968 2009-06-30] ()
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_TATIHTU.EXE [220800 2013-08-02] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Run: [ownCloud] => C:\Program Files\ownCloud\owncloud.exe [23416869 2014-12-18] ()
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {42de7e31-5715-11e4-bbee-e0ca947c51af} - E:\LGAutoRun.exe
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {42de7e35-5715-11e4-bbee-e0ca947c51af} - E:\LGAutoRun.exe
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {4f677a70-6ca3-11e4-bbd1-e0ca947c51af} - D:\LGAutoRun.exe
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {4f7c33b7-32af-11e3-b87e-99da9e00c704} - D:\AutoRun.exe
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [  OCError] -> {0960F090-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCErrorShared] -> {0960F091-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOK] -> {0960F092-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOKShared] -> {0960F093-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSync] -> {0960F094-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSyncShared] -> {0960F095-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarning] -> {0960F096-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarningShared] -> {0960F097-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton 360\Engine\20.6.0.27\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton 360\Engine\20.6.0.27\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton 360\Engine\20.6.0.27\buShell.dll (Symantec Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton 360\Engine\20.6.0.27\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files\Norton 360\Engine\20.6.0.27\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.6.0.27\coIEPlg.dll (Symantec Corporation)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.6.1

FireFox:
========
FF ProfilePath: C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2065253504-3069135328-3144787471-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF Extension: KeeFox - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\keefox@chris.tomlinson [2015-01-15]
FF Extension: Bookmark Favicon Changer - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\bookmarkfaviconchanger@sonthakit.xpi [2013-08-02]
FF Extension: Firebug - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\firebug@software.joehewitt.com.xpi [2013-08-02]
FF Extension: Firepicker - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\firepicker@thedarkone.xpi [2013-08-02]
FF Extension: SQLite Manager - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\SQLiteManager@mrinalkant.blogspot.com.xpi [2014-12-31]
FF Extension: Delete Bookmark Icons - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{04514a2c-a3ab-4f47-8688-55f911b0fe75}.xpi [2013-08-02]
FF Extension: Showcase - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}.xpi [2013-08-02]
FF Extension: Password Exporter - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi [2013-08-02]
FF Extension: Adblock Plus - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-02]
FF Extension: Tab Mix Plus - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2013-08-02]
FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn [2015-02-03]

Chrome: 
=======
CHR Profile: C:\Users\Juergen\AppData\Local\Google\Chrome\User Data\default
CHR HKLM\...\Chrome\Extension: [bejnhdlplbjhffionohbdnpcbobfejcc] - C:\Program Files\Norton 360\Engine\20.6.0.27\Exts\Chrome.crx [2014-12-09]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 N360; C:\Program Files\Norton 360\Engine\20.6.0.27\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
R2 USBLogonService; C:\Program Files\USBLogon\usblonsvc.exe [12288 2013-10-01] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20150106.001\BHDrvx86.sys [1164504 2015-01-06] (Symantec Corporation)
R3 btwampfl; C:\Windows\system32\drivers\btwampfl.sys [508632 2015-01-16] (Broadcom Corporation.)
R1 ccSet_N360; C:\Windows\system32\drivers\N360\1406000.01B\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [378672 2014-12-13] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [111408 2014-12-13] (Symantec Corporation)
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20150130.001\IDSvix86.sys [503000 2015-01-13] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20150202.034\NAVENG.SYS [95704 2015-01-26] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20150202.034\NAVEX15.SYS [1636696 2015-01-26] (Symantec Corporation)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [15688 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [10320 2013-09-30] ()
S3 SNPSTD3; C:\Windows\System32\DRIVERS\snpstd3.sys [10526464 2009-07-03] (Sonix Co. Ltd.)
R3 SRTSP; C:\Windows\System32\Drivers\N360\1406000.01B\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360\1406000.01B\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360\1406000.01B\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360\1406000.01B\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-08-04] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360\1406000.01B\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360\1406000.01B\SYMNETS.SYS [339544 2013-04-25] (Symantec Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-03 22:38 - 2015-02-03 22:39 - 00014650 _____ () C:\Users\Juergen\Downloads\FRST.txt
2015-02-03 22:38 - 2015-02-03 22:38 - 01122304 _____ (Farbar) C:\Users\Juergen\Downloads\FRST.exe
2015-02-03 22:38 - 2015-02-03 22:38 - 00000000 ____D () C:\FRST
2015-02-03 22:17 - 2015-02-03 22:17 - 00000559 _____ () C:\Users\Juergen\Desktop\fixlist.txt
2015-02-03 22:16 - 2015-02-03 22:16 - 00000559 _____ () C:\Users\Juergen\Desktop\filelist.txt
2015-02-03 21:31 - 2015-02-03 21:31 - 11225840 _____ (SurfRight B.V.) C:\Users\Juergen\Downloads\hitmanpro_x64.exe
2015-02-03 21:06 - 2015-02-03 22:07 - 00000000 ____D () C:\AdwCleaner
2015-02-03 21:05 - 2015-02-03 21:05 - 02194432 _____ () C:\Users\Juergen\Downloads\adwcleaner_4.109.exe
2015-02-03 20:22 - 2015-02-03 21:38 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-03 20:21 - 2015-02-03 20:21 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-02-03 20:21 - 2015-02-03 20:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-02-03 20:21 - 2015-02-03 20:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-03 20:21 - 2015-02-03 20:21 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 
2015-02-03 20:21 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-03 20:21 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-03 20:21 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-03 20:20 - 2015-02-03 20:20 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Juergen\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-03 19:41 - 2015-02-03 19:41 - 00000000 ____D () C:\Users\Juergen\AppData\Local\FreeOCR
2015-02-03 19:35 - 2015-02-03 20:37 - 00000000 ____D () C:\FreeOCR
2015-02-03 19:35 - 2007-03-10 10:11 - 02680320 _____ (HiComponents) C:\Windows\system32\ImageEnXLibrary.ocx
2015-02-03 19:33 - 2015-02-03 19:33 - 00000000 ____D () C:\Program Files\Temp
2015-02-03 19:32 - 2015-02-03 19:32 - 00414625 _____ ( ) C:\Users\Juergen\Downloads\FreeOCR-5.02.exe
2015-02-03 19:32 - 2015-02-03 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2015-02-03 19:31 - 2015-02-03 19:32 - 00000000 ____D () C:\Program Files\PDFCreator
2015-02-03 19:31 - 2015-01-22 16:14 - 00098488 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2015-02-03 19:26 - 2015-02-03 19:26 - 27721680 _____ (pdfforge ) C:\Users\Juergen\Downloads\PDFCreator-2_0_2-setup.exe
2015-01-28 22:25 - 2015-01-28 22:25 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-01-28 22:25 - 2015-01-28 22:21 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2015-01-28 22:25 - 2015-01-28 22:21 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2015-01-28 22:25 - 2015-01-28 22:21 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-01-28 22:23 - 2015-01-28 22:23 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-01-18 21:05 - 2015-01-18 21:06 - 00000000 ____D () C:\Users\Juergen\ownCloudBoule
2015-01-18 20:59 - 2015-01-18 20:59 - 46286392 _____ (ownCloud) C:\Users\Juergen\Downloads\ownCloud-1.7.1.4382-setup(1).exe
2015-01-18 20:05 - 2014-12-11 18:47 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-18 20:05 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-01-18 11:03 - 2015-01-18 16:34 - 00001372 _____ () C:\Users\Juergen\Desktop\Dapile wecken.lnk
2015-01-18 11:00 - 2015-01-18 11:00 - 00000000 ____D () C:\Users\Juergen\AppData\Local\www.oette.info
2015-01-18 10:59 - 2015-01-18 10:59 - 00077936 _____ (Gammadyne Corporation) C:\Users\Juergen\Downloads\wol.exe
2015-01-18 10:55 - 2015-01-18 10:55 - 00000000 ____H () C:\Users\Juergen\Documents\Default.rdp
2015-01-18 10:46 - 2015-01-18 10:46 - 01964729 _____ () C:\Users\Juergen\Downloads\WOL2.7z
2015-01-18 00:30 - 2015-01-18 00:30 - 00039424 _____ () C:\Users\Juergen\Desktop\Hessen.xls
2015-01-18 00:25 - 2015-01-18 00:25 - 00035672 _____ () C:\Users\Juergen\Desktop\Mappe1.txt
2015-01-17 23:09 - 2015-01-17 23:09 - 00004290 _____ () C:\Users\Juergen\Desktop\karte_hessen.html
2015-01-17 23:08 - 2015-01-17 23:08 - 00004290 _____ () C:\Users\Juergen\Downloads\karte_hessen.html
2015-01-17 22:44 - 2015-01-17 22:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2015-01-17 22:44 - 2015-01-17 22:44 - 00000000 ____D () C:\Program Files\7-Zip
2015-01-17 22:40 - 2015-01-17 22:40 - 01110476 _____ () C:\Users\Juergen\Downloads\7z920.exe
2015-01-17 22:39 - 2015-01-17 22:39 - 01376768 _____ () C:\Users\Juergen\Downloads\7z920-x64.msi
2015-01-17 22:26 - 2015-01-17 22:26 - 00196096 _____ () C:\Users\Juergen\Desktop\DM-Meldung_2014.xls
2015-01-17 10:54 - 2013-10-02 00:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-01-17 10:53 - 2013-10-02 01:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2015-01-17 10:53 - 2013-10-02 01:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-01-17 10:53 - 2013-10-02 01:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-01-17 10:53 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2015-01-17 10:53 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2015-01-17 10:53 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-01-17 10:53 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-01-17 10:53 - 2013-10-01 23:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-01-17 10:53 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-01-17 00:47 - 2015-01-17 00:49 - 00004270 _____ () C:\Users\Juergen\Desktop\karte_hallen.html
2015-01-16 16:31 - 2015-01-17 01:48 - 00284672 _____ () C:\Users\Juergen\Desktop\d5c41_joodb_spielorte-1.xls
2015-01-16 16:18 - 2015-01-16 16:18 - 00171501 _____ () C:\Users\Juergen\Downloads\d5c41_joodb_spielorte.csv
2015-01-16 14:53 - 2015-01-16 14:57 - 00004305 _____ () C:\Users\Juergen\Desktop\karte_gesamt.html
2015-01-16 08:47 - 2015-01-16 08:47 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte
2015-01-16 08:46 - 2015-01-16 08:46 - 00000000 ____D () C:\Users\Juergen\Documents\Bluetooth-Exchange-Ordner
2015-01-16 08:46 - 2015-01-16 08:46 - 00000000 ____D () C:\Users\Juergen\AppData\Local\Broadcom
2015-01-16 08:46 - 2015-01-16 08:35 - 00508632 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwampfl.sys
2015-01-16 08:39 - 2015-01-16 08:39 - 00001125 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Problem Report.lnk
2015-01-16 08:38 - 2015-01-16 08:35 - 00175144 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwavdt.sys
2015-01-16 08:38 - 2015-01-16 08:35 - 00152400 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwaudio.sys
2015-01-16 08:38 - 2015-01-16 08:35 - 00033832 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwl2cap.sys
2015-01-16 08:38 - 2015-01-16 08:35 - 00018728 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwrchid.sys
2015-01-16 08:36 - 2015-01-16 08:36 - 00000000 ____D () C:\Program Files\WIDCOMM
2015-01-16 08:23 - 2015-01-16 08:23 - 04171576 _____ (Broadcom Corporation.) C:\Users\Juergen\Downloads\SetupBtwDownloadSE.exe
2015-01-15 23:31 - 2014-12-19 03:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-15 23:31 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-01-15 23:31 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-15 23:30 - 2014-12-19 02:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-15 23:30 - 2014-12-06 04:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-15 00:08 - 2015-01-15 00:08 - 00771699 _____ () C:\Users\Juergen\Desktop\OpenLayers.js
2015-01-14 23:54 - 2015-01-14 23:54 - 00014336 _____ () C:\Users\Juergen\Desktop\pois.xls
2015-01-14 23:27 - 2015-01-15 00:03 - 00000701 _____ () C:\Users\Juergen\Desktop\dbcsv.php
2015-01-14 23:27 - 2015-01-14 23:29 - 00000207 _____ () C:\Users\Juergen\Desktop\dbconnect.php
2015-01-14 23:26 - 2015-01-15 00:17 - 00004251 _____ () C:\Users\Juergen\Desktop\karte.html
2015-01-14 23:25 - 2015-01-14 23:25 - 00258079 _____ () C:\Users\Juergen\Desktop\basic.html
2015-01-11 15:46 - 2015-01-18 21:02 - 00000981 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ownCloud.lnk
2015-01-11 15:45 - 2015-01-11 15:46 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-11 15:41 - 2015-01-11 15:43 - 46286392 _____ (ownCloud) C:\Users\Juergen\Downloads\ownCloud-1.7.1.4382-setup.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-03 22:32 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-02-03 22:18 - 2013-10-06 19:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-03 22:15 - 2009-07-14 05:34 - 00016352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-03 22:15 - 2009-07-14 05:34 - 00016352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-03 22:13 - 2013-07-30 17:54 - 01865468 _____ () C:\Windows\WindowsUpdate.log
2015-02-03 22:08 - 2010-11-20 22:48 - 00137298 _____ () C:\Windows\PFRO.log
2015-02-03 22:08 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-03 22:08 - 2009-07-14 05:39 - 00045827 _____ () C:\Windows\setupact.log
2015-02-03 20:58 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system
2015-02-03 20:40 - 2013-11-18 21:26 - 00000000 ____D () C:\Users\Juergen\ownCloud
2015-02-03 20:38 - 2013-12-09 20:21 - 00000000 ____D () C:\Program Files\Free mp3 Wma Converter
2015-02-03 07:00 - 2013-08-01 07:05 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-01-28 22:27 - 2014-01-29 21:09 - 00000000 ____D () C:\ProgramData\Oracle
2015-01-28 22:22 - 2014-10-18 08:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-01-28 22:21 - 2014-10-18 08:53 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2015-01-28 22:20 - 2014-08-18 12:29 - 00000000 ____D () C:\Program Files\Java
2015-01-25 10:40 - 2013-08-03 15:56 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-01-25 10:40 - 2013-08-03 15:56 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-01-20 21:08 - 2014-08-18 12:36 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\vlc
2015-01-20 19:47 - 2014-08-19 12:48 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\dvdcss
2015-01-20 19:43 - 2010-11-20 22:01 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-18 21:03 - 2013-11-18 21:25 - 00000000 ____D () C:\Users\Juergen\AppData\Local\ownCloud
2015-01-18 21:02 - 2013-11-18 21:25 - 00000000 ____D () C:\Program Files\ownCloud
2015-01-18 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-01-18 11:20 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-01-18 10:49 - 2013-08-02 10:14 - 00000000 ___RD () C:\Users\Juergen\Desktop\Programme
2015-01-17 11:05 - 2009-07-14 03:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-17 11:04 - 2011-03-20 08:51 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE
2015-01-16 08:01 - 2013-08-24 01:37 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\Mp3tag
2015-01-15 23:39 - 2013-08-02 09:17 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-15 23:32 - 2013-07-31 21:58 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-15 23:28 - 2013-08-25 09:04 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\foobar2000
2015-01-11 16:58 - 2014-12-13 12:36 - 00000000 ____D () C:\Users\Juergen\Desktop\Desktop Ablage 20141213
2015-01-04 09:54 - 2014-12-29 22:51 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\FileZilla

