![]() |
|
Plagegeister aller Art und deren Bekämpfung: Getwindowinfo entfernenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #3 |
| ![]() Getwindowinfo entfernen FRST Logfile:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-09-2013 Ran by Nadine333 (administrator) on KATERLIE on 13-09-2013 19:40:20 Running from C:\Users\Nadine333\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Simplygen) C:\Program Files (x86)\HomeTab\ProtectedSearch.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Windows Net) C:\Users\Nadine333\AppData\Roaming\Windows Net Data\net.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apntex.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe (Microsoft Corporation) C:\Windows\sysWOW64\wbem\wmiprvse.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\Admload.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10134560 2010-04-07] (Realtek Semiconductor) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [226160 2010-07-30] (Alps Electric Co., Ltd.) HKCU\...\Run: [iPhone PC Suite] - C:\Program Files (x86)\NetDragon\91 Mobile\iPhone\iPhone PC Suite.exe /start HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-03-03] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [NortonOnlineBackupReminder] - C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe [538472 2009-06-17] (Symantec Corporation) HKLM-x32\...\Run: [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [597792 2010-01-21] (Sony Corporation) HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [74752 2011-03-22] (Nullsoft, Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.) HKU\Gast\...\Run: [msnmsgr] - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [3872080 2010-04-16] (Microsoft Corporation) Startup: C:\Users\Nadine333\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk ShortcutTarget: net.lnk -> C:\Users\Nadine333\AppData\Roaming\Windows Net Data\net.exe (Windows Net) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.certified-toolbar.com?si=99&tid=0&st=bs&q= HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SVED&bmod=EU01 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.certified-toolbar.com?si=99&tid=0&st=bs&q= HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.certified-toolbar.com?si=99&tid=0&st=bs&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.certified-toolbar.com?si=99&tid=0&st=bs&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.certified-toolbar.com?si=99&tid=0&st=bs&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.certified-toolbar.com?si=99&tid=0&st=bs&q= SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms} SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms} SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms} SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms} SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms} SearchScopes: HKCU - {A16712E9-48DE-43B2-AC61-48E3896C0296} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices SearchScopes: HKCU - {A6E824C5-A7AC-46F9-AA13-A8DCA465AA82} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-0/4?satitle={searchTerms} SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms} SearchScopes: HKCU - {F0F15ED0-8B4E-4D3B-951A-50761BF672F8} URL = hxxp://de.shopping.com/?linkin_id=8056363 BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll No File BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: HomeTab - {a25e7121-3dd8-41b3-855b-756c5bc45449} - C:\Users\Nadine333\AppData\Roaming\HomeTab\HomeTab.dll (Simply Tech Ltd.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Web Check - {E155F23C-9931-47c6-A619-20E6FCA86D75} - C:\Program Files (x86)\Web Check\WebCheck.dll (Web Check) BHO-x32: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll No File Toolbar: HKLM-x32 - HomeTab - {a25e7121-3dd8-41b3-855b-756c5bc45449} - C:\Users\Nadine333\AppData\Roaming\HomeTab\HomeTab.dll (Simply Tech Ltd.) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - No Name - {56CF4856-ECB4-4E46-A897-A378821F97B9} - No File Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll (Microsoft Corporation) Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 10.0.0.138 FireFox: ======== FF ProfilePath: C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default FF NewTab: about:home FF SearchEngineOrder.1: Web Search FF Homepage: about:home FF Keyword.URL: hxxp://search.certified-toolbar.com?si=99&tid=0&st=bs&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\searchplugins\11-suche.xml FF SearchPlugin: C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\searchplugins\sweetim.xml FF SearchPlugin: C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\searchplugins\Web Search.xml FF SearchPlugin: C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Web Search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: pricealarm - C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM FF Extension: HomeTab - C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\{ad7ef860-f366-4be1-8d12-4363b9356947} FF Extension: FoxyDeal - C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\{F58A62EB-38DC-43C4-A539-DC52E135208D} FF Extension: No Name - C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\complitly_0.sqlite FF Extension: No Name - C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\WTB_GLOBAL.sqlite FF Extension: No Name - C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: No Name - C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01}.xpi FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF HKLM-x32\...