==================== Files in the root of some directories =======

2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Ambience
2013-12-05 20:12 - 2013-12-05 20:12 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Ambient
2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Analog Mono
2013-12-05 20:07 - 2013-12-05 20:07 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Audio Units
2013-12-05 21:07 - 2013-12-05 21:07 - 0003584 _____ () C:\Users\Juergen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-08-04 10:14 - 2013-08-04 10:14 - 0000600 _____ () C:\Users\Juergen\AppData\Local\PUTTY.RND
2014-11-15 16:21 - 2014-11-15 16:21 - 0000218 _____ () C:\Users\Juergen\AppData\Local\recently-used.xbel
2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\ProgramData\Analog Swirl
2013-12-05 20:12 - 2013-12-05 20:12 - 0000268 ___RH () C:\ProgramData\Analog Sync
2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\ProgramData\Animals
2013-12-05 20:12 - 2013-12-05 20:12 - 0000012 ___RH () C:\ProgramData\Basic Track
2013-12-05 20:09 - 2013-12-05 20:09 - 0000012 ___RH () C:\ProgramData\Bass
2013-12-05 20:07 - 2013-12-05 20:09 - 0000012 ___RH () C:\ProgramData\BSD
2013-12-05 20:07 - 2013-12-05 20:07 - 0000012 ___RH () C:\ProgramData\ColorSync
2013-12-05 20:07 - 2013-12-05 20:08 - 0000020 ____H () C:\ProgramData\PKP_DLeo.DAT
2013-12-05 20:12 - 2014-01-25 13:02 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT
2013-12-05 20:09 - 2014-11-12 09:25 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT
2013-12-05 20:09 - 2014-11-12 09:35 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT

Some content of TEMP:
====================
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.dll
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.exe
C:\Users\Juergen\AppData\Local\Temp\DE83F836-32DF-FEC7-3997-961617D0D8B7.exe
C:\Users\Juergen\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Juergen\AppData\Local\Temp\Quarantine.exe
C:\Users\Juergen\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-14 22:51

==================== End Of Log ============================
         
--- --- ---

Addition.txt
Zitat:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 01-02-2015
Ran by Juergen at 2015-02-03 22:40:25
Running from C:\Users\Juergen\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton 360 Online (Disabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton 360 Online (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton 360 Online (Disabled) {6BFC5632-188D-B806-D13E-C607121B42A0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (HKLM\...\7-Zip) (Version: - )
Acoustica Standard Edition 5.0 (HKLM\...\Acoustica Standard Edition_is1) (Version: 5.0 - Acon AS)
Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Amazon MP3-Downloader 1.0.18 (HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC)
AppInventor Setup (HKLM\...\AppInventor Setup) (Version: 2.2 - Massachusetts Institute of Technology)
Apple Application Support (HKLM\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.4852 - CDBurnerXP)
Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6514.5001 - Microsoft Corporation)
Download Navigator (HKLM\...\{E728441A-7820-4B1C-87C9-DE7BE37B2953}) (Version: 1.1.0 - SEIKO EPSON CORPORATION)
ElsterFormular (HKLM\...\ElsterFormular) (Version: 14.4.20130909 - Landesfinanzdirektion Thüringen)
EPSON BX535WD Series Printer Uninstall (HKLM\...\EPSON BX535WD Series) (Version: - SEIKO EPSON Corporation)
Epson Easy Photo Print 2 (HKLM\...\{FFF841F3-9A15-4F61-BD16-C19F132E5A27}) (Version: 2.3.0.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION2)
Epson Event Manager (HKLM\...\{FA9D303D-0FB2-49C7-9397-8E6B11EA892D}) (Version: 2.50.0001 - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.4j - SEIKO EPSON CORPORATION)
Extended Asian Language font pack for Adobe Reader XI (HKLM\...\{AC76BA86-7AD7-2530-0000-A00000000004}) (Version: 11.0.0 - Adobe Systems Incorporated)
FFmpeg v0.6.2 for Audacity (HKLM\...\FFmpeg for Audacity_is1) (Version: - )
FileZilla Client 3.9.0.6 (HKLM\...\FileZilla Client) (Version: 3.9.0.6 - Tim Kosse)
FLAC 1.2.1b (remove only) (HKLM\...\FLAC) (Version: 1.2.1b - Xiph.org)
foobar2000 v1.3 (HKLM\...\foobar2000) (Version: 1.3 - Peter Pawlowski)
FreeFileSync 6.8 (HKLM\...\FreeFileSync) (Version: 6.8 - Zenju)
Freemake Audio Converter Version 1.1.0 (HKLM\...\Freemake Audio Converter_is1) (Version: 1.1.0 - Ellora Assets Corporation)
Frontplatten Designer (HKLM\...\Frontplatten Designer) (Version: 4.3.1 - Schaeffer AG)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
inSSIDer Home (HKLM\...\{9E54E4AE-B67A-4925-8E92-0E1F9817FD73}) (Version: 3.1.2.1 - MetaGeek, LLC)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.14.10.2117 - Intel Corporation)
iTunes (HKLM\...\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
Java 8 Update 31 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Kinovea (HKLM\...\Kinovea) (Version: 0.8.15 - Kinovea) <==== ATTENTION!
LAME v3.99.3 (for Windows) (HKLM\...\LAME_is1) (Version: - )
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM\...\{90110407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
MiniTool Partition Wizard Home Edition 8.1.1 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Solution Ltd.)
Mozilla Firefox 35.0.1 (x86 de) (HKLM\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mp3tag v2.64 (HKLM\...\Mp3tag) (Version: v2.64 - Florian Heidenreich)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nikon Message Center 2 (HKLM\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon)
Nikon Movie Editor (HKLM\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.8.0 - Nikon)
Norton 360 (HKLM\...\N360) (Version: 20.6.0.27 - Symantec Corporation)
Notepad++ (HKLM\...\Notepad++) (Version: 6.6.9 - Notepad++ Team)
ownCloud (HKLM\...\ownCloud) (Version: 1.7.1.4382 - ownCloud)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.2 - pdfforge)
Picture Control Utility (HKLM\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.4.15 - Nikon)
Softsqueeze 3.9b2 (HKLM\...\Softsqueeze 3.9b2) (Version: - Ralph Irving)
Trust Webcam (HKLM\...\{ECD03DA7-5952-406A-8156-5F0C93618D1F}) (Version: 5.18.1211.103 - Sonix)
USBLogon 1.6.2.3 (HKLM\...\{E7D9D138-7DFA-441A-B1A9-703193C5D6D3}_is1) (Version: 1.6.2.3 - Quadsoft)
ViewNX 2 (HKLM\...\{E64C137C-D0B7-467A-B47F-460AAB30F0A3}) (Version: 2.8.2 - Nikon)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
WIDCOMM Bluetooth Software (HKLM\...\{A1439D4F-FD46-47F2-A1D3-FEE097C29A09}) (Version: 6.5.1.5800 - Broadcom Corporation)
WinRAR 4.20 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{00B7E0AB-817A-44AD-A04B-D1148D524136}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{3f04dadf-6ea4-44d1-a507-03cad176f443}\InprocServer32 -> C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)

==================== Restore Points =========================

15-01-2015 23:31:24 Windows Update
16-01-2015 08:38:24 Broadcom BTW Restore Point
17-01-2015 09:17:28 Windows Update
18-01-2015 20:05:50 Windows Update
18-01-2015 21:01:25 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
03-02-2015 21:26:44 Norton 360 Registry Clean

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {06B6DDAB-AAB0-4D0B-B52A-F905DE9B6A9F} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files\Norton 360\Engine\20.6.0.27\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {196C89FF-F3D9-448B-B7C1-92B1A0935C07} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton 360\Engine\20.6.0.27\WSCStub.exe [2014-12-06] (Symantec Corporation)
Task: {485B4A61-78AF-4C9E-A9CC-B8529DC8CE1B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-25] (Adobe Systems Incorporated)
Task: {65FAAE39-54E7-4A39-B113-451EEB66F7D5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {850628D5-9DE8-48E0-A6CF-EF448C6902A6} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files\Norton 360\Engine\20.6.0.27\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {CB7C8110-39F3-4E02-B442-E083E9851C10} - System32\Tasks\{945E7209-E1C4-479E-A68B-7B35F0A2E979} => pcalua.exe -a C:\Users\Juergen\Downloads\softsqueeze_windows_3_9b2.exe -d C:\Users\Juergen\Downloads

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2014-10-11 12:06 - 2014-10-11 12:06 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-10-16 10:15 - 2014-10-16 10:15 - 00035328 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2014-05-24 17:41 - 2014-05-24 17:41 - 00091648 _____ () C:\Program Files\FileZilla FTP Client\libgcc_s_sjlj-1.dll
2014-05-24 17:41 - 2014-05-24 17:41 - 00892416 _____ () C:\Program Files\FileZilla FTP Client\libstdc++-6.dll
2013-11-04 13:23 - 2013-10-01 17:11 - 00012288 _____ () C:\Program Files\USBLogon\usblonsvc.exe
2014-12-09 16:50 - 2012-05-30 07:51 - 00699280 ____R () C:\PROGRAM FILES\NORTON 360\ENGINE\20.6.0.27\wincfi39.dll
2014-12-17 12:44 - 2014-12-17 12:44 - 00046592 _____ () C:\Program Files\ownCloud\shellext\OCUtil_x86.dll
2014-11-30 14:14 - 2007-05-10 13:18 - 00835584 _____ () C:\Windows\vsnpstd3.exe
2014-11-30 14:14 - 2009-06-30 16:20 - 00339968 _____ () C:\Windows\tsnpstd3.exe
2013-05-22 19:50 - 2013-05-22 19:50 - 00400704 _____ () C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
2014-12-18 12:53 - 2014-12-18 12:53 - 23416869 _____ () C:\Program Files\ownCloud\owncloud.exe
2014-12-18 12:53 - 2014-12-18 12:53 - 03044905 _____ () C:\Program Files\ownCloud\libocsync.dll
2014-09-24 09:23 - 2014-09-24 09:23 - 00158048 _____ () C:\Program Files\ownCloud\libneon-27.dll
2014-09-21 23:32 - 2014-09-21 23:32 - 00084012 _____ () C:\Program Files\ownCloud\zlib1.dll
2014-09-22 02:45 - 2014-09-22 02:45 - 00095790 _____ () C:\Program Files\ownCloud\libgcc_s_sjlj-1.dll
2014-09-22 02:13 - 2014-09-22 02:13 - 00172695 _____ () C:\Program Files\ownCloud\libproxy.dll
2014-09-22 02:11 - 2014-09-22 02:11 - 00042626 _____ () C:\Program Files\ownCloud\libmodman.dll
2014-09-22 02:45 - 2014-09-22 02:45 - 00847430 _____ () C:\Program Files\ownCloud\libstdc++-6.dll
2014-09-22 01:05 - 2014-09-22 01:05 - 01150984 _____ () C:\Program Files\ownCloud\libxml2-2.dll
2014-09-22 01:10 - 2014-09-22 01:10 - 02164003 _____ () C:\Program Files\ownCloud\icui18n53.dll
2014-09-22 01:10 - 2014-09-22 01:10 - 01288240 _____ () C:\Program Files\ownCloud\icuuc53.dll
2014-09-22 01:10 - 2014-09-22 01:10 - 21540519 _____ () C:\Program Files\ownCloud\icudata53.dll
2014-09-22 01:16 - 2014-09-22 01:16 - 00144533 _____ () C:\Program Files\ownCloud\libpcre16-0.dll
2014-09-22 01:15 - 2014-09-22 01:15 - 01345629 _____ () C:\Program Files\ownCloud\libGLESv2.dll
2014-09-22 00:58 - 2014-09-22 00:58 - 00203567 _____ () C:\Program Files\ownCloud\libpng16-16.dll
2014-12-18 12:53 - 2014-12-18 12:53 - 15901197 _____ () C:\Program Files\ownCloud\libowncloudsync.dll
2014-09-22 01:15 - 2014-09-22 01:15 - 00150916 _____ () C:\Program Files\ownCloud\libEGL.dll
2014-09-22 01:08 - 2014-09-22 01:08 - 00197062 _____ () C:\Program Files\ownCloud\libjpeg-8.dll
2014-09-22 01:13 - 2014-09-22 01:13 - 00646511 _____ () C:\Program Files\ownCloud\libsqlite3-0.dll
2014-09-22 02:28 - 2014-09-22 02:28 - 00247028 _____ () C:\Program Files\ownCloud\libwebp-4.dll
2014-09-22 03:24 - 2014-09-22 03:24 - 00228655 _____ () C:\Program Files\ownCloud\libxslt-1.dll
2014-09-24 08:38 - 2014-09-24 08:38 - 00052119 _____ () C:\Program Files\ownCloud\libqt5keychain.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00702136 _____ () C:\Program Files\ownCloud\platforms\qwindows.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00032568 _____ () C:\Program Files\ownCloud\imageformats\qgif.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00035173 _____ () C:\Program Files\ownCloud\imageformats\qico.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00048436 _____ () C:\Program Files\ownCloud\imageformats\qjpeg.dll
2015-01-28 22:25 - 2015-01-28 22:25 - 03925104 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2015-01-25 10:40 - 2015-01-25 10:40 - 16844976 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\Juergen\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Juergen\Desktop\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Public\Downloads\.DS_Store:AFP_AfpInfo