\Firefox\Extensions: [{52b0f3db-f988-4788-b9dc-861d016f4487}] - C:\Program Files (x86)\Web Check\WebCheck.xpi FF Extension: No Name - C:\Program Files (x86)\Web Check\WebCheck.xpi FF HKCU\...\Firefox\Extensions: [sparpilot@sparpilot.com] - C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\extensions\sparpilot@sparpilot.com Chrome: ======= CHR Extension: () - C:\Users\NADINE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\background.html CHR HKLM-x32\...\Chrome\Extension: [bddpogknpjlgfpbboediomaiiaecfajn] - C:\Program Files (x86)\HomeTab\chrome\HomeTab.crx CHR HKLM-x32\...\Chrome\Extension: [dacechnliklhcacondhhkkfobapdopee] - C:\Program Files (x86)\Web Check\WebCheck.crx CHR HKLM-x32\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files (x86)\DealPly\DealPly.crx CHR HKLM-x32\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Users\Nadine333\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx CHR HKLM-x32\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Users\Nadine333\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetNT.crx ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-20] (Avira Operations GmbH & Co. KG) S3 Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [313840 2009-11-25] (Sonic Solutions) S2 Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [362992 2009-11-25] (Sonic Solutions) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) S3 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-09-13] (soft Xpansion) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [74496 2010-09-27] (Sony Corporation) S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [887000 2011-01-20] (Sony Corporation) R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1368624 2013-08-01] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-06] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-08-20] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-27] (Avira Operations GmbH & Co. KG) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-13 18:52 - 2013-09-13 18:54 - 00050737 _____ C:\Users\Nadine333\Downloads\Addition.txt 2013-09-13 18:50 - 2013-09-13 18:50 - 00000000 ____D C:\FRST 2013-09-13 18:49 - 2013-09-13 18:49 - 01949572 _____ (Farbar) C:\Users\Nadine333\Downloads\FRST64.exe 2013-09-13 16:23 - 2013-09-13 17:00 - 97492159 _____ C:\Windows\SysWOW64\%Ḭ 2013-09-13 12:11 - 2013-09-13 12:11 - 00010464 _____ C:\Windows\SysWOW64\sx_p2d.tlb 2013-09-13 12:10 - 2013-09-13 12:26 - 00000000 ____D C:\ProgramData\Freemium 2013-09-13 12:09 - 2013-09-13 12:09 - 00000000 ____D C:\Users\Nadine333\Downloads\freepdf 2013-09-13 12:09 - 2013-09-13 12:09 - 00000000 ____D C:\SoftwareUpdater 2013-09-13 12:07 - 2013-09-13 12:07 - 00000000 ____D C:\Program Files (x86)\Web Check 2013-09-13 12:02 - 2013-09-13 12:23 - 00000000 ____D C:\Users\Nadine333\AppData\Roaming\Windows Net Data 2013-09-13 12:02 - 2013-09-13 12:19 - 00000000 ____D C:\SoloApp 2013-09-13 12:02 - 2013-09-13 12:02 - 00000000 ____D C:\Windows\System32\Tasks\ProtectedSearch 2013-09-13 12:02 - 2013-09-13 12:02 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater 2013-09-13 12:02 - 2013-09-13 12:02 - 00000000 ____D C:\Users\Nadine333\AppData\Roaming\SimplyTech 2013-09-13 12:02 - 2013-09-13 12:02 - 00000000 ____D C:\Users\Nadine333\AppData\Roaming\HomeTab 2013-09-13 12:02 - 2013-09-13 12:02 - 00000000 ____D C:\Program Files (x86)\HomeTab 2013-09-13 12:02 - 2013-09-13 12:02 - 00000000 ____D C:\Program Files (x86)\FoxyDeal 2013-09-13 12:02 - 2013-08-13 08:38 - 00032328 _____ C:\Windows\Launcher.exe 2013-09-13 11:57 - 2013-09-13 11:58 - 00000000 ____D C:\Users\Nadine333\AppData\Local\DownloadGuide 2013-09-13 11:56 - 2013-09-13 11:56 - 00444400 _____ C:\Users\Nadine333\Downloads\DLG_free-pdf-perfect_chip_de-DE10.exe 2013-09-12 23:21 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-12 23:21 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-12 23:21 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-12 23:21 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-12 23:21 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-12 23:21 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-12 23:21 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-12 