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


========================= Accounts: ==========================

Administrator (S-1-5-21-2065253504-3069135328-3144787471-500 - Administrator - Disabled)
Gast (S-1-5-21-2065253504-3069135328-3144787471-501 - Limited - Enabled)
Juergen (S-1-5-21-2065253504-3069135328-3144787471-1000 - Administrator - Enabled) => C:\Users\Juergen

==================== Faulty Device Manager Devices =============

Name: Generischer Marvell Yukon 88E8040-PCI-E-Fast-Ethernet-Controller
Description: Generischer Marvell Yukon 88E8040-PCI-E-Fast-Ethernet-Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Marvell
Service: yukonw7
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/03/2015 10:10:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 10:03:13 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (02/03/2015 09:48:01 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm adwcleaner_4.109.exe, Version 4.1.0.9 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: fa0

Startzeit: 01d03ff1cb531d5a

Endzeit: 31

Anwendungspfad: C:\Users\Juergen\Downloads\adwcleaner_4.109.exe

Berichts-ID:

Error: (02/03/2015 09:31:39 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (02/03/2015 09:14:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 09:00:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 08:41:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 07:02:51 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2015 11:20:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 35044267

Error: (02/02/2015 11:20:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 35044267


System errors:
=============
Error: (02/03/2015 10:08:53 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom

Error: (02/03/2015 09:58:59 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/03/2015 09:58:49 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/03/2015 09:58:42 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/03/2015 09:58:26 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/03/2015 09:58:21 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/03/2015 09:57:58 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/03/2015 09:57:53 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/03/2015 09:15:23 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {EA022610-0748-4C24-B229-6C507EBDFDBB}

Error: (02/03/2015 09:12:48 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom


Microsoft Office Sessions:
=========================
Error: (02/03/2015 10:10:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 10:03:13 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Users\Juergen\Downloads\hitmanp ro_x64.exe

Error: (02/03/2015 09:48:01 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: adwcleaner_4.109.exe4.1.0.9fa001d03ff1cb531d5a31C:\Users\Juergen\Downloads\adwcleaner_4.109.exe

Error: (02/03/2015 09:31:39 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Users\Juergen\Downloads\hitmanp ro_x64.exe

Error: (02/03/2015 09:14:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 09:00:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 08:41:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 07:02:51 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2015 11:20:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 35044267

Error: (02/02/2015 11:20:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 35044267


==================== Memory info ===========================

Processor: Intel(R) Atom(TM) CPU N455 @ 1.66GHz
Percentage of memory in use: 44%
Total physical RAM: 2037.3 MB
Available physical RAM: 1126.5 MB
Total Pagefile: 4074.59 MB
Available Pagefile: 3111.82 MB
Total Virtual: 2047.88 MB
Available Virtual: 1901.41 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:119.14 GB) (Free:12.64 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: E91F5269)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=119.1 GB) - (Type=07 NTFS)

==================== End Of Log ============================
Dank im voraus
Jürgen

Alt 03.02.2015, 23:00   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Blockandsurf win7 nicht los zu kriegen - Standard

Blockandsurf win7 nicht los zu kriegen



Hi,

Virenscanner vor dem Löschen mit den Tools bitte deaktivieren:

Adware/Junkware/Toolbars entfernen

(alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!)

1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.




3. Schritt: Frisches Log mit FRST

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________

__________________

Alt 03.02.2015, 23:33   #3
hatzi
 
Blockandsurf win7 nicht los zu kriegen - Standard

SChnelle Hilfe - Vielen Dank



Und hier die Files:
AdwCleaner:
AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v4.109 - Bericht erstellt am 03/02/2015 um 23:10:38
# Aktualisiert 24/01/2015 von Xplode
# Database : 2015-02-03.1 [Live]
# Betriebssystem : Windows 7 Starter Service Pack 1 (32 bits)
# Benutzername : Juergen - JUERGEN-NETBOOK
# Gestartet von : C:\Users\Juergen\Desktop\AdwCleaner_4.109(1).exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****


***** [ Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17496


-\\ Mozilla Firefox v35.0.1 (x86 de)


-\\ Google Chrome v


*************************

AdwCleaner[R0].txt - [5239 octets] - [03/02/2015 21:06:19]
AdwCleaner[R1].txt - [333 octets] - [03/02/2015 21:43:31]
AdwCleaner[R2].txt - [1238 octets] - [03/02/2015 22:03:26]
AdwCleaner[R3].txt - [1113 octets] - [03/02/2015 23:06:18]
AdwCleaner[S0].txt - [5452 octets] - [03/02/2015 21:11:45]
AdwCleaner[S1].txt - [1308 octets] - [03/02/2015 22:07:53]
AdwCleaner[S2].txt - [1035 octets] - [03/02/2015 23:10:38]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1095 octets] ##########
         
--- --- ---


JRT:
Zitat:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Starter x86
Ran by Juergen on 03.02.2015 at 23:14:15,82
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Emptied folder: C:\Users\Juergen\AppData\Roaming\mozilla\firefox\profiles\z20qwztm.default\minidumps [46 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.02.2015 at 23:22:13,60
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-02-2015
Ran by Juergen (administrator) on JUERGEN-NETBOOK on 03-02-2015 23:24:42
Running from C:\Users\Juergen\Desktop
Loaded Profiles: Juergen (Available profiles: Juergen)
Platform: Microsoft Windows 7 Starter  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.6.0.27\ccsvchst.exe
() C:\Program Files\USBLogon\usblonsvc.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.6.0.27\ccsvchst.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
() C:\Windows\vsnpstd3.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
() C:\Windows\tsnpstd3.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_TATIHTU.EXE
() C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
() C:\Program Files\ownCloud\owncloud.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [USBLogon] => C:\Program Files\USBLogon\usblondetect.exe [12288 2013-10-01] (Quadsoft)
HKLM\...\Run: [Nikon Message Center 2] => C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM\...\Run: [snpstd3] => C:\Windows\vsnpstd3.exe [835584 2007-05-10] ()
HKLM\...\Run: [tsnpstd3] => C:\Windows\tsnpstd3.exe [339968 2009-06-30] ()
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_TATIHTU.EXE [220800 2013-08-02] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Run: [ownCloud] => C:\Program Files\ownCloud\owncloud.exe [23416869 2014-12-18] ()
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {42de7e31-5715-11e4-bbee-e0ca947c51af} - E:\LGAutoRun.exe
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {42de7e35-5715-11e4-bbee-e0ca947c51af} - E:\LGAutoRun.exe
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {4f677a70-6ca3-11e4-bbd1-e0ca947c51af} - D:\LGAutoRun.exe
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {4f7c33b7-32af-11e3-b87e-99da9e00c704} - D:\AutoRun.exe
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [  OCError] -> {0960F090-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCErrorShared] -> {0960F091-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOK] -> {0960F092-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOKShared] -> {0960F093-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSync] -> {0960F094-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSyncShared] -> {0960F095-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarning] -> {0960F096-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarningShared] -> {0960F097-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton 360\Engine\20.6.0.27\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton 360\Engine\20.6.0.27\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton 360\Engine\20.6.0.27\buShell.dll (Symantec Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton 360\Engine\20.6.0.27\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files\Norton 360\Engine\20.6.0.27\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.6.0.27\coIEPlg.dll (Symantec Corporation)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.6.1

FireFox:
========
FF ProfilePath: C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2065253504-3069135328-3144787471-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF Extension: KeeFox - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\keefox@chris.tomlinson [2015-01-15]
FF Extension: Bookmark Favicon Changer - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\bookmarkfaviconchanger@sonthakit.xpi [2013-08-02]
FF Extension: Firebug - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\firebug@software.joehewitt.com.xpi [2013-08-02]
FF Extension: Firepicker - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\firepicker@thedarkone.xpi [2013-08-02]
FF Extension: SQLite Manager - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\SQLiteManager@mrinalkant.blogspot.com.xpi [2014-12-31]
FF Extension: Delete Bookmark Icons - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{04514a2c-a3ab-4f47-8688-55f911b0fe75}.xpi [2013-08-02]
FF Extension: Showcase - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}.xpi [2013-08-02]
FF Extension: Password Exporter - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi [2013-08-02]
FF Extension: Adblock Plus - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-02]
FF Extension: Tab Mix Plus - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2013-08-02]
FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn [2015-02-03]

Chrome: 
=======
CHR Profile: C:\Users\Juergen\AppData\Local\Google\Chrome\User Data\default
CHR HKLM\...\Chrome\Extension: [bejnhdlplbjhffionohbdnpcbobfejcc] - C:\Program Files\Norton 360\Engine\20.6.0.27\Exts\Chrome.crx [2014-12-09]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 N360; C:\Program Files\Norton 360\Engine\20.6.0.27\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
R2 USBLogonService; C:\Program Files\USBLogon\usblonsvc.exe [12288 2013-10-01] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20150106.001\BHDrvx86.sys [1164504 2015-01-06] (Symantec Corporation)
R3 btwampfl; C:\Windows\system32\drivers\btwampfl.sys [508632 2015-01-16] (Broadcom Corporation.)
R1 ccSet_N360; C:\Windows\system32\drivers\N360\1406000.01B\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [378672 2014-12-13] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [111408 2014-12-13] (Symantec Corporation)
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20150130.001\IDSvix86.sys [503000 2015-01-13] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20150202.034\NAVENG.SYS [95704 2015-01-26] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20150202.034\NAVEX15.SYS [1636696 2015-01-26] (Symantec Corporation)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [15688 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [10320 2013-09-30] ()
S3 SNPSTD3; C:\Windows\System32\DRIVERS\snpstd3.sys [10526464 2009-07-03] (Sonix Co. Ltd.)
R3 SRTSP; C:\Windows\System32\Drivers\N360\1406000.01B\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360\1406000.01B\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360\1406000.01B\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360\1406000.01B\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-08-04] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360\1406000.01B\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360\1406000.01B\SYMNETS.SYS [339544 2013-04-25] (Symantec Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-03 23:24 - 2015-02-03 23:25 - 00014503 _____ () C:\Users\Juergen\Desktop\FRST.txt
2015-02-03 23:22 - 2015-02-03 23:22 - 00000756 _____ () C:\Users\Juergen\Desktop\JRT.txt
2015-02-03 23:13 - 2015-02-03 23:13 - 01388274 _____ (Thisisu) C:\Users\Juergen\Desktop\JRT.exe
2015-02-03 23:05 - 2015-02-03 23:05 - 02194432 _____ () C:\Users\Juergen\Desktop\AdwCleaner_4.109(1).exe
2015-02-03 22:40 - 2015-02-03 22:41 - 00026758 _____ () C:\Users\Juergen\Downloads\Addition.txt
2015-02-03 22:38 - 2015-02-03 23:24 - 00000000 ____D () C:\FRST
2015-02-03 22:38 - 2015-02-03 22:41 - 00030559 _____ () C:\Users\Juergen\Downloads\FRST.txt
2015-02-03 22:38 - 2015-02-03 22:38 - 01122304 _____ (Farbar) C:\Users\Juergen\Desktop\FRST.exe
2015-02-03 21:31 - 2015-02-03 21:31 - 11225840 _____ (SurfRight B.V.) C:\Users\Juergen\Downloads\hitmanpro_x64.exe
2015-02-03 21:06 - 2015-02-03 23:10 - 00000000 ____D () C:\AdwCleaner
2015-02-03 21:05 - 2015-02-03 21:05 - 02194432 _____ () C:\Users\Juergen\Downloads\adwcleaner_4.109.exe
2015-02-03 20:22 - 2015-02-03 21:38 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-03 20:21 - 2015-02-03 20:21 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-02-03 20:21 - 2015-02-03 20:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-02-03 20:21 - 2015-02-03 20:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-03 20:21 - 2015-02-03 20:21 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 
2015-02-03 20:21 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-03 20:21 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-03 20:21 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-03 20:20 - 2015-02-03 20:20 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Juergen\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-03 19:41 - 2015-02-03 19:41 - 00000000 ____D () C:\Users\Juergen\AppData\Local\FreeOCR
2015-02-03 19:35 - 2015-02-03 20:37 - 00000000 ____D () C:\FreeOCR
2015-02-03 19:35 - 2007-03-10 10:11 - 02680320 _____ (HiComponents) C:\Windows\system32\ImageEnXLibrary.ocx
2015-02-03 19:33 - 2015-02-03 19:33 - 00000000 ____D () C:\Program Files\Temp
2015-02-03 19:32 - 2015-02-03 19:32 - 00414625 _____ ( ) C:\Users\Juergen\Downloads\FreeOCR-5.02.exe
2015-02-03 19:32 - 2015-02-03 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2015-02-03 19:31 - 2015-02-03 19:32 - 00000000 ____D () C:\Program Files\PDFCreator
2015-02-03 19:31 - 2015-01-22 16:14 - 00098488 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2015-02-03 19:26 - 2015-02-03 19:26 - 27721680 _____ (pdfforge ) C:\Users\Juergen\Downloads\PDFCreator-2_0_2-setup.exe
2015-01-28 22:25 - 2015-01-28 22:25 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-01-28 22:25 - 2015-01-28 22:21 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2015-01-28 22:25 - 2015-01-28 22:21 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2015-01-28 22:25 - 2015-01-28 22:21 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-01-28 22:23 - 2015-01-28 22:23 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-01-18 21:05 - 2015-01-18 21:06 - 00000000 ____D () C:\Users\Juergen\ownCloudBoule
2015-01-18 20:59 - 2015-01-18 20:59 - 46286392 _____ (ownCloud) C:\Users\Juergen\Downloads\ownCloud-1.7.1.4382-setup(1).exe
2015-01-18 20:05 - 2014-12-11 18:47 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-18 20:05 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-01-18 11:03 - 2015-01-18 16:34 - 00001372 _____ () C:\Users\Juergen\Desktop\Dapile wecken.lnk
2015-01-18 11:00 - 2015-01-18 11:00 - 00000000 ____D () C:\Users\Juergen\AppData\Local\www.oette.info
2015-01-18 10:59 - 2015-01-18 10:59 - 00077936 _____ (Gammadyne Corporation) C:\Users\Juergen\Downloads\wol.exe
2015-01-18 10:55 - 2015-01-18 10:55 - 00000000 ____H () C:\Users\Juergen\Documents\Default.rdp
2015-01-18 10:46 - 2015-01-18 10:46 - 01964729 _____ () C:\Users\Juergen\Downloads\WOL2.7z
2015-01-18 00:30 - 2015-01-18 00:30 - 00039424 _____ () C:\Users\Juergen\Desktop\Hessen.xls
2015-01-18 00:25 - 2015-01-18 00:25 - 00035672 _____ () C:\Users\Juergen\Desktop\Mappe1.txt
2015-01-17 23:09 - 2015-01-17 23:09 - 00004290 _____ () C:\Users\Juergen\Desktop\karte_hessen.html
2015-01-17 23:08 - 2015-01-17 23:08 - 00004290 _____ () C:\Users\Juergen\Downloads\karte_hessen.html
2015-01-17 22:44 - 2015-01-17 22:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2015-01-17 22:44 - 2015-01-17 22:44 - 00000000 ____D () C:\Program Files\7-Zip
2015-01-17 22:40 - 2015-01-17 22:40 - 01110476 _____ () C:\Users\Juergen\Downloads\7z920.exe
2015-01-17 22:39 - 2015-01-17 22:39 - 01376768 _____ () C:\Users\Juergen\Downloads\7z920-x64.msi
2015-01-17 22:26 - 2015-01-17 22:26 - 00196096 _____ () C:\Users\Juergen\Desktop\DM-Meldung_2014.xls
2015-01-17 10:54 - 2013-10-02 00:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-01-17 10:53 - 2013-10-02 01:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2015-01-17 10:53 - 2013-10-02 01:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-01-17 10:53 - 2013-10-02 01:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-01-17 10:53 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2015-01-17 10:53 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2015-01-17 10:53 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-01-17 10:53 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-01-17 10:53 - 2013-10-01 23:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-01-17 10:53 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-01-17 00:47 - 2015-01-17 00:49 - 00004270 _____ () C:\Users\Juergen\Desktop\karte_hallen.html
2015-01-16 16:31 - 2015-01-17 01:48 - 00284672 _____ () C:\Users\Juergen\Desktop\d5c41_joodb_spielorte-1.xls
2015-01-16 16:18 - 2015-01-16 16:18 - 00171501 _____ () C:\Users\Juergen\Downloads\d5c41_joodb_spielorte.csv
2015-01-16 14:53 - 2015-01-16 14:57 - 00004305 _____ () C:\Users\Juergen\Desktop\karte_gesamt.html
2015-01-16 08:47 - 2015-01-16 08:47 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte
2015-01-16 08:46 - 2015-01-16 08:46 - 00000000 ____D () C:\Users\Juergen\Documents\Bluetooth-Exchange-Ordner
2015-01-16 08:46 - 2015-01-16 08:46 - 00000000 ____D () C:\Users\Juergen\AppData\Local\Broadcom
2015-01-16 08:46 - 2015-01-16 08:35 - 00508632 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwampfl.sys
2015-01-16 08:39 - 2015-01-16 08:39 - 00001125 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Problem Report.lnk
2015-01-16 08:38 - 2015-01-16 08:35 - 00175144 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwavdt.sys
2015-01-16 08:38 - 2015-01-16 08:35 - 00152400 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwaudio.sys
2015-01-16 08:38 - 2015-01-16 08:35 - 00033832 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwl2cap.sys
2015-01-16 08:38 - 2015-01-16 08:35 - 00018728 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwrchid.sys
2015-01-16 08:36 - 2015-01-16 08:36 - 00000000 ____D () C:\Program Files\WIDCOMM
2015-01-16 08:23 - 2015-01-16 08:23 - 04171576 _____ (Broadcom Corporation.) C:\Users\Juergen\Downloads\SetupBtwDownloadSE.exe
2015-01-15 23:31 - 2014-12-19 03:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-15 23:31 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-01-15 23:31 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-15 23:30 - 2014-12-19 02:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-15 23:30 - 2014-12-06 04:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-15 00:08 - 2015-01-15 00:08 - 00771699 _____ () C:\Users\Juergen\Desktop\OpenLayers.js
2015-01-14 23:54 - 2015-01-14 23:54 - 00014336 _____ () C:\Users\Juergen\Desktop\pois.xls
2015-01-14 23:27 - 2015-01-15 00:03 - 00000701 _____ () C:\Users\Juergen\Desktop\dbcsv.php
2015-01-14 23:27 - 2015-01-14 23:29 - 00000207 _____ () C:\Users\Juergen\Desktop\dbconnect.php
2015-01-14 23:26 - 2015-01-15 00:17 - 00004251 _____ () C:\Users\Juergen\Desktop\karte.html
2015-01-14 23:25 - 2015-01-14 23:25 - 00258079 _____ () C:\Users\Juergen\Desktop\basic.html
2015-01-11 15:46 - 2015-01-18 21:02 - 00000981 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ownCloud.lnk
2015-01-11 15:45 - 2015-01-11 15:46 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-11 15:41 - 2015-01-11 15:43 - 46286392 _____ (ownCloud) C:\Users\Juergen\Downloads\ownCloud-1.7.1.4382-setup.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-03 23:18 - 2013-10-06 19:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-03 23:18 - 2009-07-14 05:34 - 00016352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-03 23:18 - 2009-07-14 05:34 - 00016352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-03 23:15 - 2013-07-30 17:54 - 01871724 _____ () C:\Windows\WindowsUpdate.log
2015-02-03 23:11 - 2010-11-20 22:48 - 00137608 _____ () C:\Windows\PFRO.log
2015-02-03 23:11 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-03 23:11 - 2009-07-14 05:39 - 00045883 _____ () C:\Windows\setupact.log
2015-02-03 22:32 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-02-03 20:58 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system
2015-02-03 20:40 - 2013-11-18 21:26 - 00000000 ____D () C:\Users\Juergen\ownCloud
2015-02-03 20:38 - 2013-12-09 20:21 - 00000000 ____D () C:\Program Files\Free mp3 Wma Converter
2015-02-03 07:00 - 2013-08-01 07:05 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-01-28 22:27 - 2014-01-29 21:09 - 00000000 ____D () C:\ProgramData\Oracle
2015-01-28 22:22 - 2014-10-18 08:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-01-28 22:21 - 2014-10-18 08:53 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2015-01-28 22:20 - 2014-08-18 12:29 - 00000000 ____D () C:\Program Files\Java
2015-01-25 10:40 - 2013-08-03 15:56 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-01-25 10:40 - 2013-08-03 15:56 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-01-20 21:08 - 2014-08-18 12:36 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\vlc
2015-01-20 19:47 - 2014-08-19 12:48 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\dvdcss
2015-01-20 19:43 - 2010-11-20 22:01 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-18 21:03 - 2013-11-18 21:25 - 00000000 ____D () C:\Users\Juergen\AppData\Local\ownCloud
2015-01-18 21:02 - 2013-11-18 21:25 - 00000000 ____D () C:\Program Files\ownCloud
2015-01-18 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-01-18 11:20 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-01-18 10:49 - 2013-08-02 10:14 - 00000000 ___RD () C:\Users\Juergen\Desktop\Programme
2015-01-17 11:05 - 2009-07-14 03:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-17 11:04 - 2011-03-20 08:51 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE
2015-01-16 08:01 - 2013-08-24 01:37 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\Mp3tag
2015-01-15 23:39 - 2013-08-02 09:17 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-15 23:32 - 2013-07-31 21:58 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-15 23:28 - 2013-08-25 09:04 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\foobar2000
2015-01-11 16:58 - 2014-12-13 12:36 - 00000000 ____D () C:\Users\Juergen\Desktop\Desktop Ablage 20141213
2015-01-04 09:54 - 2014-12-29 22:51 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\FileZilla