23:21 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-12 23:21 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-12 23:21 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-12 23:21 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-12 23:21 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-12 23:21 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-12 23:21 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-12 23:21 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-12 23:21 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-12 23:21 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-12 23:21 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-12 23:21 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-12 23:21 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-12 23:21 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-12 23:21 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-12 23:21 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-12 23:21 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-12 23:21 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-12 23:21 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-12 23:21 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-12 23:21 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-12 23:21 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-12 23:21 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-12 23:21 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-12 21:31 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-12 21:31 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-12 21:31 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-12 21:31 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-12 21:31 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-12 21:31 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-12 21:31 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-12 21:31 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-12 21:31 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-12 21:31 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-12 21:31 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-12 21:31 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-12 21:31 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-12 21:31 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-12 21:31 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-12 21:31 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-12 21:31 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-12 21:31 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-12 21:31 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-12 21:31 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-12 21:31 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-12 21:31 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-12 21:31 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-12 21:31 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-12 21:31 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-12 21:31 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-12 21:31 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-12 20:44 - 2013-09-12 21:41 - 00000000 ____D C:\Users\Nadine333\Documents\Gutachten - Befundaufnahme 2013-09-10 11:30 - 2013-09-10 11:32 - 00000000 ____D C:\Program Files (x86)\MSECache 2013-08-24 21:56 - 2013-09-10 12:18 - 00000000 ___RD C:\Users\Nadine333\Desktop\Studium 2013-08-19 11:54 - 2013-08-19 11:54 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-19 11:53 - 2013-08-19 11:54 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-19 11:53 - 2013-08-19 11:54 - 00000000 ____D C:\Program Files\iTunes 2013-08-19 11:53 - 2013-08-19 11:54 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-19 11:53 - 2013-08-19 11:53 - 00000000 ____D C:\Program Files\iPod 2013-08-19 11:41 - 2013-09-13 12:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-14 15:10 - 2013-09-12 23:20 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 08:40 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 08:40 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 08:40 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 08:40 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 08:40 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 08:40 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 08:40 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 08:40 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 08:40 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 08:40 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 08:39 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 08:39 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 08:39 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 08:39 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 