==================== Files in the root of some directories =======

2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Ambience
2013-12-05 20:12 - 2013-12-05 20:12 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Ambient
2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Analog Mono
2013-12-05 20:07 - 2013-12-05 20:07 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Audio Units
2013-12-05 21:07 - 2013-12-05 21:07 - 0003584 _____ () C:\Users\Juergen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-08-04 10:14 - 2013-08-04 10:14 - 0000600 _____ () C:\Users\Juergen\AppData\Local\PUTTY.RND
2014-11-15 16:21 - 2014-11-15 16:21 - 0000218 _____ () C:\Users\Juergen\AppData\Local\recently-used.xbel
2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\ProgramData\Analog Swirl
2013-12-05 20:12 - 2013-12-05 20:12 - 0000268 ___RH () C:\ProgramData\Analog Sync
2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\ProgramData\Animals
2013-12-05 20:12 - 2013-12-05 20:12 - 0000012 ___RH () C:\ProgramData\Basic Track
2013-12-05 20:09 - 2013-12-05 20:09 - 0000012 ___RH () C:\ProgramData\Bass
2013-12-05 20:07 - 2013-12-05 20:09 - 0000012 ___RH () C:\ProgramData\BSD
2013-12-05 20:07 - 2013-12-05 20:07 - 0000012 ___RH () C:\ProgramData\ColorSync
2013-12-05 20:07 - 2013-12-05 20:08 - 0000020 ____H () C:\ProgramData\PKP_DLeo.DAT
2013-12-05 20:12 - 2014-01-25 13:02 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT
2013-12-05 20:09 - 2014-11-12 09:25 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT
2013-12-05 20:09 - 2014-11-12 09:35 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT

Some content of TEMP:
====================
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.dll
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.exe
C:\Users\Juergen\AppData\Local\Temp\DE83F836-32DF-FEC7-3997-961617D0D8B7.exe
C:\Users\Juergen\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Juergen\AppData\Local\Temp\Quarantine.exe
C:\Users\Juergen\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-14 22:51

==================== End Of Log ============================
         
--- --- ---


Addition:
Zitat:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 01-02-2015
Ran by Juergen at 2015-02-03 23:26:15
Running from C:\Users\Juergen\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton 360 Online (Disabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton 360 Online (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton 360 Online (Disabled) {6BFC5632-188D-B806-D13E-C607121B42A0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (HKLM\...\7-Zip) (Version: - )
Acoustica Standard Edition 5.0 (HKLM\...\Acoustica Standard Edition_is1) (Version: 5.0 - Acon AS)
Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Amazon MP3-Downloader 1.0.18 (HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC)
AppInventor Setup (HKLM\...\AppInventor Setup) (Version: 2.2 - Massachusetts Institute of Technology)
Apple Application Support (HKLM\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.4852 - CDBurnerXP)
Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6514.5001 - Microsoft Corporation)
Download Navigator (HKLM\...\{E728441A-7820-4B1C-87C9-DE7BE37B2953}) (Version: 1.1.0 - SEIKO EPSON CORPORATION)
ElsterFormular (HKLM\...\ElsterFormular) (Version: 14.4.20130909 - Landesfinanzdirektion Thüringen)
EPSON BX535WD Series Printer Uninstall (HKLM\...\EPSON BX535WD Series) (Version: - SEIKO EPSON Corporation)
Epson Easy Photo Print 2 (HKLM\...\{FFF841F3-9A15-4F61-BD16-C19F132E5A27}) (Version: 2.3.0.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION2)
Epson Event Manager (HKLM\...\{FA9D303D-0FB2-49C7-9397-8E6B11EA892D}) (Version: 2.50.0001 - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.4j - SEIKO EPSON CORPORATION)
Extended Asian Language font pack for Adobe Reader XI (HKLM\...\{AC76BA86-7AD7-2530-0000-A00000000004}) (Version: 11.0.0 - Adobe Systems Incorporated)
FFmpeg v0.6.2 for Audacity (HKLM\...\FFmpeg for Audacity_is1) (Version: - )
FileZilla Client 3.9.0.6 (HKLM\...\FileZilla Client) (Version: 3.9.0.6 - Tim Kosse)
FLAC 1.2.1b (remove only) (HKLM\...\FLAC) (Version: 1.2.1b - Xiph.org)
foobar2000 v1.3 (HKLM\...\foobar2000) (Version: 1.3 - Peter Pawlowski)
FreeFileSync 6.8 (HKLM\...\FreeFileSync) (Version: 6.8 - Zenju)
Freemake Audio Converter Version 1.1.0 (HKLM\...\Freemake Audio Converter_is1) (Version: 1.1.0 - Ellora Assets Corporation)
Frontplatten Designer (HKLM\...\Frontplatten Designer) (Version: 4.3.1 - Schaeffer AG)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
inSSIDer Home (HKLM\...\{9E54E4AE-B67A-4925-8E92-0E1F9817FD73}) (Version: 3.1.2.1 - MetaGeek, LLC)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.14.10.2117 - Intel Corporation)
iTunes (HKLM\...\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
Java 8 Update 31 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Kinovea (HKLM\...\Kinovea) (Version: 0.8.15 - Kinovea) <==== ATTENTION!
LAME v3.99.3 (for Windows) (HKLM\...\LAME_is1) (Version: - )
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM\...\{90110407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
MiniTool Partition Wizard Home Edition 8.1.1 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Solution Ltd.)
Mozilla Firefox 35.0.1 (x86 de) (HKLM\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mp3tag v2.64 (HKLM\...\Mp3tag) (Version: v2.64 - Florian Heidenreich)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nikon Message Center 2 (HKLM\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon)
Nikon Movie Editor (HKLM\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.8.0 - Nikon)
Norton 360 (HKLM\...\N360) (Version: 20.6.0.27 - Symantec Corporation)
Notepad++ (HKLM\...\Notepad++) (Version: 6.6.9 - Notepad++ Team)
ownCloud (HKLM\...\ownCloud) (Version: 1.7.1.4382 - ownCloud)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.2 - pdfforge)
Picture Control Utility (HKLM\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.4.15 - Nikon)
Softsqueeze 3.9b2 (HKLM\...\Softsqueeze 3.9b2) (Version: - Ralph Irving)
Trust Webcam (HKLM\...\{ECD03DA7-5952-406A-8156-5F0C93618D1F}) (Version: 5.18.1211.103 - Sonix)
USBLogon 1.6.2.3 (HKLM\...\{E7D9D138-7DFA-441A-B1A9-703193C5D6D3}_is1) (Version: 1.6.2.3 - Quadsoft)
ViewNX 2 (HKLM\...\{E64C137C-D0B7-467A-B47F-460AAB30F0A3}) (Version: 2.8.2 - Nikon)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
WIDCOMM Bluetooth Software (HKLM\...\{A1439D4F-FD46-47F2-A1D3-FEE097C29A09}) (Version: 6.5.1.5800 - Broadcom Corporation)
WinRAR 4.20 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{00B7E0AB-817A-44AD-A04B-D1148D524136}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{3f04dadf-6ea4-44d1-a507-03cad176f443}\InprocServer32 -> C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)

==================== Restore Points =========================

15-01-2015 23:31:24 Windows Update
16-01-2015 08:38:24 Broadcom BTW Restore Point
17-01-2015 09:17:28 Windows Update
18-01-2015 20:05:50 Windows Update
18-01-2015 21:01:25 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
03-02-2015 21:26:44 Norton 360 Registry Clean

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {06B6DDAB-AAB0-4D0B-B52A-F905DE9B6A9F} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files\Norton 360\Engine\20.6.0.27\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {196C89FF-F3D9-448B-B7C1-92B1A0935C07} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton 360\Engine\20.6.0.27\WSCStub.exe [2014-12-06] (Symantec Corporation)
Task: {485B4A61-78AF-4C9E-A9CC-B8529DC8CE1B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-25] (Adobe Systems Incorporated)
Task: {65FAAE39-54E7-4A39-B113-451EEB66F7D5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {850628D5-9DE8-48E0-A6CF-EF448C6902A6} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files\Norton 360\Engine\20.6.0.27\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {CB7C8110-39F3-4E02-B442-E083E9851C10} - System32\Tasks\{945E7209-E1C4-479E-A68B-7B35F0A2E979} => pcalua.exe -a C:\Users\Juergen\Downloads\softsqueeze_windows_3_9b2.exe -d C:\Users\Juergen\Downloads

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2014-10-11 12:06 - 2014-10-11 12:06 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-10-16 10:15 - 2014-10-16 10:15 - 00035328 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2014-05-24 17:41 - 2014-05-24 17:41 - 00091648 _____ () C:\Program Files\FileZilla FTP Client\libgcc_s_sjlj-1.dll
2014-05-24 17:41 - 2014-05-24 17:41 - 00892416 _____ () C:\Program Files\FileZilla FTP Client\libstdc++-6.dll
2013-11-04 13:23 - 2013-10-01 17:11 - 00012288 _____ () C:\Program Files\USBLogon\usblonsvc.exe
2014-12-09 16:50 - 2012-05-30 07:51 - 00699280 ____R () C:\PROGRAM FILES\NORTON 360\ENGINE\20.6.0.27\wincfi39.dll
2014-11-30 14:14 - 2007-05-10 13:18 - 00835584 _____ () C:\Windows\vsnpstd3.exe
2014-11-30 14:14 - 2009-06-30 16:20 - 00339968 _____ () C:\Windows\tsnpstd3.exe
2013-05-22 19:50 - 2013-05-22 19:50 - 00400704 _____ () C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
2014-12-18 12:53 - 2014-12-18 12:53 - 23416869 _____ () C:\Program Files\ownCloud\owncloud.exe
2014-12-18 12:53 - 2014-12-18 12:53 - 03044905 _____ () C:\Program Files\ownCloud\libocsync.dll
2014-09-24 09:23 - 2014-09-24 09:23 - 00158048 _____ () C:\Program Files\ownCloud\libneon-27.dll
2014-09-21 23:32 - 2014-09-21 23:32 - 00084012 _____ () C:\Program Files\ownCloud\zlib1.dll
2014-09-22 02:45 - 2014-09-22 02:45 - 00095790 _____ () C:\Program Files\ownCloud\libgcc_s_sjlj-1.dll
2014-09-22 02:13 - 2014-09-22 02:13 - 00172695 _____ () C:\Program Files\ownCloud\libproxy.dll
2014-09-22 02:11 - 2014-09-22 02:11 - 00042626 _____ () C:\Program Files\ownCloud\libmodman.dll
2014-09-22 02:45 - 2014-09-22 02:45 - 00847430 _____ () C:\Program Files\ownCloud\libstdc++-6.dll
2014-09-22 01:05 - 2014-09-22 01:05 - 01150984 _____ () C:\Program Files\ownCloud\libxml2-2.dll
2014-09-22 01:10 - 2014-09-22 01:10 - 02164003 _____ () C:\Program Files\ownCloud\icui18n53.dll
2014-09-22 01:10 - 2014-09-22 01:10 - 01288240 _____ () C:\Program Files\ownCloud\icuuc53.dll
2014-09-22 01:10 - 2014-09-22 01:10 - 21540519 _____ () C:\Program Files\ownCloud\icudata53.dll
2014-09-22 01:16 - 2014-09-22 01:16 - 00144533 _____ () C:\Program Files\ownCloud\libpcre16-0.dll
2014-09-22 01:15 - 2014-09-22 01:15 - 01345629 _____ () C:\Program Files\ownCloud\libGLESv2.dll
2014-09-22 00:58 - 2014-09-22 00:58 - 00203567 _____ () C:\Program Files\ownCloud\libpng16-16.dll
2014-12-18 12:53 - 2014-12-18 12:53 - 15901197 _____ () C:\Program Files\ownCloud\libowncloudsync.dll
2014-09-22 01:15 - 2014-09-22 01:15 - 00150916 _____ () C:\Program Files\ownCloud\libEGL.dll
2014-09-22 01:08 - 2014-09-22 01:08 - 00197062 _____ () C:\Program Files\ownCloud\libjpeg-8.dll
2014-09-22 01:13 - 2014-09-22 01:13 - 00646511 _____ () C:\Program Files\ownCloud\libsqlite3-0.dll
2014-09-22 02:28 - 2014-09-22 02:28 - 00247028 _____ () C:\Program Files\ownCloud\libwebp-4.dll
2014-09-22 03:24 - 2014-09-22 03:24 - 00228655 _____ () C:\Program Files\ownCloud\libxslt-1.dll
2014-09-24 08:38 - 2014-09-24 08:38 - 00052119 _____ () C:\Program Files\ownCloud\libqt5keychain.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00702136 _____ () C:\Program Files\ownCloud\platforms\qwindows.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00032568 _____ () C:\Program Files\ownCloud\imageformats\qgif.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00035173 _____ () C:\Program Files\ownCloud\imageformats\qico.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00048436 _____ () C:\Program Files\ownCloud\imageformats\qjpeg.dll
2014-12-17 12:44 - 2014-12-17 12:44 - 00046592 _____ () C:\Program Files\ownCloud\shellext\OCUtil_x86.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\Juergen\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Juergen\Desktop\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Public\Downloads\.DS_Store:AFP_AfpInfo