08:39 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 08:39 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys ==================== One Month Modified Files and Folders ======= 2013-09-13 19:04 - 2012-04-18 21:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-13 19:01 - 2013-06-01 13:01 - 00000304 _____ C:\Windows\Tasks\Dealply.job 2013-09-13 18:54 - 2013-09-13 18:52 - 00050737 _____ C:\Users\Nadine333\Downloads\Addition.txt 2013-09-13 18:50 - 2013-09-13 18:50 - 00000000 ____D C:\FRST 2013-09-13 18:49 - 2013-09-13 18:49 - 01949572 _____ (Farbar) C:\Users\Nadine333\Downloads\FRST64.exe 2013-09-13 18:48 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-13 18:48 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-13 18:42 - 2010-12-07 05:34 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-13 18:42 - 2010-12-07 05:34 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-13 18:28 - 2011-04-19 16:05 - 01194135 _____ C:\Windows\WindowsUpdate.log 2013-09-13 17:00 - 2013-09-13 16:23 - 97492159 _____ C:\Windows\SysWOW64\%Ḭ 2013-09-13 12:28 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-13 12:28 - 2009-07-14 06:51 - 00144135 _____ C:\Windows\setupact.log 2013-09-13 12:27 - 2010-12-07 06:04 - 00137896 _____ C:\Windows\PFRO.log 2013-09-13 12:26 - 2013-09-13 12:10 - 00000000 ____D C:\ProgramData\Freemium 2013-09-13 12:23 - 2013-09-13 12:02 - 00000000 ____D C:\Users\Nadine333\AppData\Roaming\Windows Net Data 2013-09-13 12:19 - 2013-09-13 12:02 - 00000000 ____D C:\SoloApp 2013-09-13 12:18 - 2011-04-19 16:09 - 00003946 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{02601A2E-B72F-4DB2-9ECC-7A01B39F69F6} 2013-09-13 12:11 - 2013-09-13 12:11 - 00010464 _____ C:\Windows\SysWOW64\sx_p2d.tlb 2013-09-13 12:09 - 2013-09-13 12:09 - 00000000 ____D C:\Users\Nadine333\Downloads\freepdf 2013-09-13 12:09 - 2013-09-13 12:09 - 00000000 ____D C:\SoftwareUpdater 2013-09-13 12:08 - 2013-08-19 11:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-13 12:07 - 2013-09-13 12:07 - 00000000 ____D C:\Program Files (x86)\Web Check 2013-09-13 12:06 - 2011-04-19 16:09 - 00000000 ___RD C:\Users\Nadine333\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-13 12:02 - 2013-09-13 12:02 - 00000000 ____D C:\Windows\System32\Tasks\ProtectedSearch 2013-09-13 12:02 - 2013-09-13 12:02 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater 2013-09-13 12:02 - 2013-09-13 12:02 - 00000000 ____D C:\Users\Nadine333\AppData\Roaming\SimplyTech 2013-09-13 12:02 - 2013-09-13 12:02 - 00000000 ____D C:\Users\Nadine333\AppData\Roaming\HomeTab 2013-09-13 12:02 - 2013-09-13 12:02 - 00000000 ____D C:\Program Files (x86)\HomeTab 2013-09-13 12:02 - 2013-09-13 12:02 - 00000000 ____D C:\Program Files (x86)\FoxyDeal 2013-09-13 11:58 - 2013-09-13 11:57 - 00000000 ____D C:\Users\Nadine333\AppData\Local\DownloadGuide 2013-09-13 11:56 - 2013-09-13 11:56 - 00444400 _____ C:\Users\Nadine333\Downloads\DLG_free-pdf-perfect_chip_de-DE10.exe 2013-09-13 11:01 - 2011-04-19 23:33 - 00000000 ____D C:\Users\Nadine333\AppData\Roaming\Winamp 2013-09-13 08:42 - 2011-04-19 16:09 - 00000000 ___RD C:\Users\Nadine333\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-13 08:40 - 2009-07-14 06:45 - 00301536 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-13 08:35 - 2010-12-07 05:34 - 00000000 ____D C:\Program Files\Google 2013-09-13 08:35 - 2010-12-07 05:34 - 00000000 ____D C:\Program Files (x86)\Google 2013-09-12 23:21 - 2011-04-22 18:38 - 01527912 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-09-12 23:21 - 2011-04-22 18:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client 2013-09-12 23:21 - 2010-12-07 14:13 - 00654852 _____ C:\Windows\system32\perfh007.dat 2013-09-12 23:21 - 2010-12-07 14:13 - 00130434 _____ C:\Windows\system32\perfc007.dat 2013-09-12 23:20 - 2013-08-14 15:10 - 00000000 ____D C:\Windows\system32\MRT 2013-09-12 23:17 - 2011-04-29 18:23 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-12 23:08 - 2011-04-22 18:39 - 00000000 ____D C:\Users\Nadine333\AppData\Roaming\SoftGrid Client 2013-09-12 21:41 - 2013-09-12 20:44 - 00000000 ____D C:\Users\Nadine333\Documents\Gutachten - Befundaufnahme 2013-09-12 21:35 - 2013-05-08 00:50 - 00013874 _____ C:\Windows\IE10_main.log 2013-09-12 21:26 - 2011-04-19 16:14 - 00000000 ____D C:\Users\Nadine333\AppData\Local\Google 2013-09-12 21:26 - 2010-12-07 05:34 - 00000000 ____D C:\ProgramData\Google 2013-09-12 21:04 - 2012-04-18 21:32 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-12 21:04 - 2012-04-18 21:32 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-12 21:04 - 2011-06-17 15:14 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-12 20:55 - 2011-04-25 10:45 - 00000000 ____D C:\Update 2013-09-12 20:48 - 2010-12-07 05:35 - 00000000 ____D C:\ProgramData\Sony Corporation 2013-09-10 12:18 - 2013-08-24 21:56 - 00000000 ___RD