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


========================= Accounts: ==========================

Administrator (S-1-5-21-2065253504-3069135328-3144787471-500 - Administrator - Disabled)
Gast (S-1-5-21-2065253504-3069135328-3144787471-501 - Limited - Enabled)
Juergen (S-1-5-21-2065253504-3069135328-3144787471-1000 - Administrator - Enabled) => C:\Users\Juergen

==================== Faulty Device Manager Devices =============

Name: Generischer Marvell Yukon 88E8040-PCI-E-Fast-Ethernet-Controller
Description: Generischer Marvell Yukon 88E8040-PCI-E-Fast-Ethernet-Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Marvell
Service: yukonw7
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================

System errors:
=============

Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Processor: Intel(R) Atom(TM) CPU N455 @ 1.66GHz
Percentage of memory in use: 44%
Total physical RAM: 2037.3 MB
Available physical RAM: 1122.94 MB
Total Pagefile: 4074.59 MB
Available Pagefile: 3157.92 MB
Total Virtual: 2047.88 MB
Available Virtual: 1919.73 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:119.14 GB) (Free:12.66 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: E91F5269)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=119.1 GB) - (Type=07 NTFS)

==================== End Of Log ============================
Danke
__________________

Alt 03.02.2015, 23:36   #4
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Blockandsurf win7 nicht los zu kriegen - Standard

Blockandsurf win7 nicht los zu kriegen



(edit: das tool scheint doch ok zu sein, vergiss es, poste gleich neu)


Virenscanner vor dem Fix bitte abdrehen

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path
C:\ProgramData\PKP_DLeo.DAT
C:\ProgramData\PKP_DLes.DAT
C:\ProgramData\PKP_DLet.DAT
C:\ProgramData\PKP_DLev.DAT
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.dll
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.exe
C:\Users\Juergen\AppData\Local\Temp\DE83F836-32DF-FEC7-3997-961617D0D8B7.exe
C:\Users\Juergen\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Juergen\AppData\Local\Temp\Quarantine.exe
C:\Users\Juergen\AppData\Local\Temp\sqlite3.dll
EmptyTemp:
Hosts:
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

__________________
Logfiles bitte immer in CODE-Tags posten

Alt 03.02.2015, 23:42   #5
hatzi
 
Blockandsurf win7 nicht los zu kriegen - Standard

Keine Ahnung??



Also im Infobereich wird mir immer noch ein Benachrichtigungssymbol "BlockAndSurf.exe" angezeigt und im Firefox gibt es immer noch jede Menge Werbung.

Danke


Alt 03.02.2015, 23:47   #6
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Blockandsurf win7 nicht los zu kriegen - Standard

Blockandsurf win7 nicht los zu kriegen



Fixlog fehlt.
__________________
--> Blockandsurf win7 nicht los zu kriegen

Alt 03.02.2015, 23:54   #7
hatzi
 
Blockandsurf win7 nicht los zu kriegen - Standard

Überschnitten und Fixlog



Meine Nachricht war vor deinem Post. Sorry!
Fixlog:
Zitat:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 01-02-2015
Ran by Juergen at 2015-02-03 23:43:21 Run:1
Running from C:\Users\Juergen\Desktop
Loaded Profiles: Juergen (Available profiles: Juergen)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path
C:\ProgramData\PKP_DLeo.DAT
C:\ProgramData\PKP_DLes.DAT
C:\ProgramData\PKP_DLet.DAT
C:\ProgramData\PKP_DLev.DAT
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.dll
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.exe
C:\Users\Juergen\AppData\Local\Temp\DE83F836-32DF-FEC7-3997-961617D0D8B7.exe
C:\Users\Juergen\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Juergen\AppData\Local\Temp\Quarantine.exe
C:\Users\Juergen\AppData\Local\Temp\sqlite3.dll
EmptyTemp:
Hosts:

*****************

HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\iikflkcanblccfahdhdonehdalibjnif" => Key deleted successfully.
C:\ProgramData\PKP_DLeo.DAT => Moved successfully.
C:\ProgramData\PKP_DLes.DAT => Moved successfully.
C:\ProgramData\PKP_DLet.DAT => Moved successfully.
C:\ProgramData\PKP_DLev.DAT => Moved successfully.
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.dll => Moved successfully.
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.exe => Moved successfully.
C:\Users\Juergen\AppData\Local\Temp\DE83F836-32DF-FEC7-3997-961617D0D8B7.exe => Moved successfully.
C:\Users\Juergen\AppData\Local\Temp\jre-8u31-windows-au.exe => Moved successfully.
C:\Users\Juergen\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Juergen\AppData\Local\Temp\sqlite3.dll => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 469.2 MB temporary data.


The system needed a reboot.

==== End of Fixlog 23:45:54 ====
Zusatz:
Firefox ist wohl clean.

Im Infobereich aber immer noch BAS-Symbol

Aber trotzdem großes Danke für die erste Arbeit.

Danke
Hatzi

Alt 04.02.2015, 00:03   #8
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Blockandsurf win7 nicht los zu kriegen - Standard

Blockandsurf win7 nicht los zu kriegen



Okay, dann Kontrollscans mit MBAM und ESET bitte:

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

__________________
Logfiles bitte immer in CODE-Tags posten

Antwort

Themen zu Blockandsurf win7 nicht los zu kriegen
adware, bonjour, browser, cpu, desktop, downloader, fehler, firefox, flash player, ftp, google, home, karte, mozilla, mp3, problem, registry, scan, security, software, svchost.exe, symantec, system, windows, wma



Ähnliche Themen: Blockandsurf win7 nicht los zu kriegen


  1. BlockandSurf Reste nicht auffindbar
    Log-Analyse und Auswertung - 12.01.2015 (9)
  2. BlockAndSurf loswerden!
    Plagegeister aller Art und deren Bekämpfung - 03.12.2014 (3)
  3. Werbeeinblendungen in Chrome durch BlockAndSurf
    Plagegeister aller Art und deren Bekämpfung - 20.10.2014 (5)
  4. Win7 TR/Agent.37888.248 kann nicht gelöscht werden, Echtzeitscanner funktioniert nicht mehr
    Log-Analyse und Auswertung - 21.07.2014 (26)
  5. Win7 bootet 20min, Bluescreens, langsames OS. Firewall nicht deaktivierbar. Remoteunterstützung nicht möglich.
    Log-Analyse und Auswertung - 30.06.2014 (9)
  6. BlockAndSurf entfernen
    Anleitungen, FAQs & Links - 10.03.2014 (2)
  7. Oxtender von Hosteurope auf Win7 Laptop nicht mehr vorhanden, Defender nicht startbar
    Plagegeister aller Art und deren Bekämpfung - 16.01.2014 (18)
  8. Win7-64: Eltern-PC infiziert; ESET startet nicht, Malwarebytes updatet nicht
    Plagegeister aller Art und deren Bekämpfung - 31.12.2013 (11)
  9. P2P-Botnetz ZeroAccess kaum tot zu kriegen
    Nachrichten - 16.12.2013 (0)
  10. GVU Trojaner Win7 64 bit abgesicherter Modus geht nicht, Kaspersky WindowsUnlocker klapppt auch nicht
    Plagegeister aller Art und deren Bekämpfung - 17.11.2013 (13)
  11. Win7 64Bit: Programme öffnen sich nicht - USB und mehr funzt nicht.
    Alles rund um Windows - 28.10.2012 (7)
  12. BKA-Sperrung auch bei mir - Rechner wieder sauber (zu kriegen)?
    Log-Analyse und Auswertung - 02.10.2012 (30)
  13. Mehrere Plagegeister die nicht tot zu kriegen sind CI.A Sasfis.A etc
    Log-Analyse und Auswertung - 18.04.2012 (9)
  14. Win7 herunterfahren Button reagiert nicht, strg+alt+entf geht nicht mehr & cmd.exe geht nicht auf
    Plagegeister aller Art und deren Bekämpfung - 15.12.2011 (25)
  15. TR/Crypt.XPack.Gen3 ist nicht von meinem Rechner zu kriegen!!!
    Plagegeister aller Art und deren Bekämpfung - 01.12.2010 (19)
  16. Trojaner an Bord und nicht zu kriegen...
    Log-Analyse und Auswertung - 23.07.2010 (17)
  17. lsass.exe nich tot zu kriegen!! óò
    Plagegeister aller Art und deren Bekämpfung - 19.04.2010 (8)

Zum Thema Blockandsurf win7 nicht los zu kriegen - Guten Abend, trotz Norton 360 leider BlockAndSurf gefangen. Ich hoffe es kann mir jemand helfen. FRST wirft folgendes aus: FRST.txt FRST Logfile: Code: Alles auswählen Aufklappen ATTFilter Scan result of - Blockandsurf win7 nicht los zu kriegen...
Archiv
Du betrachtest: Blockandsurf win7 nicht los zu kriegen auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.