C:\Users\Nadine333\Desktop\Studium 2013-09-10 11:33 - 2011-04-19 16:06 - 00066104 _____ C:\Users\Nadine333\AppData\Local\GDIPFONTCACHEV1.DAT 2013-09-10 11:32 - 2013-09-10 11:30 - 00000000 ____D C:\Program Files (x86)\MSECache 2013-09-10 11:31 - 2010-12-07 05:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2013-09-06 09:07 - 2013-03-27 19:17 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-08-26 18:32 - 2013-03-04 21:19 - 00000000 ___RD C:\Users\Nadine333\Desktop\Vienna pics 2013-08-25 21:32 - 2011-04-24 01:11 - 00000000 ____D C:\Users\Nadine333\Desktop\Handy pics 2013-08-25 18:32 - 2011-04-20 11:12 - 00000000 ____D C:\Users\Nadine333\Documents\Bewerbungsunterlagen 2013-08-24 21:43 - 2012-04-30 20:08 - 00000000 ____D C:\Users\Nadine333\Documents\Word Dateien 2013-08-24 21:40 - 2013-02-06 20:23 - 00000000 ____D C:\Users\Public\Documents\Wohnung 2013-08-23 21:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-21 15:27 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-08-21 07:53 - 2012-05-05 11:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-20 11:16 - 2009-07-14 07:13 - 01500294 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-20 10:14 - 2013-05-06 14:11 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-08-20 10:14 - 2013-03-27 19:17 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-08-19 11:54 - 2013-08-19 11:54 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-19 11:54 - 2013-08-19 11:53 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-19 11:54 - 2013-08-19 11:53 - 00000000 ____D C:\Program Files\iTunes 2013-08-19 11:54 - 2013-08-19 11:53 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-19 11:53 - 2013-08-19 11:53 - 00000000 ____D C:\Program Files\iPod Files to move or delete: ==================== C:\Users\Gast\AppData\Local\Temp\AskSLib.dll C:\Users\Gast\AppData\Local\Temp\msgA344.exe C:\Users\Nadine333\AppData\Local\Temp\84962-658111-microsoft-office-2010-professional.exe C:\Users\Nadine333\AppData\Local\Temp\apptorun.exe C:\Users\Nadine333\AppData\Local\Temp\AskSLib.dll C:\Users\Nadine333\AppData\Local\Temp\dealply.exe C:\Users\Nadine333\AppData\Local\Temp\EAD27CA.exe C:\Users\Nadine333\AppData\Local\Temp\EAD2A0D.exe C:\Users\Nadine333\AppData\Local\Temp\EAD3890.exe C:\Users\Nadine333\AppData\Local\Temp\EAD3C7.exe C:\Users\Nadine333\AppData\Local\Temp\EAD54B.exe C:\Users\Nadine333\AppData\Local\Temp\EAD5502.exe C:\Users\Nadine333\AppData\Local\Temp\EAD9936.exe C:\Users\Nadine333\AppData\Local\Temp\EADA622.exe C:\Users\Nadine333\AppData\Local\Temp\EADC88B.exe C:\Users\Nadine333\AppData\Local\Temp\EADCD4C.exe C:\Users\Nadine333\AppData\Local\Temp\EADEEA2.exe C:\Users\Nadine333\AppData\Local\Temp\EADF5E6.exe C:\Users\Nadine333\AppData\Local\Temp\installerdll166687.dll C:\Users\Nadine333\AppData\Local\Temp\installerdll188558.dll C:\Users\Nadine333\AppData\Local\Temp\installerdll44766234.dll C:\Users\Nadine333\AppData\Local\Temp\installerdll44788729.dll C:\Users\Nadine333\AppData\Local\Temp\instloffer.exe C:\Users\Nadine333\AppData\Local\Temp\jre-1.6.0_20-windows-i586-iftw.exe_90744722.exe C:\Users\Nadine333\AppData\Local\Temp\jre-6u20-windows-i586-jinstall_uac.exe C:\Users\Nadine333\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe C:\Users\Nadine333\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe C:\Users\Nadine333\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe C:\Users\Nadine333\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe C:\Users\Nadine333\AppData\Local\Temp\jre-6u33-windows-i586-iftw.exe C:\Users\Nadine333\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe C:\Users\Nadine333\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe C:\Users\Nadine333\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe C:\Users\Nadine333\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe C:\Users\Nadine333\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Nadine333\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Nadine333\AppData\Local\Temp\mgsqlite3.dll C:\Users\Nadine333\AppData\Local\Temp\Setup.exe C:\Users\Nadine333\AppData\Local\Temp\Shortcut_bundlesweetimsetup.exe C:\Users\Nadine333\AppData\Local\Temp\SIMEEI2Installer.exe C:\Users\Nadine333\AppData\Local\Temp\SIMEEIInstaller.exe C:\Users\Nadine333\AppData\Local\Temp\SIntf16.dll C:\Users\Nadine333\AppData\Local\Temp\SIntf32.dll C:\Users\Nadine333\AppData\Local\Temp\SIntfNT.dll C:\Users\Nadine333\AppData\Local\Temp\toolbar_vit_sweetim.exe C:\Users\Nadine333\AppData\Local\Temp\_is7E05.exe C:\Users\Nadine333\AppData\Local\Temp\~convert4585880079106920541.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-06 09:36 ==================== End Of Log ============================ --- --- --- addition.txt kam noch nicht =( |
Themen zu Getwindowinfo entfernen |
dankbar, entferne, entfernen, getwindowinfo, hilfe, hilfe!, hilfe!!, hilfe!!!, troja, trojaner |